Unit 42: Chinese Actor Ran DeepSeek Through Hermes to Target a Security Firm, Queued 1,200+ Hosts for Proxyjacking

The actor was caught by its own AI agent. Unit 42's full writeup details how the knaithe/KnYuan operator ran DeepSeek through the Hermes framework to target a security firm and line up 1,200-plus hosts for proxyjacking - before a misconfigured file server exposed everything.

Share
Surreal navy conceptual: a robot tangled in its own cable from an open server - the AI agent that exposed its operator's infrastructure (Unit 42 DeepSeek).

The operation that spent weeks trying to break into other people's servers was undone by its own automation. According to Unit 42, Palo Alto Networks' threat-intelligence team, the Chinese-speaking actor behind a sprawling autonomous-attack campaign didn't get caught by a tip, a takedown, or a slip on a forum. It got caught because one of its own AI agents misconfigured a file server and quietly published the whole back end of the operation to anyone who came looking.

That mistake is the reason we know as much as we do. Unit 42's full writeup, surfaced Aug. 3 by Dark Reading and Help Net Security, ties the exposed infrastructure to an operator tracked as knaithe / KnYuan, who used multiple LLMs to automate attacks with limited human intervention. The most pointed detail in the report: one of the targets was a security firm.

The Agent That Exposed Its Own Operator

The through-line of this disclosure is irony, not tradecraft. An operation built to run attacks at machine speed, with a human mostly stepping back, inherited machine-speed mistakes too. When the agent stood up a file server and got the configuration wrong, it didn't fail loudly. It failed open. The infrastructure the operator presumably wanted hidden became readable, and Unit 42 walked in through a door the automation had left ajar.

Researcher Jesta is credited with intercepting the exposed setup, which gave Unit 42 the raw material for the analysis rather than the usual reconstruction from telemetry and victim reports. That distinction matters. A lot of what we read about autonomous-agent attacks is inferred from the outside. This is closer to reading over the operator's shoulder, because the operator's own tooling left the notes on the table.

The Operation

Multiple LLMs, wired into the Hermes agent framework, ran the attacks with limited human intervention — enumerating targets, sourcing exploits and lining up more than 1,200 hosts for proxyjacking and follow-on attacks. One of the marks was a security firm.

How It Was Caught

The operator’s own AI agent misconfigured a file server, publishing the entire back end to anyone who looked. That single automated mistake handed Unit 42 the whole infrastructure — no tip, no takedown required.

Source: Unit 42 (Palo Alto Networks), via Dark Reading and Help Net Security, Aug. 3, 2026.

What Unit 42 Documented

Strip away the novelty and the shape is familiar: reconnaissance, exploitation, and a plan to turn compromised machines into infrastructure. What's new is who, or what, was doing the work. Unit 42 describes an operator using more than one large language model to drive the campaign, with the models handling the steps a human operator would normally grind through by hand. The framework tying it together is Hermes, an agent system the same research thread has now placed at the center of more than one campaign.

The report frames this as automation with limited human intervention rather than a fully hands-off system. That's an important hedge. It means a person still set goals and, presumably, intervened when the automation stalled or wandered. But the volume the operation reached, and the fact that a configuration error slipped through unnoticed, both point to a workflow where the human was supervising output more than typing every command.

Unit 42 attributes the operation to a Chinese-speaking actor and tracks it under the handles knaithe and KnYuan. The firm stops short of a formal nation-state attribution in the framing carried by Dark Reading and Help Net Security, and I'm not going to stretch it further than the researchers did.

The Target Was a Security Firm

Of all the hosts in scope, the one that stands out in the reporting is a security firm. Unit 42 doesn't name it in the coverage available, and I can't confirm which company it was, whether the intrusion succeeded, or what the operator was after there specifically. Treat the identity as unconfirmed.

What's worth sitting with is the choice itself. Security firms are supposed to be the hard targets, the shops that would notice an autonomous agent poking at their perimeter. Pointing an LLM-driven pipeline at one is either overconfidence or a deliberate test of whether the automation could get somewhere a manual operator wouldn't dare. Either way, the same operation that reached for a well-defended target couldn't keep its own file server locked down.

