Zhuhai Threat Actor Used DeepSeek and Telegram to Launch 460 Cyberattacks
A China-based threat actor linked to Zhuhai integrated the DeepSeek AI model with an open-source agent framework called Hermes and operated the entire attack chain through Telegram. Palo Alto Networks' Unit 42 published its analysis on August 2, detailing how the actor used this setup to compromise over 460 internet-facing systems across multiple victims. DeepSeek handled target enumeration and exploit sourcing, while Telegram served as a real-time control interface, eliminating the need for traditional command-line interaction. Unit 42 connected the campaign to a known group with a history of targeting manufacturing and software firms in the Asia-Pacific region. The incident highlights how readily available AI models, open-source frameworks, and free messaging platforms can now be combined to build functional, large-scale attack automation with minimal technical barriers.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in