Chinese-Speaking Threat Actor Used DeepSeek LLMs via Hermes Agent for Autonomous Attack Campaign
Unit 42 reports a Chinese speaking threat actor operating under aliases knaithe and KnYuan configured DeepSeek LLMs via the Hermes Agent open source agent fram…
Published on MyPrivateClaw
Jul 31, 2026, 4:10 PM UTC
Coverage date
Jul 31, 2026
Last updated
Jul 31, 2026, 4:10 PM UTC
News summary
The actor configured the Hermes Agent with three red teaming skills including a godmode jailbreaking skill and integrated the FofaMap MCP server for internet asset enumeration, while also evaluating Qwen, GLM, Kimi, MiniMax LLMs plus limited Claude Code and Codex usage. The Hermes Agent autonomously identified and attempted exploitation of CVE 2026 33017 against Langflow instances and CVE 2026 21858/CVE 2025 68613 against n8n Workflow Automation targets, but all autonomous attempts failed due to missing auto login configuration or authentication requirements. Manual campaigns achieved confirmed impact including data exfiltration from three organizations via CVE 2026 3055 and command execution on 11 Marimo instances via CVE 2026 39987. The Hermes Agent inadvertently exposed its full operational environment by starting an HTTP file server on port 8888 from the actor's home directory, reve…