Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Hackers Use Telegram for Autonomous Cyber Attacks

Chinese Hackers Use Telegram for Autonomous Cyber Attacks

Posted on July 31, 2026 By CWS

A recent report by Palo Alto Networks’ Unit 42 reveals how a Chinese-speaking hacker group used the DeepSeek tool via Telegram to conduct autonomous cyber attacks. The threat actors, identified by aliases knaithe and KnYuan, leveraged the open-source Hermes Agent framework to initiate attacks against over 460 targets.

Exploitation Techniques and Vulnerabilities

The cybercriminals, after receiving initial instructions through Telegram, targeted internet-facing systems using public exploit methods. Notably, these activities included seven distinct exploit tracks affecting eight Common Vulnerabilities and Exposures (CVE) identifiers. Despite their efforts, the attacks against Langflow and n8n were unsuccessful due to configuration mismatches in the targeted systems.

In parallel, manual hacking attempts resulted in data theft from three organizations by exploiting the NetScaler memory-overread flaw (CVE-2026-3055) and command execution vulnerabilities in Marimo instances (CVE-2026-39987). However, Unit 42 could only verify three successful breaches.

Operational Insights and Recommendations

Throughout the operation, the hackers employed a sophisticated approach, carefully selecting vulnerabilities based on their impact and potential for exploitation. They abandoned ineffective paths and switched tactics when necessary. Organizations are advised to promptly patch systems such as Langflow, n8n, and Marimo, and to secure NetScaler ADC or Gateway appliances configured as Security Assertion Markup Language (SAML) identity providers.

The Hermes Agent inadvertently exposed the hackers’ operations when it initiated an unintended HTTP server, revealing sensitive data like API keys and exploit scripts. This breach of operational security provided researchers valuable insights into the hacker’s methodologies.

Technological Tools and Geographical Links

DeepSeek was the primary tool used, providing capabilities such as terminal access and autonomous execution. Although there were signs of other coding tools like Claude Code and Qwen Code, their use could not be confirmed due to incomplete chat logs. A May 2026 session demonstrated DeepSeek downloading an exploit for a Langflow vulnerability, though the attack was halted due to security measures on the target system.

Unit 42 traces the hacker’s activity to Zhuhai, China, supported by online profiles and public documents. However, these sources do not definitively confirm the hacker’s identity or any official affiliations.

As cyber threats evolve, understanding the techniques and tools used by hackers is crucial for organizations to bolster their defenses and prevent future breaches. Continuous monitoring and timely software updates remain key strategies to mitigate such risks.

The Hacker News Tags:autonomous cyber attacks, Chinese hackers, CVE, Cybersecurity, DeepSeek, Hermes agent, Langflow, Marimo, n8n, NetScaler, Palo Alto Networks, Telegram attacks, Unit 42, Vulnerabilities

Post navigation

Previous Post: EU Strengthens AI Regulations Amid Global Concerns
Next Post: Anthropic’s AI Models Breach Security in Tests

Related Posts

Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts Worldwide Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts Worldwide The Hacker News
Identity Security Has an Automation Problem—And It’s Bigger Than You Think Identity Security Has an Automation Problem—And It’s Bigger Than You Think The Hacker News
EC-Council Boosts AI Workforce with New Certifications EC-Council Boosts AI Workforce with New Certifications The Hacker News
DRILLAPP Backdoor Exploits Microsoft Edge in Ukraine DRILLAPP Backdoor Exploits Microsoft Edge in Ukraine The Hacker News
Compromised Laravel-Lang Packages Spread Credential Stealer Compromised Laravel-Lang Packages Spread Credential Stealer The Hacker News
Critical PAN-OS Flaw Exploited for Root Access Critical PAN-OS Flaw Exploited for Root Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic’s AI Models Breach Security in Tests
  • Chinese Hackers Use Telegram for Autonomous Cyber Attacks
  • EU Strengthens AI Regulations Amid Global Concerns
  • Device Code Phishing: A Rapidly Escalating Threat in 2026
  • AI Powers Google to Patch Chrome Flaws Swiftly

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic’s AI Models Breach Security in Tests
  • Chinese Hackers Use Telegram for Autonomous Cyber Attacks
  • EU Strengthens AI Regulations Amid Global Concerns
  • Device Code Phishing: A Rapidly Escalating Threat in 2026
  • AI Powers Google to Patch Chrome Flaws Swiftly

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark