Intelligence
highCampaignActive

Chinese Actor's Autonomous AI Exploitation Failed While Manual Attacks Breached Targets

Unit 42 linked the aliases knaithe and KnYuan to failed autonomous exploitation using DeepSeek through Hermes Agent and to separate, successful manual attacks. Confirmed impact—three Citrix data exfiltrations and command execution on 11 Marimo endpoints—came from manual exploitation, not AI autonomy.

S
Sebastion

Affected

Citrix NetScaler ADC and GatewayMarimo NotebookMalaysian government entity

Unit 42 documented activity by a Chinese-speaking actor using the aliases knaithe and KnYuan. The actor configured DeepSeek as the reasoning model in the Hermes Agent framework for autonomous enumeration, exploit acquisition and attempted exploitation, while also conducting separate manual campaigns.

The autonomous component failed to compromise its intended targets. DeepSeek/Hermes Agent attempted CVE-2026-33017 against Langflow, but required configuration was absent. It then assessed n8n exploitation involving CVE-2026-21858, but authentication on exposed forms prevented exploitation. Unit 42 found no full compromise from the autonomous campaigns.

Confirmed impact came from conventional manual workflows. Unit 42 verified data exfiltration from three Citrix NetScaler targets through CVE-2026-3055 and command execution on 11 Marimo Notebook endpoints through CVE-2026-39987. The actor also staged or attempted activity involving CVE-2026-34486 in Apache Tomcat, CVE-2026-0300 in PAN-OS and CVE-2026-33824 in Windows IKE. A Malaysian government entity was persistently targeted through the Citrix flaw.

The research shows an actor operationalising AI-assisted reconnaissance and exploit selection, but it does not show AI autonomously achieving the confirmed breaches. Defenders should prioritise the seven listed CVEs according to exposure and distinguish automated attempts from the manually executed compromises when assessing the campaign.