News

SecFlow AI agents hit Asian government systems

Hunt.io says a Chinese-speaking operator used SecFlow agents that swap Claude, Qwen, and DeepSeek against government and education systems in Asia. The deepest confirmed hit is Fengtai District OA. Model traffic went through niestools.com. Target egress used authenticated SOCKS. A bad Shiro claim drove 27-plus failed follow-ups.

SecFlow AI agents hit Asian government systems

Hunt.io published threat research on 3 September 2026 describing a second, separate Chinese-speaking operator campaign that embeds commercial AI models as operational components. The Hunt blog was held under TLP:AMBER for the relevant CERTs until that date. It is a commercial intel note, not a government indictment and not proof of a named PLA unit.

Targets included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam. The deepest confirmed intrusion is a Fengtai District government Office Automation environment: command execution, LSASS and registry hives, government and health records, and multiple Windows implants.

The orchestrator is SecFlow. Specialist workers handled recon, exploitation, collection, and reporting. The runtime could switch Claude, Qwen, and DeepSeek profiles without changing the task interface. Hunt is clear that AI organized the work. Exploitation still depended on conventional scripts, public PoCs, leaked credentials, webshells, and custom implants. Claude and Qwen did not hack the systems alone.

Hunt connected five exposed open directories through a shared SOCKS pivot. Initial access used a fake MySQL deserialization service. Active workflows covered eight CVE classes: Shellshock, Spring4Shell, Ghostcat, Shiro deserialization, Log4Shell, Grafana and Nexus path traversals, and a Nacos authentication bypass.

The extra operational split is easy to miss in "AI agents" headlines. Private niestools.com endpoints proxied model traffic. Target-facing requests used authenticated SOCKS relays. The handle Nie shows up across the model-service namespace and the proxy accounts. AI also amplified a miss: an unsupported Shiro success claim carried into later tasks, more than 27 follow-up tests failed, and workers still kept getting GLUTTON assignments off that earlier claim.

AI-assisted intrusion is the same class of problem OpenAI's Daybreak pledge is trying to fund on the defense side. It does not replace patching the browser and hypervisor holes already in this week's queue, including Chrome's in-the-wild V8 fix and VMware Workstation and Fusion host escapes. Vendor-intel campaigns still need the same artifact hunt as Mirage Kitten's fake coding challenges or a cascade like Aesto Health.

If you run a SOC, a government CERT, or an internet-facing Java app this week, hunt for SecFlow, GLUTTON, and SecBox artifacts and for niestools.com egress. Patch the eight CVE classes Hunt listed, treat OA and file-upload handlers as exfil paths, and do not wait for a model-vendor blocklist to be the control.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free