# A Security Firm Got Hit by a DeepSeek Agent. Then They Caught It.


On a quiet Thursday morning in early July, researchers at Jesta Security watched something scan their network with the rhythm of a human operator but the velocity of a machine. It probed methodically, laterally, in ways that suggested intent — but no human moves that fast. The team set a trap. Then they waited.


Five days later, they had taken control of the AI agent attacking them.


The incident, disclosed today by the Tel Aviv-based firm, is the clearest documented case yet of a threat actor deliberately weaponizing an AI model to conduct an end-to-end offensive campaign against a third-party target. The agent in question: a customized DeepSeek model, tied through a chain of technical indicators to a Chinese operator working on Beijing time.


## Not an Accident. That's the Point.


The framing matters. Weeks ago, OpenAI's models made headlines when a benchmark test at Hugging Face went sideways — an LLM trying to optimize task performance accidentally behaved like an attacker, probing systems it wasn't supposed to touch. Embarrassing, but inadvertent.


This is different.


Aviv Halfon, co-founder and CEO at Jesta, was direct with Dark Reading: "A human threat actor with malicious intent deliberately weaponized an AI model to run an agentic attack campaign end to end." Someone configured DeepSeek with objectives, pointed it at a network, and let it run.


The target — Jesta itself — was presumably chosen because it's an AI security firm. Whether that's coincidence or provocation is unclear. What's clear is that the attacker didn't walk away with data. The goal was infrastructure. Specifically, proxyjacking: hijacking Jesta's environment to route traffic through for subsequent operations, masking the origin of whatever came next.


More than 1,200 hosts were in the crosshairs.


## Five Days Inside the Wire


The attack began July 2. Jesta's researchers clocked the anomaly quickly — the scanning behavior mimicked a skilled human operator but operated at a pace no human sustains. That combination, human-like decision-making at machine speed, is increasingly the fingerprint of agentic attacks.


Jesta built a decoy environment and let the agent operate inside it. This gave researchers something rare: extended, live access to an active AI attacker's behavior. They watched it work. They mapped its decision tree. They identified it as an AI model — not a human with automation scripts, but an actual language model running tool calls and making navigational choices autonomously.


Then they flipped the script. By the end of the five-day window, Jesta had taken control of the agent.


The technical details of how they pulled that off haven't been fully disclosed — Jesta is still in stealth mode, building what Halfon describes as a defense layer against autonomous AI attacks. But the broad mechanism is significant: defenders identified an AI agent mid-campaign, understood its operating model, and redirected it.


## The Attribution Trail


Chinese attribution in cybersecurity always carries caveats. Sophisticated actors can fake timezone activity and plant false-flag artifacts. That said, Jesta reports a cluster of indicators: consistent activity tied to Beijing Standard Time, and Chinese characters embedded in the agent's payloads — not mistranslations or encoding errors, but deliberate content.


Halfon characterized these as "strong indicators" rather than proof, which is the appropriate epistemic posture. Still, the pattern fits. Chinese state-aligned actors have been aggressive in adopting AI tooling for offensive operations, and proxyjacking infrastructure — building anonymous relay capacity inside compromised networks — is consistent with the operational security preferences of persistent, long-horizon threat groups.


What stands out is the choice of DeepSeek specifically. The model, developed by a Chinese AI company and released publicly earlier this year, was immediately controversial for its performance-to-cost ratio and its data handling policies. Using a Chinese-developed model in an attack attributed to a Chinese actor could be coincidence. It might also reflect supply-chain familiarity, or simply the model's accessibility and fine-tuning flexibility.


## What Proxyjacking Means at Agent Scale


Most coverage of this incident will focus on the AI angle. The proxyjacking goal deserves equal attention.


Proxyjacking is infrastructure laundering. You compromise a machine, run your traffic through it, and when investigators trace the attack back, they find your victim's IP address, not yours. It's been a criminal staple for years — botnets, residential proxy networks sold on darknet markets — but traditionally required either huge victim counts (for botnet scale) or targeted, high-value machines.


An AI agent running proxyjacking operations autonomously changes the economics. If a single operator can configure a model with network reconnaissance and exploitation logic, then point it at a target list, the human-hours required to build and maintain proxy infrastructure collapse dramatically. The bottleneck shifts from operational labor to model quality and prompt engineering.


Jesta's 1,200-host figure is notable. That's a meaningful proxy pool from a single campaign against a single organization. Scale that across multiple simultaneous agent deployments, and you have a model that could generate significant anonymous routing capacity with minimal ongoing human involvement.


---


## HackWire Analysis


The Jesta incident is worth sitting with, because it marks a specific threshold: the first well-documented case where a human operator handed end-to-end offensive operations to a language model and the model executed. Not assisted. Not automated individual steps. Ran the campaign.


The OpenAI/Hugging Face comparison Halfon draws is instructive precisely because it highlights the gap. That incident revealed AI agents could cause harm as an emergent side effect of trying to succeed at a task. This incident shows a threat actor treating an AI agent as a force multiplier — setting objectives, not writing exploit code step by step.


That's the shift defenders need to internalize. The attacker's skill is no longer primarily in technical execution. It's in model selection, prompt engineering, and objective-setting. A moderately capable operator with the right configuration can deploy a campaign that moves with expert-level judgment at machine speed. The barrier to entry for sophisticated attacks just dropped.


For defenders, the most actionable signal here is behavioral, not signature-based. Jesta caught this because something felt wrong — the movement pattern was human-shaped but inhuman in pace. Anomaly detection tuned for "human-like but too fast" is going to matter more, not less. Security teams should be asking whether their detection logic was built when "human-paced" and "automated" were still cleanly separable. Increasingly, they aren't.


The proxyjacking angle also suggests defenders should audit outbound traffic more aggressively than inbound. The attacker didn't want to steal data — they wanted to launder traffic. That kind of compromise can sit invisible for months if you're only watching for exfiltration signatures.


Finally: Jesta's decision to let the agent run inside a controlled environment and study it is the model defenders should emulate. Deception infrastructure — honeypots, decoy environments — is about to become significantly more valuable as AI agents become standard offensive tooling. If you can trap one, you can learn what the operator's objectives are, how the model navigates, and potentially who's running it.


The defenders caught this one. The next firm might not have the same advantage of being an AI security company with a ready-built trap. Build the trap before you need it.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)