Military & Security

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

· July 31, 2026
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

What happened

A Chinese-speaking hacker tracked under the aliases knaithe and KnYuan used the DeepSeek tool through the open-source Hermes Agent framework to launch autonomous cyberattacks. This operation was controlled via a single instruction sent over Telegram. After initial commands, the agent scanned the internet for exposed systems, identified vulnerable targets, and chose public exploits to deploy without further input from the operator. Palo Alto Networks’ Unit 42 uncovered no additional interaction, indicating a largely hands-off, automated attack cycle.

The risk

This case shows how attackers are increasingly relying on autonomous agents that reduce the need for continuous manual control. DeepSeek’s integration with Hermes Agent lets a hacker initiate a fully automated assault chain, meaning responses must account for faster attack execution and less need for human error. The use of publicly known exploits increases the risk to unpatched or misconfigured internet-facing systems. Angela steps back once the initial command is given and lets the AI-driven agent take over, accelerating attack speed and lowering the attacker’s operational cost and risk of detection.

Why it matters

The shift towards autonomous hacking tools raises the bar for real-time network defense. Operators can no longer rely solely on detecting repetitive attacker actions or prolonged command sessions. Defense teams must tighten automated vulnerability management and monitoring for sudden out-of-pattern exploit attempts. Organizations facing such autonomy-enabled threats must improve rapid patching and intrusion prevention to close attack windows that agents like DeepSeek aggressively exploit. Investors and security buyers should price in elevated risks from AI-assisted autonomous attacks, increasing demand for proactive and automated cybersecurity solutions.

Who should pay attention

Enterprise security teams running internet-facing services, especially those exposed to common exploit frameworks, need heightened vigilance. Cloud and infrastructure operators must reconsider asset visibility and quick remediation workflows to disrupt AI-automated attack sequences. Security researchers and threat intelligence analysts should track this trend as it could expand to additional open-agent frameworks and AI models controlling offensive operations. Regulators might also monitor how autonomous tools challenge established cybersecurity compliance and incident response norms.

What to watch next

Look for more attacks leveraging open-source automation frameworks combined with AI or script-driven autonomous payload deployment. The pace of autonomous cyber campaigns will likely increase, pressuring defensive tooling and forcing faster iteration of security automation. Keep an eye on how threat actors evolve their agent frameworks to reduce command surface while increasing stealth. Development of automated detection and response solutions calibrated to stop one-shot autonomous attack flows will be vital to counter this emerging threat vector.

AI Quick Briefs Editorial Desk

Stay ahead of AI Get the most important AI news delivered to your inbox — free.