The real shift is that this campaign is no longer just about one exploited box. Defenders pulled session logs and configs out of the attacker’s own environment, and those records show a multi-LLM workflow that was built to enumerate targets, pull public exploit code, and pivot into proxyjacking across exposed services.
Unit 42 says the operator known as knaithe and KnYuan was using Hermes Agent with DeepSeek as the reasoning layer, plus other LLMs, to automate reconnaissance and exploit selection. The recovered material also shows targeting of Langflow and n8n, not just Citrix NetScaler, and one branch of the activity tried to turn the victim network into proxy infrastructure instead of stealing data.
That means patching the first compromised service is not the full response. The exposed automation stack and any internet-facing app the agent can find are part of the blast radius, and an AI agent with browser and action access can be used as an autonomous attacker rather than a helper.