Friday, September 25, 2026

Chinese-Speaking Hackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Systems

Chinese-speaking threat operators have been observed using Claude, Qwen and DeepSeek-powered AI agents as operational components in a second intrusion campaign targeting government, political, education and industrial organizations across Asia.

The campaign is distinct from an earlier operation reported in July that used Claude Code and DeepSeek against government and financial-sector targets.

In this newer cluster, researchers linked infrastructure through a shared SOCKS proxy endpoint, 103.45.65[.]93:35888, which appeared in 120 file-content matches across five servers.

The shared artifacts included SecFlow configurations, GLUTTON webshell tooling, reused proxy credentials and a direct connection between a fake MySQL service and a payload-distribution host.

Targets included Taiwan’s Kuomintang Party History Archives, Indonesia’s Ministry of Foreign Affairs, government and education organizations in mainland China, and industrial systems in Da Nang, Vietnam.

The most severe confirmed breach affected a Fengtai District government Office Automation environment, where operators obtained Windows command execution, stole credential material and collected government and health-related records.

At the center of the campaign was SecFlow, an AI-agent orchestration framework that converted high-level objectives into specialist tasks.

Workers were assigned reconnaissance, vulnerability validation, exploitation, collection and reporting duties, while sharing a filesystem, target configurations, proxy routes and evidence generated by earlier tasks.

Recovered runtime settings showed operators could switch between Claude, Qwen and DeepSeek model profiles without changing the task interface.

Claude ACP and Qwen Code wrappers were configured with broad permissions, including bypass-permission settings and “yolo” approval modes.

Model traffic was routed through private endpoints under the niestools[.]com namespace as well as official provider APIs.

This model-swapping architecture matters because it separates the agent framework from the underlying model. An operator can retain the same attack workflow while changing providers, API routes or model capabilities.

The AI systems organized tasks and generated or adapted commands, but the underlying intrusions still depended on public proof-of-concept exploits, credential attacks, custom scripts, webshells and malware.

Researchers also found a significant operational weakness: a false-positive Shiro vulnerability claim was accepted by the AI workflow and propagated into more than 27 failed follow-up tests.

The Hunt.io Attack Report on the open directory 152.42.200[.]25:9999 assessed an actor primarily targeting Taiwanese and Indonesian government systems.

Hunt.io AttackCapture Analysis Report (Source : Hunt.io).
Hunt.io AttackCapture Analysis Report (Source : Hunt.io).

The incident highlights that autonomous or semi-autonomous offensive workflows can amplify flawed assumptions as efficiently as valid findings.

Hunt.io Researchers said that, the activity, uncovered through five exposed attacker workspaces, shows how AI orchestration can accelerate reconnaissance, exploitation, post-exploitation and reporting without replacing conventional offensive tooling.

AI-Powered Government Attacks

The Fengtai compromise progressed from an internet-facing Office Automation application to webshell deployment, Windows discovery, credential theft, database access and attempted lateral movement.

Pivoting on the shared SOCKS endpoint surfaces five open directories and a direct second-stage relationship between the fake MySQL server and the payload host  (Source : Hunt.io).
Pivoting on the shared SOCKS endpoint surfaces five open directories and a direct second-stage relationship between the fake MySQL server and the payload host (Source : Hunt.io).

Operators deployed ASPX command shells to execute Windows commands, enumerate processes and services, scan internal systems and interact with Oracle and Microsoft SQL Server services.

The attackers collected an LSASS memory dump along with SAM and SYSTEM registry hives, then downloaded the data in 37 chunks through web-accessible handlers.

They also extracted 822 OA account records and inserted a new privileged account, providing an application-layer persistence route independent of the deployed webshells.

The compromised environment contained approximately 949 attachments totaling 1.28 GB, including administrative documents, health-related files and a chronic-disease report with patient information.

AI-powered intrusions (Source : Hunt.io).
AI-powered intrusions (Source : Hunt.io).

A Go-based remote-access implant dubbed SecBox was subsequently staged through ASPX files.

The malware supports remote shell access, file transfers, port scanning, SOCKS proxying, port forwarding and dead-drop resolver mechanisms for updating command-and-control routes.

SecFlow workers were instructed to use GLUTTON, a webshell-generation capability supporting Java, .NET, Node.js and multiple server-side formats.

GLUTTON included options for obfuscation, randomized identifiers, encoded strings and steganographic delivery.

One recovered loader accepted PNG images containing executable payload data hidden in RGB pixel values.

The payload was XOR-decoded and loaded directly into memory, allowing attackers to disguise executable content as image traffic and reduce the effectiveness of extension- or MIME-based filtering.

The campaign also incorporated workflows for eight known vulnerabilities, including Shellshock, Ghostcat, Spring4Shell, Apache Shiro deserialization, Log4Shell, Grafana and Nexus path traversal flaws, and a Nacos authentication bypass.

Evidence showed active Shellshock payloads directed at the KMT party archive path, while an XOR-encrypted webshell client referenced an Indonesian Foreign Ministry endpoint.

The investigation attributes the infrastructure cluster to a Chinese-speaking operator with moderate confidence, citing Simplified Chinese artifacts, the recurring “Nie” handle, Chinese proxy-management services and the niestools[.]com model-routing infrastructure.

However, the available evidence does not justify attribution to a specific state-sponsored group.

The campaign demonstrates a developing reality for defenders: AI agents are increasingly being integrated into attacker workflows as force multipliers.

Security teams should prioritize exposure management, patching of internet-facing applications, monitoring for webshell behavior, proxy-aware logging and detection of anomalous image uploads or HTTP-based file transfer patterns.

IOCs

IndicatorRole
81.70.240[.]170Open directory containing the SecFlow workspace; AI execution host, SSH jump host, Layer 2 egress point, and out-of-band listener
43.99.61[.]170Open directory containing the Java/CAS exploitation workspace, GLUTTON tooling, and JNDI listener
152.42.200[.]25Open directory containing the Shellshock and credential-testing workspace and callback listener
129.211.184[.]149Open directory used as a payload-distribution, C2, and post-exploitation store

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

★ Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Salmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Systems

San Francisco, USA, September 25th, 2026, CyberNewswire Archipelo today announced...

14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape

A vulnerability in the Linux kernel’s AF_ALG cryptographic interface,...

ServiceNow Security Flaws Allow Attackers to Execute SQL and Modify Instance Data

ServiceNow has disclosed five vulnerabilities affecting its AI Platform,...

Rogue AI Agents Tried to Hack Public Websites After Data Retrieval Failed

Research from Transluce shows that autonomous AI agents shifted...

CISA Flags WSO2 Security Flaw Under Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

CISA Adds Multiple Check Point Product Flaws to Exploited Vulnerabilities List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Salesforce Agentforce Flaw Enables 0-Click Data Exfiltration via Prompt Injection

Security researchers have revealed a vulnerability chain known as...

Sudo Vulnerability Lets Attackers Bypass Time-Based Authorization Controls

A recently disclosed high-severity vulnerability in Sudo could allow...

Related Articles

Recent News