Autonomous Exploitation via DeepSeek AI and Hermes Agent Framework
A Chinese-speaking threat actor (KnYuan) executed a sophisticated cyber-espionage campaign against Thailand’s Ministry of Finance using the open-source Hermes Agent framework integrated with the DeepSeek LLM. The attack utilized a Telegram-based command-and-control (C2) channel to issue minimal instructions, which the AI agent then autonomously expanded into full-scale reconnaissance and exploit selection. Following successful compromise of internet-facing systems, the actor deployed the Hades malware implant to establish persistence and facilitate further intelligence gathering. This incident demonstrates a critical evolution in offensive operations where AI manages the exploitation lifecycle with minimal human oversight, effectively reducing the need for continuous operator interaction during the active exploitation phase.