Chinese hackers deploy open-source AI agents to automate espionage against Taiwan and Thailand

Chinese-speaking threat actors are now deploying open-source AI agents to automate espionage-grade hacking against government targets across Asia, according to coordinated disclosures from Hunt.io, Palo Alto Networks Unit 42, and the Financial Times. The campaign, active since at least June 2026, centers on Hermes, an open-source autonomous agent framework that crossed 140,000 GitHub stars by July. Operators run Hermes in "YOLO mode," a configuration that removes human approval prompts and lets

2 min
Chinese hackers deploy open-source AI agents to automate espionage against Taiwan and Thailand

Chinese-speaking threat actors are now deploying open-source AI agents to automate espionage-grade hacking against government targets across Asia, according to coordinated disclosures from Hunt.io, Palo Alto Networks Unit 42, and the Financial Times.

The campaign, active since at least June 2026, centers on Hermes, an open-source autonomous agent framework that crossed 140,000 GitHub stars by July. Operators run Hermes in "YOLO mode," a configuration that removes human approval prompts and lets the agent execute commands unattended.

Hunt.io captured three open directories on a Hong Kong staging server (43.246.208.207, AS132883 TOPIDC) between July 9 and 13. The directories contained 585 files and 470 MB of exploit code, stolen credentials, webshells, and Hermes output logs showing the agent enumerating Thailand's Ministry of Finance network, traversing files, and capturing LinPEAS output from adjacent hosts.

Hades implant and infrastructure

Custom Go implant Hades and C2 infrastructure

Unit 42 independently tracked a Chinese-speaking actor (aliases knaithe, KnYuan) using DeepSeek via the Hermes Agent framework, orchestrated through Telegram. The actor targeted seven vulnerabilities across Citrix NetScaler (CVE-2026-3055), Marimo notebooks (CVE-2026-39987), Apache Tomcat (CVE-2026-34486), and IKE VPN endpoints (CVE-2026-33824), achieving confirmed data exfiltration from three organizations and persistent access to a Malaysian government entity over multiple days.

The Financial Times reported that suspected Chinese hackers used open-source AI agents to build an autonomous hacking tool that compromised Taiwanese government websites in July, citing researchers who tied the activity to the same Hermes-driven tradecraft.

Unit 42: DeepSeek and Hermes Agent

The operational pattern is consistent: operators stage exploit code and AI agent logs on exposed directories, run Hermes in unattended mode for enumeration and initial exploitation, then deploy custom implants (Hades) for persistent access. The agent handles reconnaissance, vulnerability scanning, exploit chaining, and post-exploitation enumeration — tasks that previously required continuous human operators.

Financial Times: Taiwan compromise

Hermes, released February 2026, runs as a persistent daemon accumulating memory across sessions. Its YOLO mode explicitly disables approval gates. By July it ranked among the most widely deployed public agent frameworks.

Operational pattern

ThaiCERT and Thailand's National Cyber Security Agency were notified July 15. Taiwan's government has not publicly confirmed the FT-reported compromise.

Hermes framework

The shift marks a capabilities inflection point. Open-source agent frameworks now provide nation-state-aligned operators with force multiplication: one operator can direct autonomous enumeration and exploitation across multiple target networks simultaneously, with the agent rewriting failed exploits, building cloned login pages, and adapting to target environments in real time.

Notifications and attribution

Capability inflection point

Sources

- Hunt.io: Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged (https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent)

- Palo Alto Networks Unit 42: Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks (https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign)

- Financial Times: Researchers say suspected Chinese hackers used open-source AI agents to build an autonomous hacking tool that compromised Taiwanese government websites in July (Tom Wilson)

- The Hacker News: Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks (https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html)

- The Record: Taiwan government-backed research organization targeted by APT41 hackers (https://therecord.media/taiwan-government-backed-research-institution-apt41-hack)

Written by

More to read

  • Anthropic Demonstrates Autonomous De Novo Protein Design and Chemical Analysis with Claude

    Anthropic Demonstrates Autonomous De Novo Protein Design and Chemical Analysis with Claude Anthropic has published experimental results demonstrating Claude's ability to autonomously design de novo protein binders with physical wet-lab validation and automate complex analytical chemistry workflows. The findings show frontier LLMs acting as autonomous agents across computational biology and molecular characterization pipelines. In the primary experiment, Anthropic evaluated Claude Mythos Previe

    1 min
  • Cerebras Unveils CS-4 Rack-Scale System Powered by Three WSE-3 Turbo Chips and Nexus Architecture

    Cerebras Unveils CS-4 Rack-Scale System Powered by Three WSE-3 Turbo Chips and Nexus Architecture Cerebras Systems has announced the CS-4, a rack-scale AI accelerator system designed around three of its next-generation Wafer Scale Engine 3 Turbo (WSE-3 Turbo) chips and a modular hardware architecture dubbed Nexus. Cerebras confirmed that initial customer shipments for the CS-4 are scheduled to begin in the current quarter. The new system marks a structural shift from Cerebras's single-wafer CS

    1 min
  • AI FinOps: Cutting LLM Inference Costs by 30-60% Through Model Tiering, Caching, and GPU Optimization

    AI FinOps: Cutting LLM Inference Costs by 30-60% Through Model Tiering, Caching, and GPU Optimization Inference costs have become the second-largest line item in enterprise AI budgets, trailing only talent spend according to RapidData's State of Enterprise AI 2026. This shift represents a fundamental inversion from the 2021-2023 era when training dominated AI expenditure. The compounding nature of serving costs—accumulating every hour as long as users hit the API—means that even modest producti

    1 min