Autonomous AI Cyber Campaign Attributed to $11.40 in API Calls and a Telegram Group Chat
SAN FRANCISCO— The autonomous AI cyberattack that the security industry has spent years and roughly $14 billion preparing for arrived in Q2 2026 as a Telegram bot running a three-cent language model, according to a threat-intelligence report published Thursday by Palo Alto Networks Unit 42.
The campaign, attributed to a Zhuhai-based actor identified as 'knaithe,' wired DeepSeek V4-Flash into the open-source Hermes Agent framework and directed it, over Telegram, to enumerate targets, pull public exploits from GitHub, and attack more than 460 internet-facing systems — compromising three Citrix NetScaler installations and 11 Marimo notebook instances at a total operational cost analysts estimate at $11.40.
The disclosure has prompted significant internal revision across the cybersecurity sector, where threat-modeling frameworks had assumed the AI attacker would arrive better funded. "Our entire response playbook was calibrated for a system that cost what our products cost," said one senior threat researcher, who asked not to be named. Vendors with AI threat-detection platforms priced between $200,000 and $1.4M annually confirmed their systems performed as designed. "Ours elevated the incident to Tier 2 review within four hours," said one provider, "where it remains actively prioritized."
The 460 targets were identified, assessed, and attacked with, Unit 42 reported, "minimal human follow-up." Several targeted organizations paid more than $11.40 for the alert notifying them they had been compromised.
The industry is preparing revised threat intelligence reports for Q3. Early drafts describe the emerging AI threat actor as "motivated, low-cost, and agnostic to whether your vendor attends RSA."