Chinese Hacker Uses DeepSeek AI to Automate Vulnerability Exploitation
Brief
A Chinese-speaking threat actor has been observed using DeepSeek AI as an autonomous offensive operator to identify exposed infrastructure, research vulnerabilities, acquire public proof-of-concept exploits, and launch attacks with minimal human intervention.
Palo Alto Networks Unit 42 tracked the activity to an actor known as knaithe and KnYuan, describing the campaign as an early but functional example of end-to-end AI-assisted cyberattack automation.
While the autonomous operations produced limited confirmed impact, the researchers warned that the campaign demonstrates how large language models can accelerate vulnerability research, target prioritization, and exploitation workflows.
