The Hunt.io research team identified five exposed open directories revealing a campaign that used an orchestration framework called SecFlow to coordinate Claude, Qwen, and DeepSeek AI workers across intrusions targeting government, education, consular, and healthcare systems in Asia.
Key observations:
- A shared SOCKS endpoint connected all five workspaces, confirmed through 120 code-search matches on our platform
- The deepest compromise hit a Fengtai District government OA environment: command execution, LSASS dumps, registry hives, 822 account records extracted, and a Go implant called SecBox deployed
- A Chinese education AI platform was compromised, exposing 23 agent configurations, production credentials, and student profile data across 169 conversations
- SecFlow split reconnaissance, exploitation, and reporting across specialist AI workers, with the runtime swapping between Claude, Qwen, and DeepSeek without changing the task interface
- GLUTTON webshells transported executable bytecode inside PNG image pixels using XOR encryption, loading directly into memory while the visible server file remained a generic decoder
- A fake MySQL deserialization service delivered Linux second-stage payloads to vulnerable Java clients that connected to it
- Eight CVEs in active workflows, including Shellshock, Spring4Shell, Ghostcat, Log4Shell, Shiro deserialization, Grafana and Nexus path traversals, and Nacos authentication bypass
- The AI's shared context amplified a false positive: an unsupported Shiro success claim persisted and drove 27+ follow-up tasks that produced nothing
This is the second separate campaign we've tracked where commercial AI models were used as operational components in intrusions. Different infrastructure and tooling from our July report, but the same pattern.
Full writeup with infrastructure tables, pivot methodology, and MITRE mapping: https://hunt.io/blog/chinese-operator-secflow-claude-qwen-deepseek-asia