Chinese-Speaking Operator Used AI Agents to Target Government and Education Systems Across Asia

· Original article ↗

Summary

Hunt.io links five exposed workspaces to a Chinese-speaking operator using AI agents and conventional exploits. The campaign compromised government and education systems, stealing credentials and records and deploying webshells and SecBox implants.

Key points

  • Hunt.io connected five exposed workspaces through shared proxy infrastructure, accounts and tooling, linking activity across six countries and nearly a dozen sectors.
  • The SecFlow framework assigned reconnaissance, exploitation, collection and reporting tasks to Claude, Qwen and DeepSeek workers; exploitation relied on conventional scripts, public proof-of-concept code, credentials and custom tools.
  • In a Fengtai District government environment, the operator gained command execution, collected LSASS data and registry hives, accessed government and health records, extracted 822 OA account records and deployed Windows implants.
  • An education AI platform's unauthenticated backend exposed agent configurations, credentials and dialogue records. Leaked credentials were used against production services, exposing additional conversations and student-profile information.
  • The investigation also found root database and Grafana administrator access to a university campus-card system, and a fake MySQL service designed to trigger Java deserialization and deliver a second-stage implant.
  • The campaign tested or staged workflows involving eight CVEs and used webshells, including GLUTTON loaders that concealed executable payloads in PNG image data. Not every vulnerability attempt succeeded.
  • Hunt.io says it disclosed the findings to relevant national CERTs under TLP:AMBER and delayed publication until September 3, 2026.

Article Details

Attack Vectors
  • The operator used an OA FileManage handler to upload web-accessible ASPX command shells into the Fengtai government environment.
  • A malicious MySQL-compatible service returned crafted serialized Java objects to connecting vulnerable clients, triggering a platform-aware second-stage downloader.
  • Shellshock payloads placed a Bash command chain in the User-Agent header of requests to the KMT Party History Archives.
  • The operator used exposed AI-platform management services and disclosed application credentials to access configurations, conversations and production Dify APIs.
  • SecFlow workers tested or staged the eight listed CVEs; the article distinguishes probes and prepared payloads from successful access.
Defensive Notes
  • The recovered reporting workflow required control requests, reproducible results, impact evidence and severity checks, but an unsupported Shiro success claim propagated despite more than 27 unsuccessful follow-up tests.
  • The education AI-platform evidence confirms an accepted unauthenticated configuration-write request, but does not establish that the configuration persisted, its external URL was accessed, or SSRF or backend code execution occurred.
  • No automatic persistence mechanism was confirmed in the reviewed SecBox builds; the Fengtai operator separately created and verified a privileged OA application account.

