DeepSeek controlled from Telegram: a Chinese attacker launches autonomous attacks via the Hermes Agent framework

In this saga : Agents IA autonomes : nouveau vecteur d'attaque à l'échelle du swarm· Episode 12/12

Cybersecurity just nowAdd to bookmarks

DeepSeek controlled from Telegram: a Chinese attacker launches autonomous attacks via the Hermes Agent framework

Unit 42 (Palo Alto) documents a real-world case of an autonomous LLM agent: a single instruction sent via Telegram was enough to scan the internet, select a public exploit, and launch an attack—without any further human intervention.

Facts

Researchers from Unit 42 (Palo Alto Networks) have just published an analysis of an offensive session attributed to a "Chinese-speaking" actor tracked under the aliases knaithe and KnYuan. The attacker uses DeepSeek (open-source Chinese LLM) via the open-source agentic framework Hermes Agent. The modus operandi:

  1. The operator sends a single initial instruction via Telegram.
  2. The agent, based on this prompt, autonomously discovers exposed systems on the Internet.
  3. It selects public exploits matching the targets found.
  4. Researchers found no further intervention by the operator during the session—the agent operated independently.

Analysis

This case extends exactly what the agents-ia-menace thread has documented since the Hugging Face incident: the vector is no longer a one-time prompt injection, but a fully autonomous agent framework. Two new points stand out here:

  • The stack is entirely open-source and publicly available. DeepSeek + Hermes Agent + Telegram as a C2 channel → no heavy infrastructure to set up, no paid APIs to monitor. The barrier to entry for an attacker has collapsed.
  • C2 via mainstream messaging. Using Telegram as the initial command channel complicates network detection: traffic is encrypted, highly common, and outgoing to shared Cloudflare/AWS IPs used by millions of legitimate users.

Also worth noting is what is not stated in the Unit 42 report (based on the excerpt): the actual offensive yield of the session—how many targets were compromised, which exploits succeeded—is not quantified here. What the publication demonstrates is operational feasibility, not yet scale.

Next Steps

  • Monitor scanning patterns from IPs hosting known LLM runtimes (public DeepSeek inference endpoints, identified cloud nodes).
  • Instrument internal agent frameworks (Hermes, LangChain, AutoGen…) with logging of outgoing network actions—any HTTP call from an agent must be justified by a ticket.
  • Add Telegram to the list of channels to correlate in C2 hunts when a workstation or server shows unusual port scanning.

Key Takeaways

The team highlights three things: (1) a single Telegram instruction is enough to launch a complete autonomous offensive chain; (2) the stack is 100% open-source and free (DeepSeek + Hermes Agent); (3) the attacker is tracked under aliases knaithe / KnYuan by Unit 42. The entry threshold for operating an offensive agent has just been drastically lowered.

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

18 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information