A Chinese LLM attacked our lab, so we made it work for us
3 hours ago
- Jesta Security detected the first live LLM-managed cyber attack campaign, lasting five days and using 871 sessions.
- The exact model behind the attack was identified as deepseek-v4-flash-free (DeepSeek V4 Flash free tier) from inside the intrusion.
- Researchers took control of the AI agent, extracting its target list and operational details.
- The goal was proxyjacking: installing SOCKS5 proxies to create a network of base stations for further attacks.
- Over 1,000 victims were identified, with the actual number likely higher.
- The AI displayed human-like behavior (iterating commands) and super-human speed, including hallucination and retry loops.
- The attack highlights the rise of autonomous AI cyber threats requiring new defense approaches.