Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia
Campaign
Summary
Hide ▲
Show ▼
The knaithe / KnYuan campaign used LLMs and Hermes Agent over Telegram to automate enumeration and exploitation against internet-exposed infrastructure in Asia, increasing the speed and scale of attacks across China and Malaysia. The operator blended autonomous AI-driven scanning with manual exploitation and tested multiple models, including Qwen, GLM, Kimi, MiniMax, Claude Code, and OpenAI Codex. The run touched 10 product families and pivoted to seven CVEs, including CVE-2026-3055 and CVE-2026-39987. Impact stayed limited, with no full compromise of intended targets, but the workflow shows a reusable AI-assisted intrusion pattern.
Related Happenings
Trim ecosystem shift changes threat-actor operations
Threat Actor Meta
H score22
First: 21.07.2026 17:00
Last: 21.07.2026 17:00
Sources 1
About this happening:
Trim shifted from publishing Claude Opus jailbreak techniques to selling AI Pentest Checker, accelerating the commercialization of jailbreak-based offensive tooling. T...
Trim ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: Trim shifted from publishing Claude Opus jailbreak techniques to selling AI Pentest Checker, accelerating the commercialization of jailbreak-based offensive tooling. T...
CL-STA-1062 Southeast Asia critical infrastructure campaign using TinyRCT
Campaign
H score18
First: 26.06.2026 13:30
Last: 26.06.2026 13:30
Sources 1
About this happening:
A China-linked campaign by CL-STA-1062 is targeting government entities and critical infrastructure across Southeast Asia, with activity reaching state-owned...
CL-STA-1062 Southeast Asia critical infrastructure campaign using TinyRCT
CampaignAbout this happening: A China-linked campaign by CL-STA-1062 is targeting government entities and critical infrastructure across Southeast Asia, with activity reaching state-owned...
GREYVIBE's Kremlin-aligned role in the Russian cybercrime ecosystem
Threat Actor Meta
H score15
First: 29.05.2026 14:31
Last: 29.05.2026 14:31
Sources 1
About this happening:
A newly characterized GREYVIBE actor sits in a grey zone between Kremlin-aligned intelligence work and the Russian cybercrime ecosystem, complicating attribution f...
GREYVIBE's Kremlin-aligned role in the Russian cybercrime ecosystem
Threat Actor MetaAbout this happening: A newly characterized GREYVIBE actor sits in a grey zone between Kremlin-aligned intelligence work and the Russian cybercrime ecosystem, complicating attribution f...
Shadow-Aether-040 AI-augmented campaign against Mexican government entities
Campaign
H score41
First: 13.05.2026 16:00
Last: 13.05.2026 16:00
Sources 1
About this happening:
The Shadow-Aether-040 campaign used AI agents and custom tooling to compromise six government entities in Mexico, increasing the risk of follow-on intrusion and data...
Shadow-Aether-040 AI-augmented campaign against Mexican government entities
CampaignAbout this happening: The Shadow-Aether-040 campaign used AI agents and custom tooling to compromise six government entities in Mexico, increasing the risk of follow-on intrusion and data...
Google GTIG analysis of adversary AI use for exploit development and attack orchestration
Technical Analysis
H score33
First: 11.05.2026 16:00
Last: 11.05.2026 16:00
Sources 1
About this happening:
Google Threat Intelligence Group published findings showing adversaries using AI for exploit development and attack orchestration, signaling that model-assisted tr...
Google GTIG analysis of adversary AI use for exploit development and attack orchestration
Technical AnalysisAbout this happening: Google Threat Intelligence Group published findings showing adversaries using AI for exploit development and attack orchestration, signaling that model-assisted tr...
Timeline
-
30.07.2026 03:00 2 articles · 2d ago
Unit 42 details AI-orchestrated exploitation against exposed infrastructure in Asia
Initial DisclosureUnit 42 reported that a Chinese-speaking operator using the aliases knaithe and KnYuan, based in Zhuhai, China, used Hermes Agent with a DeepSeek AI model and other LLMs over Telegram to orchestrate exploitation against internet-exposed infrastructure in Asia. The workflow combined autonomous AI-driven enumeration and automated exploitation with manual exploitation, scanned 10 product families, pivoted to seven CVEs including CVE-2026-3055, CVE-2026-39987, and CVE-2026-33824, and showed limited impact without full compromise of intended targets in China and Malaysia.
Show sources
- Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits — www.infosecurity-magazine.com — 31.07.2026 18:00
- Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits — www.infosecurity-magazine.com — 31.07.2026 18:00