Threat Actor Uses a DeepSeek-Powered Hermes Agent in Langflow and n8n Exploitation Attempts
- AI Infrastructure
- System Compromise & RCE
A Chinese-speaking threat actor operating as knaithe or KnYuan configured Hermes Agent to use DeepSeek as its reasoning engine. Hermes supplied terminal access, Telegram-based operator control, and a skills system containing both bundled and actor-created red-team skills. The actor also integrated an MCP server that exposed FOFA search, query translation, and Nuclei scan-generation capabilities. Unit 42 recovered a detailed Hermes Agent session dated May 7, 2026. The actor supplied an initial task through Telegram, but Unit 42 recovered no additional operator input during the session. The DeepSeek-powered Hermes Agent then autonomously searched for targets, obtained public exploits, ran scans, evaluated the results, and revised its approach. The agent initially targeted Langflow using a public exploit for CVE-2026-33017. After determining that available targets lacked the exploit's prerequisites, it abandoned that path, compared vulnerabilities across 10 product families, and selected n8n based on apparent severity, exposure, and exploitability. It then obtained a public exploit chain for CVE-2026-21858 and CVE-2025-68613 and probed candidate systems identified through FOFA. Although several systems appeared to run affected versions, the agent found that they lacked the required unauthenticated file-upload functionality. None of the autonomous exploitation attempts obtained access. Separate workspace evidence documented manual actor activity involving Citrix NetScaler data extraction, Marimo command execution, and reverse-shell attempts against Tomcat and IKE VPN systems. Unit 42 obtained this visibility after Hermes Agent responded to a Telegram command by starting an HTTP file server from the actor's home directory, `/home/worker`, instead of an isolated staging directory. This unintentionally exposed the actor's workspace, including AI tool configurations, API keys, exploit scripts, target lists, Bash history, and autonomous exploitation session logs.
Mapped threat techniques
AML.CS0070Threat Actor Uses a DeepSeek-Powered Hermes Agent in Langflow and n8n Exploitation AttemptsAML.T0016.002AML.T0016.002AML.T0016.001AML.T0016.001AML.T0016.004AML.T0016.004AML.T0017.002AML.T0017.002AML.T0040AML.T0040AML.T0117AML.T0117AML.T0102AML.T0102AML.T0116AML.T0116AML.T0000.003AML.T0000.003AML.T0016.003AML.T0016.003AML.T0006AML.T0006AML.T0049AML.T0049AML.T0095.000AML.T0095.000AML.T0000AML.T0000