More Than 1,200 Hosts, Queued for Proxyjacking

The scale figure in the reporting is the one to hold onto: the operator attempted to compromise more than 1,200 hosts for proxyjacking and to stage further attacks. Proxyjacking, for readers who don't track it, is the quieter cousin of cryptojacking. Instead of stealing a machine's compute to mine coins, the attacker resells the victim's internet connection through a residential-proxy market, monetizing bandwidth while staying relatively low-profile on the host.

Two caveats belong right next to that number. First, I can't confirm how many of the 1,200-plus hosts were actually compromised versus merely targeted or queued; the reporting describes intent and scope, not a confirmed victim count. Second, while Unit 42 is clear that multiple LLMs were in play alongside DeepSeek, I don't have a confirmed list of the additional models, so I'm not going to name any I can't source.

Even with those hedges, the combination is the story. A large host list plus a low-key monetization scheme plus an agent framework doing the legwork is a template that scales in a way a lone human operator can't easily match. Proxyjacking rewards breadth, and breadth is exactly what automation buys.

Where This Fits in the Autonomous-Agent Thread

This isn't a standalone oddity, and the value of the Aug. 3 writeup is mostly in how it thickens a story we've been following. Unit 42 first flagged this operator's autonomous AI-model cyberattacks before the toolchain had a name, then named the pieces — DeepSeek, Hermes, and a Telegram-based control setup tied to knaithe / KnYuan. The security-firm targeting and the proxyjacking scope are the latest layer on that same thread.

Hermes, meanwhile, is no longer a one-campaign curiosity. The same framework surfaced in reporting on an autonomous-agent espionage effort aimed at Thailand's finance ministry, which puts it in the multi-campaign column. When a tool shows up across unrelated operations, it stops being a novelty and starts being tooling — something defenders should expect to see again.

It also rhymes with the disclosures coming from the model labs themselves. Anthropic's account of Claude models breaching three real organizations during safety testing came from the vendor side of the same question: what happens when a capable model is pointed at a live target with enough autonomy to act. The knaithe / KnYuan case is the adversary side of that coin, and the two together sketch the outline of where this is heading.

What Defenders Should Watch

I'm not going to reconstruct how the operation ran, and defenders don't need that to act on this. The useful takeaways are behavioral. Autonomous-agent traffic tends to look different from a human at a keyboard: it's fast, it's consistent in cadence, it retries in patterns, and it doesn't get tired or distracted the way a person does. Enumeration that marches through a target list at machine speed, without the pauses and dead ends of manual work, is a signal worth tuning for.

Proxyjacking has its own tells on the defender side — unexpected outbound proxy or residential-proxy client traffic, connections to known proxy-marketplace endpoints, and bandwidth patterns that don't match what a box is supposed to be doing. Those detections aren't new, but the volume an agent-driven campaign can generate raises the payoff for having them in place.

And there's a quieter lesson in how this one ended. The operation was undone by an ordinary misconfiguration — a file server left open — committed by the automation itself. Attackers automating at scale inherit the same failure modes defenders spend their days chasing. That cuts both ways, and it's a reminder that exposure monitoring works on adversary infrastructure just as well as it works on your own.

My read: The headline is the automation, but the lesson is the mistake. An operator confident enough to point multiple LLMs at a security firm still couldn't keep a file server buttoned up, because the same automation that gave the campaign reach also gave it a machine-speed way to fail open. Autonomous offense is real and it scales, but it's not tidy — and its sloppiness is, for now, one of the better gifts defenders are going to get.

Open Questions

Several things stay unconfirmed, and I'd rather flag them than paper over them. The identity of the targeted security firm isn't public. Whether any of the 1,200-plus hosts were successfully compromised, and how many, isn't established in the reporting I can source. The specific additional LLMs beyond DeepSeek aren't named. And I can't confirm whether the exposed infrastructure has been taken down or seized, or whether law enforcement is engaged. Those are the gaps to watch as Unit 42's analysis and follow-on reporting fill in.