A Chinese-speaking operator used AI agents inside intrusions that reached government, education and healthcare data across Asia. In one confirmed compromise, the operator ran commands in a Fengtai District government environment, collected LSASS and registry hives, accessed government and health records, and installed Windows implants.
Hunt.io’s investigation connected five exposed workspaces through a shared SOCKS endpoint found in 120 file-content matches. The security vendor, which sells the AttackCapture research platform used in the investigation, found SecFlow coordinating Claude, Qwen and DeepSeek workers. It also found a revealing failure: “AI amplified a false positive” when an unsupported Apache Shiro success claim prompted more than 27 unsuccessful follow-up tests.
Five workspaces shared one route
The five systems served different roles. One hosted SecFlow’s task state and model configuration. Others held Java and CAS exploitation tools, a fake MySQL deserialization service, Shellshock and credential-testing material, and payload distribution and command-and-control files.
The connective tissue was operational rather than thematic. The shared SOCKS route at 103[.]45[.]65[.]93:35888 appeared across the workspaces. Reused accounts, common SecFlow and GLUTTON artifacts, and a direct second-stage payload link strengthened the cluster. Recovered proxy configuration named 43[.]162[.]217[.]10:35888 as the primary route.
Hunt.io describes this as a second campaign, separate from its July reporting about another Chinese-speaking operator using commercial AI models. The report does not attribute the activity to a government. It says the workspaces touched six countries and nearly a dozen sectors, but it does not provide a complete victim count.
AI orchestration met familiar tradecraft
SecFlow turned short objectives into specialist tasks. It supplied workers with target context, tools, shared storage and network routes, then carried results forward to later workers. Recovered runtime configuration exposed profiles for Claude, Qwen and DeepSeek through official routes and private relays under niestools[.]com.
The AI layer organized the campaign. Initial access and post-compromise work still relied on public proof-of-concept code, vulnerable applications, leaked credentials, webshells and custom implants. Active workflows covered Shellshock, Spring4Shell, Ghostcat, Shiro deserialization, Log4Shell, Grafana and Nexus path traversal, and a Nacos authentication bypass.
That division matters when interpreting the evidence. A configured model profile does not show that a model provider directed or knew about the activity. Hunt.io reports operator-controlled relays at claude[.]niestools[.]com and deepseek[.]niestools[.]com, a GLUTTON authorization host at glutton[.]niestools[.]com, and a proxy console at proxy[.]niestools[.]com. The report publishes no response from Anthropic, Alibaba, DeepSeek or the affected organizations.

Long description
The diagram begins with five exposed workspaces: an AI orchestration host, a Java and CAS exploitation workspace, a Shellshock and credential-testing node, a payload and command server, and a fake MySQL service. Their shared proxy, reused files and SecFlow state converge into one operator cluster. From there, one branch shows AI task coordination through Claude, Qwen and DeepSeek profiles. A separate branch shows conventional exploitation through credentials, public exploits, webshells and implants. Both lead to confirmed access in the Fengtai government environment, a Chinese education AI platform and a university campus-card system.
Confirmed access reached sensitive systems
The Fengtai compromise began through an Office Automation application that accepted uploaded ASPX files. The operator used server-side command pages to map internal systems, query databases, collect credential material and stage SecBox, a Go-based remote-access and network-pivot implant.
Elsewhere, an exposed education AI management service revealed agent settings, secrets, conversations and student profiles. The researchers confirmed use of leaked credentials against a production API and an unauthenticated request that created an agent configuration. They did not confirm full server takeover there. A university campus-card environment showed root database access and Grafana administrator access.
The campaign’s vivid moment is also its warning about automated judgment. A claimed Shiro compromise lacked supporting evidence, yet the result flowed into later assignments as if it were established. More than 27 GLUTTON tests then failed. Fast orchestration increased both operational reach and the cost of a bad premise.
Hunt the workspace relationships
Start with the infrastructure roles, then correlate network matches with web-server and identity activity. Hunt.io tied these five exposed hosts to the campaign:
81[.]70[.]240[.]170: SecFlow orchestration, SSH jump and egress host43[.]99[.]61[.]170: Java and CAS exploitation workspace152[.]42[.]200[.]25: Shellshock and credential-testing workspace129[.]211[.]184[.]149: payload distribution, command and Fengtai post-exploitation host159[.]223[.]64[.]67: fake MySQL deserialization and payload-delivery service
Search web roots and file telemetry for cmd.aspx, down.aspx, downx.aspx, extract.aspx, sqldump.aspx and sql6.aspx. Their reported functions range from command execution and resumable file reading to LSASS parsing and arbitrary SQL access. Preserve paths, creation times, parent processes, web requests and the application identity around every match.
Network searches should retain ports and paths rather than flattening every hit into a domain alert. Correlate the five hosts, both SOCKS endpoints, the niestools[.]com relay family and unexpected outbound connections from public-facing Java, .NET and Office Automation servers. A single indicator can be copied or sinkholed; several roles appearing in sequence provide stronger incident evidence.
Verify evidence before escalation
Define a post-containment window before running the verification query. The expected result is no new contact with the seven listed IP addresses or five operator relay hostnames, no recurrence of the six named ASPX files, and an accountable host, process and identity for every historical match.
Treat failed validation as evidence too. Review task reports and operator or automation logs for findings that were promoted without a reproducible request, response and impact record. The Shiro episode shows how one unsupported result can consume later work and obscure the paths that actually succeeded.
Hunt.io disclosed the findings under TLP:AMBER to relevant national CERTs and held publication until September 3. Its record offers strong recognition evidence and several confirmed compromises. It does not establish the campaign’s full victim count, every upstream model used behind private relays, or whether all targeted systems were breached.
