Chinese-speaking threat operators have been observed using Claude, Qwen and DeepSeek-powered AI agents as operational components in a second intrusion campaign targeting government, political, education and industrial organizations across Asia.
The campaign is distinct from an earlier operation reported in July that used Claude Code and DeepSeek against government and financial-sector targets.
In this newer cluster, researchers linked infrastructure through a shared SOCKS proxy endpoint, 103.45.65[.]93:35888, which appeared in 120 file-content matches across five servers.
The shared artifacts included SecFlow configurations, GLUTTON webshell tooling, reused proxy credentials and a direct connection between a fake MySQL service and a payload-distribution host.
Targets included Taiwan’s Kuomintang Party History Archives, Indonesia’s Ministry of Foreign Affairs, government and education organizations in mainland China, and industrial systems in Da Nang, Vietnam.
The most severe confirmed breach affected a Fengtai District government Office Automation environment, where operators obtained Windows command execution, stole credential material and collected government and health-related records.
At the center of the campaign was SecFlow, an AI-agent orchestration framework that converted high-level objectives into specialist tasks.
Workers were assigned reconnaissance, vulnerability validation, exploitation, collection and reporting duties, while sharing a filesystem, target configurations, proxy routes and evidence generated by earlier tasks.
Recovered runtime settings showed operators could switch between Claude, Qwen and DeepSeek model profiles without changing the task interface.
Claude ACP and Qwen Code wrappers were configured with broad permissions, including bypass-permission settings and “yolo” approval modes.
Model traffic was routed through private endpoints under the niestools[.]com namespace as well as official provider APIs.
This model-swapping architecture matters because it separates the agent framework from the underlying model. An operator can retain the same attack workflow while changing providers, API routes or model capabilities.
The AI systems organized tasks and generated or adapted commands, but the underlying intrusions still depended on public proof-of-concept exploits, credential attacks, custom scripts, webshells and malware.
Researchers also found a significant operational weakness: a false-positive Shiro vulnerability claim was accepted by the AI workflow and propagated into more than 27 failed follow-up tests.
The Hunt.io Attack Report on the open directory 152.42.200[.]25:9999 assessed an actor primarily targeting Taiwanese and Indonesian government systems.

The incident highlights that autonomous or semi-autonomous offensive workflows can amplify flawed assumptions as efficiently as valid findings.
Hunt.io Researchers said that, the activity, uncovered through five exposed attacker workspaces, shows how AI orchestration can accelerate reconnaissance, exploitation, post-exploitation and reporting without replacing conventional offensive tooling.
AI-Powered Government Attacks
The Fengtai compromise progressed from an internet-facing Office Automation application to webshell deployment, Windows discovery, credential theft, database access and attempted lateral movement.

Operators deployed ASPX command shells to execute Windows commands, enumerate processes and services, scan internal systems and interact with Oracle and Microsoft SQL Server services.
The attackers collected an LSASS memory dump along with SAM and SYSTEM registry hives, then downloaded the data in 37 chunks through web-accessible handlers.
They also extracted 822 OA account records and inserted a new privileged account, providing an application-layer persistence route independent of the deployed webshells.
The compromised environment contained approximately 949 attachments totaling 1.28 GB, including administrative documents, health-related files and a chronic-disease report with patient information.

A Go-based remote-access implant dubbed SecBox was subsequently staged through ASPX files.
The malware supports remote shell access, file transfers, port scanning, SOCKS proxying, port forwarding and dead-drop resolver mechanisms for updating command-and-control routes.
SecFlow workers were instructed to use GLUTTON, a webshell-generation capability supporting Java, .NET, Node.js and multiple server-side formats.
GLUTTON included options for obfuscation, randomized identifiers, encoded strings and steganographic delivery.
One recovered loader accepted PNG images containing executable payload data hidden in RGB pixel values.
The payload was XOR-decoded and loaded directly into memory, allowing attackers to disguise executable content as image traffic and reduce the effectiveness of extension- or MIME-based filtering.
The campaign also incorporated workflows for eight known vulnerabilities, including Shellshock, Ghostcat, Spring4Shell, Apache Shiro deserialization, Log4Shell, Grafana and Nexus path traversal flaws, and a Nacos authentication bypass.
Evidence showed active Shellshock payloads directed at the KMT party archive path, while an XOR-encrypted webshell client referenced an Indonesian Foreign Ministry endpoint.
The investigation attributes the infrastructure cluster to a Chinese-speaking operator with moderate confidence, citing Simplified Chinese artifacts, the recurring “Nie” handle, Chinese proxy-management services and the niestools[.]com model-routing infrastructure.
However, the available evidence does not justify attribution to a specific state-sponsored group.
The campaign demonstrates a developing reality for defenders: AI agents are increasingly being integrated into attacker workflows as force multipliers.
Security teams should prioritize exposure management, patching of internet-facing applications, monitoring for webshell behavior, proxy-aware logging and detection of anomalous image uploads or HTTP-based file transfer patterns.
IOCs
| Indicator | Role |
|---|---|
| 81.70.240[.]170 | Open directory containing the SecFlow workspace; AI execution host, SSH jump host, Layer 2 egress point, and out-of-band listener |
| 43.99.61[.]170 | Open directory containing the Java/CAS exploitation workspace, GLUTTON tooling, and JNDI listener |
| 152.42.200[.]25 | Open directory containing the Shellshock and credential-testing workspace and callback listener |
| 129.211.184[.]149 | Open directory used as a payload-distribution, C2, and post-exploitation store |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
★ Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.





