ShellCodeX Intelligence Brief
HIGH
Cybersecurity
Chinese actor used DeepSeek via Telegram to automate exploit selection
Source headline: Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Threat level
High
Signal strength
70/100
Source confidence
1 source
Published
2 hours ago
Intelligence Summary
Unit 42 reports a Chinese-speaking threat actor used DeepSeek through the Hermes Agent framework. The workflow began with a Telegram instruction to the agent. After that, the agent autonomously scanned for internet-facing systems and chose public exploits to run. Researchers did not find evidence of further operator input during the session. Organizations exposed services on the internet should review for unusual scanning and exploit activity.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.
Topics
Original reporting
The Hacker News
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Open original source