Indicators of compromise

TypeIndicatorContext
DOMAINniestools[.]comOperator-controlled domain family used for model relays, proxy management and GLUTTON authorization.
HOSTNAMEclaude[.]niestools[.]comOperator-controlled private Claude model relay used by SecFlow.
HOSTNAMEdeepseek[.]niestools[.]comOperator-controlled private DeepSeek-compatible model relay used by SecFlow.
HOSTNAMEproxy[.]niestools[.]comOperator-associated proxy-pool management console.
IPV4103[.]45[.]65[.]93Shared authenticated SOCKS5 relay used across operator workspaces.
IPV4129[.]211[.]184[.]149Operator payload-distribution, C2 and post-exploitation host.
IPV4152[.]42[.]200[.]25Operator Shellshock and credential-testing workspace and callback listener.
IPV4158[.]247[.]234[.]124SecBox payload host and DDR-supplied redirector.
IPV4159[.]223[.]64[.]67Operator workspace hosting the malicious MySQL-compatible deserialization service.
IPV4207[.]148[.]109[.]245Earlier plaintext SecBox DDR redirector.
IPV4211[.]159[.]155[.]240SecFlow gateway listed in the operator-infrastructure indicators.
IPV443[.]162[.]217[.]10Primary authenticated SOCKS5 route configured for SecFlow tasks.
IPV443[.]99[.]61[.]170Operator Java/CAS exploitation workspace with GLUTTON tooling and a JNDI listener.
IPV481[.]70[.]240[.]170Operator AI-orchestration workspace, SSH jump host and egress point.
SHA25600759d29178baabcbe9682a953c64e179fd24d86dac0d6abdc8e5070216923f2GLUTTON injector intended for execution inside a victim Java application.
SHA256053c8dfb147262aaedf0d9cdce631ad73cfd5b1a808114c12bbe5adfe4796302Victim-side file-management webshell found as doc_helper.aspx and doc_view_666b2dde.aspx.
SHA2560b3d76cf1ac6648d4cfbe39c8fea67c6b28a361ea6de86a92cc7d54a0181cc9eWindows SecBox payload staged and executed on the Fengtai OA host.
SHA256135b33b289d481d60fa2527aeae5882d33adcb6756df89ea7684f4af3567b141Victim-side downx.aspx file reader with XOR-obfuscated transfers.
SHA2561c00ce5354c91a9db878e2b4db750c2a74140e0d15aeac9b8cecf4599598b736Victim-executed Java deserialization second-stage downloader payload.
SHA25620a8ed7d235cf6419e2d4b1e439595ef96961adaecf3c990c5cd507eb4a74ca4Windows SecBox-compatible multiprotocol implant, agent_new.out.
SHA256218d8508c2035c78b49d33e087e33643f4f906af5694be68cf939f17fa4b5ffdMethodInvoker.class in-memory filter component.
SHA25627fae1b7be68b0c27c5dad33aaed9de5b38406fb20b971757b6be386e3ffc7a6Victim-executed Java deserialization callback and downloader payload.
SHA2562deac4ab60f6cb1bb65fa4df5dbd9dcf7b7bc27e16bea55c3ddbe47154720277Obfuscated JSP loader for a PNG-carried in-memory payload.
SHA2563c9b2ec423f91642d2d09031d47e50d7ebe77a8b12ec5e393405f85da11a0f6aWindows implant build staged under multiple filenames.
SHA2564ecbdaedf9040dbbb33ce7a96ad961dce0f3ffb2c41285606a27a7c5ab3d2273Linux SecBox-compatible implant variant.
SHA256548df87041ea2cbe99fc519fd89c5b7cdfe935d87a803a80a5f747aa9f076091Victim-side dl_icn.aspx downloader for c22.exe.
SHA25677f5b5321e2f5c18b3c610e50084b98201fb6214e13665cc49da5afbf3f49611Victim-executed Spring gadget-chain downloader delivered through the fake MySQL workflow.
SHA256797676d3becc124bb6705ebd76189e8decedae3abf978434d730459133351064Victim-side sqldump.aspx OA database extraction payload.
SHA25679cc5855375b5c840bae8263dc3dc5a9fd9cbd7920ab4ed65d407fd830d3eda1Victim-side launchfw.aspx downloader and implant launcher.
SHA25680d778c9d9e44896f08b1a196254527e39da4e8ce5edebf8d296b7dec6b7b3e0Victim-side dl_e6.aspx SecBox loader.
SHA256853222ffdcc74dd606f6ff79ff353ce3626d50e54e9aa1a87fb03e2121e82aafRedis-assisted GLUTTON payload writer targeting victim Java applications.
SHA2569ef85857ed2b53a23eb41ce5769b4fb5b8b2225404b227a776520771df86706eVictim-side extract.aspx LSASS-dump scanner.
SHA256a407f540f4eb0c8fae5cd83fa6e210df6c4ed7fca6aedb6ebc5efbf031989ac4Victim-side potato4.aspx privilege-escalation payload.
SHA256af6404a125d1e4eb67425ec17f2abeec7242fb6f7377de739e47cb7f5d147eeeVictim-side sql6.aspx arbitrary SQL interface.
SHA256dcd59349bd6cc29e59da5105f2f08f606ece8dfac4e369e052eca1786450f541Victim-side down.aspx arbitrary-file range reader used for exfiltration.
SHA256e6ee24c6775867714d1e4b586d75c0168e61ba49b36e0a29b73cbc925df6ae47Obfuscated Node.js loader for a PNG-carried in-memory payload.
SHA256eef30bb6834bf349d1b1f4401aa0b8e73631ea632a884c6498a5b3a9e069d412Retained Windows implant sample assessed as a candidate for the c22.exe-to-fw.exe deployment path.
SHA256f51ab15a89155ce4d3bcd0a65cf6a3ccf62115f502e0863c19baf93d11c57accWebLogic or CAS ticket-interception GLUTTON variant.
SHA256f7c233df3423912296a4e78dd1fa7a1f6412606177336be0762961c93e8fae3cVictim-side dl_v11.aspx SecBox downloader.
URLhxxp[:]//129[.]211[.]184[.]149:8443/999b4e8c/public/dnc/a6d28ebe?os=<os>&arch=<arch>Operator second-stage implant download URL used by the fake MySQL deserialization payloads.
URLhxxp[:]//158[.]247[.]234[.]124:18000/c22[.]exeSecBox implant download URL used by victim-side ASPX loaders.
URLhxxps[:]//glutton[.]niestools[.]comOperator-controlled GLUTTON MCP authorization endpoint hardcoded in its binaries.

