A threat actor based in Zhuhai wired DeepSeek into an open-source agent framework called Hermes, then piloted the whole setup via Telegram to attack hundreds of internet-facing systems. Palo Alto Networks' Unit 42 published the analysis on August 2.

Here's what matters: it's not an edge case. The attacker wove together three off-the-shelf pieces, a frontier AI model, a published agent framework, and a messaging platform, into a working attack loop. DeepSeek enumerated targets, sourced public exploits from the open internet, and executed them. The Telegram interface let the operator steer in real time without touching a command line.

The scale is concrete. The actor hit 460+ systems across multiple victims. Unit 42 tied the campaign to a known Zhuhai-based group with a track record of targeting manufacturing and software companies in Asia-Pacific. This wasn't a proof-of-concept run in a lab. It was active, operational, and effective enough that Palo Alto documented and named it.

The interesting part is how little friction there was. Hermes is open source. DeepSeek is accessible. Telegram is free. The gap between "here's a capable AI model" and "here's a weaponized agent" compressed from weeks to days. A moderately skilled operator could replicate this setup without reverse-engineering anything. They could wire a different model in. They could change the target scope or the exploit selection logic. The framework stays the same.