A Chinese-speaking threat actor transformed Claude, Qwen, and DeepSeek into specialized AI agents that hunted for vulnerabilities, attacked servers, and prepared comprehensive outcome reports. The cybersecurity team at Hunt.io discovered five exposed working directories. These directories contained files from a highly sophisticated campaign. This operation explicitly targeted government, educational, medical, industrial, and commercial organizations across Asia. Researchers successfully linked this malicious infrastructure through a shared SOCKS proxy and recurring credentials. They also uncovered common SecFlow and GLUTTON software components.
SecFlow Coordinates the Autonomous AI Team
SecFlow operated as the primary coordinator for this artificial intelligence team. First, the central system received a broad overarching objective. Next, it divided the labor systematically among various autonomous agents. Furthermore, it supplied them with necessary hacking tools and specific intelligence regarding the targeted organization. The platform also provided shared storage spaces and distinct network routing. Consequently, certain agents conducted initial reconnaissance. Meanwhile, other entities verified vulnerabilities, established system persistence, harvested sensitive data, and formalized the final results.
The malicious operator could seamlessly toggle between Claude, Qwen, and DeepSeek profiles. They accomplished this without ever altering the primary task interface. Consequently, a portion of the requests traversed legitimate official application programming interfaces. Conversely, other queries routed through private gateways hosted on the niestools.com domain. These digital operatives functioned with highly elevated access privileges. For instance, they utilized specialized modes to bypass manual confirmations and automatically execute destructive commands.
Traditional Tools Power the Actual Breaches
However, conventional cybersecurity tools still executed the actual network breaches. Investigators found public demonstration programs and network scanners within the exposed working directories. They also uncovered stolen user credentials, malicious web shells, and a proprietary SecBox implant. Furthermore, the active attack scenarios featured eight prominent, widely known vulnerabilities. This dangerous arsenal specifically included Shellshock, Spring4Shell, Ghostcat, and the notorious Log4Shell.
The most severe confirmed incident involved a breach of government infrastructure within the Fengtai district of Beijing. The attacker successfully gained the ability to execute arbitrary commands. Next, the operative dumped the LSASS process memory alongside the SAM and SYSTEM registry hives. Additionally, the hacker accessed highly sensitive administrative and medical documents. They ultimately fabricated a highly privileged administrative account. Within the application directory, investigators discovered 949 distinct attachments totaling approximately 1.28 gigabytes.
Simultaneously, other AI agents breached the management backend of a Chinese educational artificial intelligence platform. This completely unprotected server exposed critical agent configurations and highly secretive cryptographic keys. It also revealed hundreds of dialogue transcripts containing highly confidential student information. Furthermore, within a university campus access system, the operator illegally acquired Grafana administrator privileges. This breach ultimately granted them complete root access to the underlying database.
Clandestine Management via GLUTTON
The attacker heavily utilized GLUTTON for the clandestine management of compromised servers. This versatile tool dynamically generated insidious web shells designed for Java, .NET, and Node.js environments. Astonishingly, the system could transmit executable code concealed within the color channels of a seemingly benign PNG image file. Following successful decryption, the malicious payload executed directly within the system memory. Therefore, this advanced technique effectively bypassed rudimentary file extension and type verifications.
Despite these advancements, artificial intelligence did not render the campaign flawless. One particular agent erroneously reported the successful exploitation of an Apache Shiro vulnerability. Consequently, SecFlow continued distributing subsequent tasks based entirely upon this fabricated result. Over 27 consecutive verification attempts ended in total failure. Nevertheless, the rigid system stubbornly directed the agents toward the next phase of the attack.
According to a detailed Hunt.io analysis of the Chinese operator using SecFlow, Claude, Qwen, and DeepSeek in Asia, AI did not simply replace traditional hacking tools. Instead, it seamlessly linked them into a unified, highly automated process. SecFlow meticulously preserved the results of all previous actions. Subsequently, it transmitted this vital intelligence to newly deployed agents. This incredible efficiency allowed a single human operator to concurrently manage reconnaissance, exploitation, data harvesting, and report generation across multiple diverse targets.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.