knaithe — APT Profile
knaithe is a Chinese speaking opportunistic exploit operator documented by Palo Alto Networks Unit 42 in July 2026, notable as one of the first publicly recorded cases of an end to end autonomous offensive campaign. The operator paired the open source Hermes Agent orchestration framework with DeepSeek as its reasoning engine, giving the agent terminal access, Telegram based command and control, and custom red team skills so it could select targets, source public exploit code and attempt intrusions with little human involvement. The autonomous runs achieved no confirmed compromises, but parallel manual operations by the same actor exfiltrated data from three organisations via a Citrix NetScaler flaw and executed commands on eleven exposed Marimo notebook instances. Unit 42 obtained unusually complete visibility after the agent exposed the operator workspace by serving an HTTP file server from the home directory.Also tracked as
KnYuan
IntelFusions coverage (1)
- A hacker let an AI agent pick and attack its own targets 2026-07-30 · AI Security
Tools & malware
- DeepSeek LLM reasoning engine (via api.deepseek[.]com)
- FOFA internet asset enumeration platform
- FofaMap-Platinum-Full-Expert MCP server
- godmode custom LLM jailbreaking skill
- Hermes Agent autonomous agent orchestration framework (open-source, NousResearch)
- Nuclei vulnerability scanner (public)
- web-terminal-exploitation custom exploitation skill
Vendor research
- Autonomous AI Cyber Attack Campaign: How One Actor Automated Exploitation Palo Alto Networks Unit 42