Abstract illustration of a translucent shield set among glowing hexagons, shifting from violet on the left to cyan on the right against dark navy

DeepSeek-Powered Agent Runs Multi-Step Attack Campaign

Unit 42 has identified an autonomous AI agent running an active, multi-step attack campaign against real infrastructure.

In research published July 30, 2026, Palo Alto Networks’ Unit 42 documented a Chinese-speaking actor using the aliases “knaithe” and “KnYuan.” The actor integrated DeepSeek as the reasoning engine within the open-source Hermes Agent framework. Hermes handled orchestration, including terminal access, Telegram-based command-and-control, and a modular “skills” system, while DeepSeek wrote code, judged vulnerabilities, and selected targets.

Unit 42 reports the campaign hit infrastructure across seven vulnerabilities, blending AI-driven enumeration with manual exploitation to compromise target environments.

This approach exposes gaps in standard Zero Trust design. Most architectures assume human-paced sessions, static identities tied to people or fixed service accounts, and endpoint-centric telemetry. An agent violates all three. It operates as a non-human identity that spawns, reasons, and acts faster than any analyst can review. It maintains session persistence across long chains of actions, and it uses tools dynamically, choosing its next move based on live output rather than a preset script.

For defenders, the required controls are specific. Issue distinct identities to agents so their activity is separable from human users. Bind agent access to short-lived, purpose-scoped tokens that expire on the timescale of a single task, not a workday. Gate tool calls: require policy checks before an agent can execute code, reach a terminal, or open outbound channels like the Telegram path Unit 42 flagged.

Treat autonomous agents as first-class principals in your policy engine now. Attackers already do.


Leave a Reply

Discover more from Digerati One (Di1) | AI Integration & Multi-Cloud Architecture

Subscribe now to keep reading and get access to the full archive.

Continue reading