Except LLMs haven't show themselves capable of that at all, they have no agency, they just generate output based on their input Ina somewhat chaotic manner.
Tools have been built that basically chain LLM output into input and given some starting directions get the LLM to generate commands that can be ran on the local machine including commands to run commands on other machines. Because various conversations on exploits and hacking and sample code are in its training corpus it will generate commands to do these things. Not because the LLM or the agent program is smart in anyway but I fact because it's dumb as bricks and has no concept of what it's doing or the consequences might be.
Ultimately a human has used it as a tool to achieve the hacking. It's might not be the intended achievement but that is on the human running a process with chaotic output with sufficient privileges with no oversight.