MITRE ATT&CK

T1003 · OS Credential DumpingThe Fengtai operator retrieved an LSASS memory dump and collected SAM and SYSTEM registry hives.T1021.004 · SSHThe article reports root SSH access to 81.70.240.170 for tunneling and tool access.T1078 · Valid AccountsThe operator used exposed application credentials and created a privileged Fengtai OA account; retained evidence also showed database and Grafana access.T1090 · ProxySecFlow routed target-facing traffic through authenticated SOCKS relays and SSH dynamic forwarding.T1105 · Ingress Tool TransferVictim-side loaders downloaded SecBox implants, including c22.exe, from operator infrastructure.T1133 · External Remote ServicesThe article reports operator access workflows involving public VPN, SSH, database, appliance and management services.T1190 · Exploit Public-Facing ApplicationThe operator sent Shellshock commands to the KMT archives and tested other listed public-facing application vulnerabilities.T1213 · Data from Information RepositoriesThe operator collected OA account records and documents, AI conversations, agent configurations and database content.T1505.003 · Web ShellThe operator uploaded and used ASPX command shells in the Fengtai environment and prepared other GLUTTON, PHP and PNG-carried webshell loaders.T1552.001 · Credentials In FilesOperator workflows collected secrets from configuration files, frontend bundles, reports, container material and application files.T1567 · Exfiltration Over Web ServiceThe article reports API pagination and export, HTTP PUT and callback-driven collection as exfiltration methods.T1595 · Active ScanningSecFlow workers performed port, subdomain, service, API and framework discovery; a separate workspace scanned Afghan telecommunications ranges.

CVE

Malware

Vendors

Products

Claude CodeIn July, we published research on a Chinese-speaking operator who embedded Claude Code and DeepSeek into intrusions across four countries. This is a second, separate campaign with different infrastructure, tooling, andCozeconfigurations disclosed multiple downstream AI-platform credentials, including Dify application keys, a Coze private key and platform AI credential material. The Dify credentials were then used successfully againstDeepSeekIn July, we published research on a Chinese-speaking operator who embedded Claude Code and DeepSeek into intrusions across four countries. This is a second, separate campaign with different infrastructure, tooling, andDify81.70.240.170The exposed configurations disclosed multiple downstream AI-platform credentials, including Dify application keys, a Coze private key and platform AI credential material. The Dify credentials were thenGrafanaShellshock, Spring4Shell, Ghostcat, Shiro deserialization, Log4Shell, Grafana and Nexus path traversals, and a Nacos authentication bypass.IISPrivilege escalationpotato.aspx, potato3.aspx, potato4.aspx, potato4r.aspxAttempted to convert an IIS or service token into SYSTEM executionMicrosoft SQL ServerOracle and Microsoft SQL Server servicesMicrosoft Windowscollected LSASS and registry hives, accessed government and health records, and deployed multiple Windows implants. Separate activity exposed a Chinese education AI platform and obtained root database access toMySQLThe exposed directories map to an AI orchestration host, a Java/CAS exploitation workspace, a fake MySQL deserialization service, a Shellshock and credential-testing node, and a payload-distribution store.NacosShellshock, Spring4Shell, Ghostcat, Shiro deserialization, Log4Shell, Grafana and Nexus path traversals, and a Nacos authentication bypass.Nexus RepositoryOracleOracle and Microsoft SQL Server servicesQwen CodeThe runtime configuration exposed five model profiles. SecFlow launched either Claude ACP or Qwen Code, injected a model name and API route, and applied broad tool permissions. Private Claude and DeepSeek-compatibleShiroShellshock, Spring4Shell, Ghostcat, Shiro deserialization, Log4Shell, Grafana and Nexus path traversals, and a Nacos authentication bypass.Sub2APIThe domain chatgpt.niestools[.]com returns a 401 Unauthorized. We can observe from the HTTP response that this domain is running the Sub2API AI gateway:

Tools

Countries

Industries

Commerciala second, separate campaign with different infrastructure, tooling, and targets, but the same pattern: commercial AI models used as operational components. Targets included Taiwan's Kuomintang Party History Archives,ConsumerFig. 05. The campaign targeted government, political, education, consular, healthcare, industrial, commercial, technology, and consumer systems across Asia.AI-powered intrusionsEducationTaiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam.GovernmentTargets included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam.HealthcareFig. 05. The campaign targeted government, political, education, consular, healthcare, industrial, commercial, technology, and consumer systems across Asia.AI-powered intrusionsIndustrialIndonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam.PoliticalFig. 05. The campaign targeted government, political, education, consular, healthcare, industrial, commercial, technology, and consumer systems across Asia.AI-powered intrusionsTechnologyFig. 05. The campaign targeted government, political, education, consular, healthcare, industrial, commercial, technology, and consumer systems across Asia.AI-powered intrusionsTelecommunicationsSeparately this open-directory showed evidence of targeted enumeration of an Afghan telecommunications operator's corporate network ranges.

Related Articles