Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

hunt+1gbhackers+1gbhackers+1Threat intelligence firm Hunt.io has uncovered a second campaign by Chinese-speaking operators embedding commercial AI models into live cyberespionage operations, targeting government, political, education, and industrial organizations across Asia. The findings, published September 3 after coordinated disclosure to national CERTs, detail how attackers used an AI orchestration framework called SecFlow to coordinate intrusions powered by Claude, Qwen, and DeepSeek Alibaba Group Holding Limited models.hunt+1
The campaign targeted Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam. Researchers linked five exposed attacker workspaces through a shared SOCKS proxy endpoint that appeared in 120 file-content matches across the servers.securityaffairs+2
SecFlow converted high-level campaign objectives into specialist tasks assigned to AI workers handling reconnaissance, vulnerability validation, exploitation, data collection, and reporting. The framework's runtime allowed operators to swap between Claude, Qwen, and DeepSeek model profiles without changing the task interface, routing traffic through private endpoints under the niestools.com domain as well as official provider APIs.cyberpress+3
The AI models did not independently compromise systems. They organized and automated conventional offensive activity — scanning for vulnerabilities, testing credentials, deploying webshells, and generating reports — while the underlying intrusions relied on public proof-of-concept exploits, custom scripts, and malware. Hunt.io also documented a telling weakness: one AI worker falsely flagged an Apache Shiro vulnerability as successfully exploited, and subsequent workers accepted the claim, triggering more than 27 failed follow-up tests before anyone corrected the error.securityaffairs+2
The most damaging confirmed intrusion struck a Fengtai District government Office Automation environment in China. Operators gained Windows command execution through internet-facing web applications, deployed ASPX webshells, and extracted an LSASS memory dump in 37 chunks along with SAM and SYSTEM registry hives containing credential material. They also pulled 822 user-account records, created a new privileged account for persistent access, and exfiltrated government administrative files, health-related documents, and a chronic-disease report containing patient information from a repository of 949 attachments totaling roughly 1.28 GB.cyberpress+3
A Go-based remote-access implant called SecBox was deployed for continued access, supporting remote shell execution, file transfers, SOCKS proxying, and network pivoting, with the ability to receive replacement command-and-control routes through Pastebin or GitHub Gists.hunt+1
The campaign is the second in two months where Hunt.io caught commercial AI tools embedded in live state-linked intrusions. An earlier operation disclosed in July used Claude Code and DeepSeek against government and financial targets in Afghanistan, Thailand, and Taiwan. Anthropic itself disclosed a related pattern in November 2025, describing attackers who used Claude for coordinated operations against roughly 30 high-value targets.securityaffairs+2
Hunt.io attributed the infrastructure to a Chinese-speaking operator with moderate confidence, citing Simplified Chinese artifacts and the recurring "Nie" handle across proxy credentials and model-service namespaces, though the firm stopped short of linking the campaign to a specific state-sponsored group.gbhackers+1