A Hacker Pointed DeepSeek at the Internet and Told It to Attack. It Did.

A threat actor connected DeepSeek to an AI agent framework, gave it a single instruction, and the AI autonomously researched vulnerabilities, selected targets, and launched attacks across 647,000 servers.

In July, we wrote about a hacker who used Google’s Gemini CLI to operate a botnet in six minutes. That story showed how AI could assist a criminal, handling the grunt work while the human stayed in control.

This one is different. This time, the human stepped back and the AI did everything on its own.

What happened

Palo Alto Networks’ Unit 42 published findings on July 31 documenting a Chinese-speaking threat actor who connected DeepSeek, an open-source AI model, to an agent framework called Hermes. Hermes can interact with operating system terminals, run commands, browse the internet, and execute multi-step tasks without waiting for human approval.

The attacker gave the system a task. What happened next was autonomous.

The AI started by searching for vulnerable servers running Langflow, an AI workflow platform. It downloaded a public proof-of-concept exploit, queried an internet asset search engine called FOFA, and identified 84 exposed instances. It scanned them, determined they couldn’t be exploited with the available tools, and moved on.

Without being told to pivot, the AI started researching other vulnerabilities. It analyzed multiple public exploit repositories, selected n8n (a workflow automation platform) as a better target, and found over 647,000 exposed instances through FOFA. It downloaded a different exploit, identified servers running vulnerable versions, and started checking them for the specific conditions needed to complete the attack.

The attacks failed. The servers required authentication that the AI couldn’t bypass. But that’s almost beside the point.

Why this is different from the Gemini botnet

The Gemini CLI botnet was AI-assisted. A person told the AI what to do. The AI executed instructions, proposed improvements, and handled routine operations. But the human was always directing: study this, migrate that, list what’s online.

The DeepSeek campaign was AI-autonomous. Unit 42 recovered a May 2026 session where the operator provided only an initial task. Everything after that, the target selection, the vulnerability research, the exploit download, the pivot to a different platform when the first one didn’t work, happened without human feedback.

Unit 42’s assessment: “This autonomous process of target identification, sampling and narrowing of scope executed hundreds of hours of manual targeting analysis in mere minutes.”

That’s the shift. A single person with an AI agent now has the targeting capacity of an entire team, and the agent works faster than any human analyst could.

The manual attacks worked

The AI agent’s autonomous attempts failed. But the same threat actor also conducted manual attacks against more than 460 systems. Unit 42 confirmed three successful compromises targeting Citrix NetScaler servers, where the attacker extracted memory and searched for authentication cookies to hijack sessions.

The attacker had also configured Qwen, Claude Code, OpenAI Codex, and several other AI platforms, though Unit 42 found they weren’t used as heavily as DeepSeek.

This person was running AI agents alongside traditional manual attacks. The AI handled the scale (scanning hundreds of thousands of targets in minutes). The human handled the complexity (exploiting the three systems the AI couldn’t crack). That combination is what makes this dangerous.

What this means for your firm

Your firm isn’t running Langflow or n8n. But you are running systems that face the internet: VPN gateways, email servers, web portals, remote access tools, cloud applications. The same scanning and exploitation workflow that targeted 647,000 n8n instances can target whatever your firm exposes.

The timeline has compressed. What used to require a team of attackers spending days on reconnaissance can now be done by a single person with an AI agent in an afternoon. The attacks are less skilled individually, but there are vastly more of them, and they run around the clock.

Three things matter more than they did six months ago:

Patching speed. When an exploit goes public, AI agents can download it and start scanning within minutes. The Certighost AD CS exploit we covered in July went from patch to public proof-of-concept in 13 days. Clients that hadn’t applied the July Patch Tuesday fixes were exposed to an automated domain compromise attack. Every week of patch delay is now a week where AI-powered scanning is looking for exactly your gap.

Attack surface awareness. Do you know what your firm exposes to the internet? Every portal, every remote access tool, every cloud application with a login page is something an AI agent can find and probe. If your IT provider can’t give you a current inventory of internet-facing services, that’s a gap worth closing.

Monitoring and response speed. AI-powered attacks don’t happen during business hours and wait for your team to notice on Monday. They run continuously. Detection and response capabilities need to match that pace. If your firm relies on someone checking logs once a day, the math doesn’t work anymore.

The tools your firm uses to be more productive are the same architecture attackers use to be more productive. The difference is who’s pointing them and what boundaries are in place.

If your firm wants to understand what it currently exposes to the internet and whether your patching and monitoring are keeping pace, that’s a conversation worth having.