A Chinese-speaking threat actor is using the DeepSeek large language model in tandem with the open-source Hermes Agent framework to conduct multi-stage cyberattacks against exposed servers with minimal human oversight, as detailed by BleepingComputer. This campaign is notable for its reliance on AI for both strategic planning and operational execution, reducing the constant need for manual operator input.
The attack chain moves beyond static scripts by combining DeepSeek's adaptive reasoning with Hermes Agent's capacity for direct system interaction. The AI model assesses target environments, formulates tactics, and adjusts its approach upon failure, while the agent translates these decisions into concrete actions like tool use and lateral movement. This creates an automated workflow capable of executing complex intrusion sequences that would be difficult for a single human operator to manage at scale.
The process isn't fully autonomous, however. Human operators establish objectives, review results, and intervene when the AI faces insurmountable challenges. This "human-in-the-loop" model maintains attacker control while offloading the repetitive, tactical decision-making to the AI stack. Security researchers highlight that this hybrid approach significantly lowers the technical skill barrier for launching sophisticated, multi-part operations.
The campaigns primarily target servers with evident security gaps, such as unpatched systems, vulnerable web applications, and services secured only by weak or reused credentials. After initial compromise, the automated components can persist, conducting reconnaissance, privilege escalation, and further exploitation with little additional direction. The Akamai research team has documented specific indicators of compromise related to Hermes Agent activity—including anomalous process chains and network connections—and has released detection tools like YARA rules to aid defenders.
For the security community, this event demonstrates how readily available AI models and offensive agent frameworks can accelerate attack automation. Open-source tools built for legitimate automation can be repurposed, and accessible LLMs reduce the expertise previously needed for adaptive intrusions. Defenders should view this as an evolution of existing attack automation that compresses the timeline from breach to deep compromise, rather than a wholly new threat category.
The most effective defenses are grounded in cybersecurity fundamentals. Organizations should prioritize prompt patching for all internet-facing assets, especially edge devices; enforce strong, unique passwords with mandatory multi-factor authentication; shut down unnecessary services and ports; and deploy behavioral monitoring to detect process and network anomalies indicative of agent-driven activity. Utilizing the publicly available YARA rules for Hermes Agent can further enhance detection capabilities.
While this particular operation has been observed in the field, the underlying pattern—leveraging general-purpose AI for attack logic alongside executable agent frameworks under light supervision—is likely to see wider adoption. Continued tracking of how these toolchains are applied to new vulnerabilities will be crucial. For now, disciplined basics like patching, credential hygiene, attack-surface reduction, and behavior-based detection remain the strongest practical defense against this emerging class of AI-assisted intrusions.
根據 BleepingComputer 的詳細報導,一個以中文為母語的威脅行為者正利用 DeepSeek 大型語言模型,結合開源 Hermes Agent 框架,對暴露的伺服器進行多階段網絡攻擊,且僅需極少的人為監督。這項行動的特點在於依賴 AI 進行戰略規劃與操作執行,大幅減少了持續性的人工操作干預需求。
該攻擊鏈超越了靜態腳本的限制,將 DeepSeek 的適應性推理與 Hermes Agent 直接與系統互動的能力相結合。AI 模型評估目標環境、制定策略,並在失敗時調整方法;而代理框架則將這些決策轉化為具體行動,例如工具使用與橫向移動。這創造了一種自動化工作流程,能夠執行複雜的入侵序列,這些序列若由單一人工操作員大規模管理將難以實現。
然而,整個過程並非完全自動化。人為操作員負責設定目標、審查結果,並在 AI 遇到無法克服的挑戰時介入干預。這種「人機協作模式」維持了攻擊者的控制權,同時將重複性、戰術性的決策工作轉交給 AI 系統處理。安全研究人員強調,這種混合方法顯著降低了發動複雜、多部分行動的技術門檻。
此類行動主要針對存在明顯安全漏洞的伺服器,例如未修補的系統、易受攻擊的網路應用程式,以及僅使用薄弱或重複密碼保護的服務。在初始入侵後,自動化組件可以持續進行偵察、權限提升和進一步利用,幾乎無需額外指示。Akamai 研究團隊已記錄了與 Hermes Agent 活動相關的具體入侵指標——包括異常的程序鏈和網絡連接——並發布了 YARA 規則等偵測工具以協助防禦者。
對安全社群而言,此事件展示了現成的 AI 模型和攻擊性代理框架如何能加速攻擊自動化。為合法自動化構建的開源工具可能被重新利用,而易於取得的大型語言模型則降低了先前進行適應性入侵所需的專業知識。防禦者應將其視為現有攻擊自動化的演進,壓縮了從入侵到深度破壞的時間表,而非一個全新的威脅類別。
最有效的防禦措施植基於網絡安全基礎原則。組織應優先為所有面向互聯網的資產(尤其是邊緣設備)進行即時修補;強制使用強大且獨特的密碼,並實行多因素認證;關閉不必要的服務和端口;並部署行為監控以偵測可能指示代理驅動活動的程序和網絡異常。利用公開可用的 Hermes Agent YARA 規則可進一步增強偵測能力。
雖然此特定操作已在實務中被觀察到,但其基本模式——利用通用 AI 作為攻擊邏輯,結合可執行的代理框架並在輕度監督下運作——很可能會被更廣泛採用。持續追蹤這些工具鏈如何應用於新漏洞將至關重要。目前而言,嚴格的基礎措施,如修補、憑證管理、攻擊面縮減和基於行為的偵測,仍是對抗這類新興 AI 輔助入侵最強大的實際防禦手段。
