A Chinese hacker connected the DeepSeek language model with tools capable of searching for vulnerable computer systems, downloading exploit code, and attempting to break into targets without ongoing human control. Security researchers describe this as a working example of how artificial intelligence can be used to automate large parts of a cyberattack.

This is according to a new report by the Palo Alto Networks research group Unit 42. The hacker, operating under the names “knaithe” and “KnYuan,” is said to be active in the Chinese city of Zhuhai.

DeepSeek was used as a decision engine in the open-source program Hermes Agent. Through the system, the model gained access to a computer terminal, search tools, and ready-made instructions to discover and attack vulnerable systems. The hacker could issue an initial assignment via the messaging service Telegram, after which the program proceeded autonomously.

Independently Chose Which Vulnerabilities to Target

In one documented attempt, the system began by searching for installations of the Langflow program. It found 84 targets and identified one using a vulnerable version, but the attack failed because certain necessary settings were not enabled.

READ ALSO: AI Models Escaped Test Environment — Hacked Another Company on Their Own

DeepSeek then independently assessed that Langflow was not worth continuing to attack. The model instead reviewed ten other software families, compared their prevalence, and searched for publicly available exploit code.

The choice fell on the automation program n8n, which was installed on hundreds of thousands of internet-connected systems. DeepSeek retrieved ready-made code for two serious security flaws, searched for vulnerable versions, and initiated attempts against several targets. These attacks also failed as the targeted systems required login credentials.

According to Unit 42, the system in just a few minutes carried out a selection process that would otherwise have required hundreds of hours of manual work.

More Than 460 Targets Faced Attack Attempts

The researchers link the hacker to attempts against over 460 targets. That figure, however, includes both automated and manually conducted attacks. Unit 42 found no evidence that the fully automated attempts resulted in any system being taken over.

READ ALSO: AI Solved 50-Year-Old Math Problem — In Less Than an Hour

The hacker, on the other hand, managed during manual attacks to extract data from three Citrix NetScaler systems and execute commands on eleven installations of the program Marimo. Among the targets was a government agency in Malaysia that was attacked over multiple days.

The operation was exposed due to a mistake by the automated system. Hermes Agent started an openly accessible file server in the hacker’s home directory, thereby exposing, among other things, keys for various services, exploit code, target lists, command history, and logs from DeepSeek’s operations.

Western Models Blocked Requests

The hacker had also tried services from Anthropic and OpenAI, but their use appears to have been limited. OpenAI told the researchers that the company’s protection systems blocked requests that violated the rules and later disabled an account deemed linked to the operation.

DeepSeek, however, was used through Hermes Agent, which lacked its own protection against harmful tasks. Unit 42 judges that the hacker chose the model that offered the least resistance.

The researchers emphasize that the results so far have been limited but warn about the direction of development. According to the report, the technical threshold for building systems that independently search, assess, and attack targets is becoming increasingly low.

READ ALSO: Ekeroth: “We All Underestimate AI’s Progress — With Deadly Results”