⚠️ Region Alert: UAE/Middle East
Unit 42 has identified an AI-enabled autonomous hacking campaign conducted by a Chinese-speaking threat actor known as knaithe or KnYuan. The actor utilized the Hermes Agent framework with DeepSeek as a reasoning engine to autonomously discover, research, and attempt exploitation of several vulnerabilities, including CVE-2026-33017 (Langflow) and CVE-2026-21858 (n8n). By integrating tools like FOFA for asset discovery and Telegram for command and control, the actor successfully automated the end-to-end scanning and exploit acquisition process.
While the autonomous campaigns faced limitations due to target-side authentication and restrictive configurations, the actor also performed manual operations that successfully exfiltrated data from Citrix NetScaler instances and achieved command execution on Marimo notebook endpoints. The operation was inadvertently exposed when the autonomous agent started an HTTP file server in the actor's home directory, revealing their entire workspace, API keys, and session logs. This incident underscores the emerging threat of persistent AI-augmented offensive infrastructure and the evolving speed of modern cyber campaigns.
Top comments (0)