Security researchers have uncovered an AI-enabled autonomous cyberattack campaign conducted by a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan. The attackers combined autonomous AI-driven reconnaissance with manual exploitation, successfully targeting infrastructure through seven known software vulnerabilities, demonstrating how generative AI is reshaping offensive cyber operations.
At the core of the campaign was DeepSeek, deployed through the Hermes Agent framework as an autonomous offensive operator. Controlled via Telegram, the AI independently identified vulnerable targets using the FOFA search engine, searched for publicly available exploit tools, and launched attacks with minimal human intervention. When initial exploitation attempts failed, the AI autonomously researched critical Common Vulnerabilities and Exposures (CVEs), analyzed GitHub repositories for trending proof-of-concept exploits, and shifted its focus toward higher-value attack opportunities.
Researchers gained unprecedented insight into the operation after the autonomous agent accidentally exposed its own infrastructure by launching a file server, revealing its configuration, session logs, and operational workflow. The investigation showed that while DeepSeek handled the primary attack logic, the threat actor also evaluated several other large language models, including Qwen, GLM, Kimi, MiniMax, and selectively tested Western AI platforms such as Claude Code for connectivity and proxy validation, along with Codex for exploit development.
Although the observed attacks had limited real-world impact, the campaign marks a significant milestone in cyber warfare by demonstrating an end-to-end autonomous offensive capability. Security experts warn that AI is rapidly evolving from a productivity tool into an operational cyber weapon capable of discovering vulnerabilities, adapting attack strategies, and executing exploitation with minimal human guidance. The findings underscore the urgent need for organizations to strengthen AI-aware threat detection, proactive vulnerability management, and autonomous cyber defense as the next generation of AI-driven attacks becomes increasingly sophisticated.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




