A Threat Actor Used DeepSeek to Orchestrate 460 Attacks via Telegram
TL;DR AI
2 min readKey summary
Palo Alto Networks Unit 42 said a Zhuhai-based threat actor linked DeepSeek with the open-source Hermes agent framework and Telegram to automate attacks against more than 460 internet-facing systems.
The actor used Telegram as a control channel to find targets, gather public exploits, and launch intrusions.
The case highlights how accessible AI models, open-source tooling, and messaging apps can be fused into a low-friction attack pipeline.
That combination could lower the barrier to automated exploitation, making future campaigns faster and harder to trace.
