Chinese‑Speaking Threat Actor Deploys AI‑Driven Autonomous Attack Campaign Targeting Seven Known Vulnerabilities
What Happened — Unit 42 uncovered a campaign in which a Chinese‑speaking actor used large language models (DeepSeek, Qwen, GLM, Kimi, MiniMax, etc.) via a custom “Hermes Agent” to automatically enumerate internet‑exposed assets, locate seven high‑severity CVEs, and launch exploits with little to no human interaction.
Why It Matters for Compliance & Audit Readiness
- Autonomous exploitation sidesteps manual detection checkpoints, underscoring the SOC 2 requirement for continuous, automated control monitoring of vulnerability‑management processes.
- Mapping this AI‑driven workflow to SOC 2 Trust Services Criteria creates defensible, audit‑ready evidence that emerging threat vectors are being identified, assessed, and mitigated.
- Verisq’s Control‑Mapping capability can automatically correlate AI‑generated alerts with the relevant SOC 2 controls, delivering continuous evidence for auditors.
Who Is Affected — Cloud‑infrastructure providers, SaaS platforms, and any organization exposing internet‑facing services.
Recommended Actions —
- Integrate AI‑generated threat‑intel feeds into your vulnerability‑management program.
- Align the new attack steps with SOC 2 CC6.1 (Risk Management) and CC7.1 (Vulnerability Management) controls, and capture continuous remediation evidence.
- Deploy automated monitoring that logs enumeration and exploit attempts as immutable audit records. Source: https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
Technical Notes — The Hermes Agent used Telegram for C2, FOFA for target discovery, and scraped GitHub PoCs to prioritize seven CVEs (specific IDs not disclosed). The vector combined LLM‑generated code with traditional exploit tools. Source: https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/