Researchers intercepted and investigated the model, which was attempting to compromise more than 1,200 hosts for proxyjacking to launch further attacks.
August 3, 2026
A DeepSeek AI agent attacked the network of a cybersecurity firm as part of a proxyjacking campaign, spurring the firm to set a trap and take control of the agent.
The attack, observed and then intercepted by Tel Aviv-based AI cybersecurity firm Jesta Security, marks the the latest example of AI agents attacking third-party networks in recent weeks, according to a report published today. But in contrast to the OpenAI model attack on Hugging Face during a benchmark test — the inadvertent result of the large language model (LLM) trying to find the best way to solve a problem — this attack was intentional, Aviv Halfon, co-founder and CEO at Jesta, tells Dark Reading.
"A human threat actor with malicious intent deliberately weaponized an AI model to run an agentic attack campaign end to end," he says. However, the goal wasn't to steal, encrypt, or modify anything on the system, but to build infrastructure for more attacks. "The attacker was using our compromised environment to stage its next operations," Halfon says.









