Chinese hackers deploy open-source AI agents to automate espionage against Taiwan and Thailand

Chinese-speaking threat actors are now deploying open-source AI agents to automate espionage-grade hacking against government targets across Asia, according to coordinated disclosures from Hunt.io, Palo Alto Networks Unit 42, and the Financial Times. The campaign, active since at least June 2026, centers on Hermes, an open-source autonomous agent framework that crossed 140,000 GitHub stars by July. Operators run Hermes in "YOLO mode," a configuration that removes human approval prompts and lets

2 min
Chinese hackers deploy open-source AI agents to automate espionage against Taiwan and Thailand

Chinese-speaking threat actors are now deploying open-source AI agents to automate espionage-grade hacking against government targets across Asia, according to coordinated disclosures from Hunt.io, Palo Alto Networks Unit 42, and the Financial Times.

The campaign, active since at least June 2026, centers on Hermes, an open-source autonomous agent framework that crossed 140,000 GitHub stars by July. Operators run Hermes in "YOLO mode," a configuration that removes human approval prompts and lets the agent execute commands unattended.

Hunt.io captured three open directories on a Hong Kong staging server (43.246.208.207, AS132883 TOPIDC) between July 9 and 13. The directories contained 585 files and 470 MB of exploit code, stolen credentials, webshells, and Hermes output logs showing the agent enumerating Thailand's Ministry of Finance network, traversing files, and capturing LinPEAS output from adjacent hosts.

Hades implant and infrastructure

Custom Go implant Hades and C2 infrastructure

Unit 42 independently tracked a Chinese-speaking actor (aliases knaithe, KnYuan) using DeepSeek via the Hermes Agent framework, orchestrated through Telegram. The actor targeted seven vulnerabilities across Citrix NetScaler (CVE-2026-3055), Marimo notebooks (CVE-2026-39987), Apache Tomcat (CVE-2026-34486), and IKE VPN endpoints (CVE-2026-33824), achieving confirmed data exfiltration from three organizations and persistent access to a Malaysian government entity over multiple days.

The Financial Times reported that suspected Chinese hackers used open-source AI agents to build an autonomous hacking tool that compromised Taiwanese government websites in July, citing researchers who tied the activity to the same Hermes-driven tradecraft.

Unit 42: DeepSeek and Hermes Agent

The operational pattern is consistent: operators stage exploit code and AI agent logs on exposed directories, run Hermes in unattended mode for enumeration and initial exploitation, then deploy custom implants (Hades) for persistent access. The agent handles reconnaissance, vulnerability scanning, exploit chaining, and post-exploitation enumeration — tasks that previously required continuous human operators.

Financial Times: Taiwan compromise

Hermes, released February 2026, runs as a persistent daemon accumulating memory across sessions. Its YOLO mode explicitly disables approval gates. By July it ranked among the most widely deployed public agent frameworks.

Operational pattern

ThaiCERT and Thailand's National Cyber Security Agency were notified July 15. Taiwan's government has not publicly confirmed the FT-reported compromise.

Hermes framework

The shift marks a capabilities inflection point. Open-source agent frameworks now provide nation-state-aligned operators with force multiplication: one operator can direct autonomous enumeration and exploitation across multiple target networks simultaneously, with the agent rewriting failed exploits, building cloned login pages, and adapting to target environments in real time.

Notifications and attribution

Capability inflection point

Sources

- Hunt.io: Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged (https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent)

- Palo Alto Networks Unit 42: Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks (https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign)

- Financial Times: Researchers say suspected Chinese hackers used open-source AI agents to build an autonomous hacking tool that compromised Taiwanese government websites in July (Tom Wilson)

- The Hacker News: Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks (https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html)

- The Record: Taiwan government-backed research organization targeted by APT41 hackers (https://therecord.media/taiwan-government-backed-research-institution-apt41-hack)

Written by

More to read

  • Chunked and Fused Cross-Entropy: How Online Logit Tiling Slashes Large-Vocabulary VRAM Bottlenecks in LLM Training

    Chunked and Fused Cross-Entropy: How Online Logit Tiling Slashes Large-Vocabulary VRAM Bottlenecks in LLM Training As frontier large language models have scaled, tokenizer vocabularies have expanded substantially. Where early architectures such as LLaMA and Mistral relied on 32,000 subword tokens, contemporary models routinely employ vocabularies of 128,256 tokens (Llama 3), 152,064 tokens (Qwen 2.5), and 256,000 tokens (Gemma 2). Larger vocabularies compress text more densely, improve multilin

    1 min
  • Kakao Splits Into KakaoAI and KakaoX to Accelerate AI and Messenger Integration

    South Korean platform giant Kakao Corp. announced a corporate split that will separate its core operations into two independent publicly traded entities: KakaoAI and KakaoX. The restructuring, approved by Kakao's board of directors, aims to isolate and accelerate the company's artificial intelligence engineering and messaging ecosystem from its broader investment portfolio. Under the spin-off terms, existing shareholders will receive shares based on a net asset book value split ratio of 36% for

    1 min
  • US Warns 35 Partner Countries to Choose Between Pax Silica and China's WAICO AI Coalition

    The U.S. Department of State is preparing formal diplomatic notices instructing 35 partner nations to select between Washington's AI alliance and Beijing's competing framework. According to a draft cable reviewed by Reuters and reported by The Decoder and CNBC, the U.S. warns that countries joining China's newly established AI initiative will be excluded from the U.S.-led Pax Silica coalition. The diplomatic draft states: "To be part of everything is to be part of nothing. Signature of the Pax

    1 min