Hackers have turned commercial AI models into working parts of a cyberattack operation. The campaign paired AI-directed tasking with familiar methods such as vulnerable public-facing servers, stolen credentials, webshells, and custom remote-access malware.
The operation reached Taiwan’s Kuomintang Party History Archives, Indonesia’s Ministry of Foreign Affairs, and government and education networks in mainland China.
A confirmed breach hit a Fengtai District government environment, exposing administrative and health records, collecting Windows credentials, and deploying implants.
Analysts at Hunt.io identified the activity after examining exposed attacker directories and tracing a shared SOCKS proxy across five connected workspaces.
Hunt.io said in a report shared with Cyber Security News (CSN) that the operators linked infrastructure, reusable accounts, SecFlow files, and GLUTTON payload material.
The findings show a practical shift in how intrusions can be managed. AI did not create the underlying security flaws, but it helped divide work, retain context, and coordinate actions at speed.
It reinforces the need for rapid patching, exposure management, credential protection, and review of unusual web-server activity.
Hackers Turn Claude, Qwen and DeepSeek Into AI Agents
The operators used a framework called SecFlow to turn a broad objective into smaller jobs for specialist AI workers.
Claude, Qwen, and DeepSeek profiles could be selected without changing the task interface, allowing the system to assign reconnaissance, exploit testing, data collection, and reporting across a shared workspace.
SecFlow connected those workers to target details, storage, proxy routes, and tool permissions. The setup included private model relays under niestools.com alongside official provider routes.
It gave later workers earlier results, so one target could quickly develop into coordinated activity. The campaign nevertheless remained grounded in conventional intrusion tradecraft.
.webp)
Workers used public proof-of-concept code, credential testing, vulnerable applications, webshells, and a custom implant named SecBox.
Readers can compare this operating model with earlier Claude DeepSeek intrusion reporting, which documented commercial models embedded in a separate China-linked campaign.
A claimed Apache Shiro success was not supported by the recovered evidence, yet it was carried into later instructions and triggered more than 27 unsuccessful GLUTTON follow-up tests.
AI coordination can therefore multiply an operator’s speed, but it can also spread an early mistake through the entire workflow.
From Exposed Servers to Data Theft
The Fengtai intrusion began through an Office Automation application that accepted uploaded ASPX files.
Attackers used server-side command pages to run Windows commands, map internal systems, attempt privilege escalation, pull LSASS memory and registry hives, query databases, and move data through ordinary HTTP requests.
They also inserted a privileged application account and staged SecBox, a Go-based remote-access and network-pivot tool. The implant could execute commands, transfer files, scan ports, proxy traffic, and use replacement command-and-control routes.
This blend of webshell access and endpoint tools illustrates why web server attacks need monitoring beyond initial exploit alerts.
Elsewhere, an exposed education AI management service disclosed agent settings, secrets, conversations, and student profile data.
The researchers confirmed use of leaked credentials against a production API and an unauthenticated request to create an agent configuration, but did not confirm a full server takeover. This distinction matters for impact assessment.
.webp)
A separate fake MySQL service targeted unsafe Java object processing, using an outbound database connection to deliver a Linux second stage.
The group also tested Shellshock, Spring4Shell, Ghostcat, Log4Shell, Grafana, Nexus, Nacos, and Shiro paths. Similar risks are explored in AI agents breach government systems, where parallel agents accelerated reconnaissance and credential attacks.
Organizations should patch internet-facing software promptly, remove exposed directories, restrict administrative interfaces, rotate exposed credentials, and inspect web servers for unexpected ASPX, JSP, PHP, or image-based loaders.
Teams should also watch for outbound connections to the listed infrastructure, review authentication and application logs, and validate automated security findings before acting on them.
Guidance on agents rebuilding failed malware tools further underlines why defenders need behavior-based detection, not only static signatures.
Network segmentation and least-privilege access can further limit the damage if a public application is compromised. Exercises also shorten containment time.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IP address | 81.70.240[.]170 | Exposed SecFlow workspace, AI execution host, SSH jump host, and egress point |
| IP address | 43.99.61[.]170 | Java/CAS exploitation workspace containing GLUTTON tooling and JNDI listener |
| IP address | 152.42.200[.]25 | Shellshock and credential-testing workspace with callback listener |
| IP address | 129.211.184[.]149 | Payload-distribution, command-and-control, and post-exploitation store |
| IP address | 159.223.64[.]67 | Fake MySQL deserialization server, scanner, and callback tooling host |
| Network endpoint | 129.211.184[.]149:64288 | Primary SecBox command-and-control endpoint embedded in Windows builds |
| Network endpoint | 129.211.184[.]149:8443 | SecBox controller backend and payload-distribution service |
| Network endpoint | 158.247.234[.]124:18000 | SecBox dead-drop-resolver TCP and WebSocket redirector |
| Network endpoint | 207.148.109[.]245:18000 | Earlier plaintext SecBox dead-drop-resolver redirector |
| Network endpoint | 103.45.65[.]93:35888 | Shared authenticated SOCKS5 route |
| Network endpoint | 43.162.217[.]10:35888 | Primary authenticated SOCKS5h route configured in SecFlow |
| IP address | 211.159.155[.]240 | SecFlow gateway |
| URL | hxxp://129.211.184[.]149:8443/999b4e8c/public/dnc/a6d28ebe?os= | Linux second-stage payload download endpoint |
| URL | hxxp://158.247.234[.]124:18000/c22.exe | Windows payload download endpoint used to stage fw.exe |
| URL | tcp://imported-concerns-listening-typing[.]trycloudflare[.]com:443 | Short-lived SecBox dead-drop-resolver TCP route |
| URL | tcp://marriage-step-wave-heavy[.]trycloudflare[.]com:443 | Short-lived SecBox dead-drop-resolver TCP route |
| URL | wss://wins-say-charm-social[.]trycloudflare[.]com/c2 | Short-lived SecBox secure WebSocket route |
| URL | ws://158.247.234[.]124:18000/ | SecBox WebSocket redirector route |
| Domain | .niestools[.]com | Operator-controlled domain family used for model relays, AI gateways, proxy management, documentation, and GLUTTON authorization |
| Domain | claude.niestools[.]com | Private Claude API relay configured in SecFlow |
| Domain | deepseek.niestools[.]com | Private DeepSeek-compatible API relay configured in SecFlow |
| Domain | glutton.niestools[.]com | Hardcoded GLUTTON MCP authorization domain |
| Domain | proxy.niestools[.]com | Proxy-pool management console |
| Domain | chatgpt.niestools[.]com | Sub2API AI gateway host |
| Domain | wiki.niestools[.]com | Observed subdomain in the operator-controlled domain family |
| Filename | agent_new.out | Windows SecBox-compatible multiprotocol implant |
| SHA-256 | 20a8ed7d235cf6419e2d4b1e439595ef96961adaecf3c990c5cd507eb4a74ca4 | Hash for agent_new.out |
| Filename | e6475722.exe / v11.exe | Windows SecBox payload staged as C:WindowsTempv11.exe |
| SHA-256 | 0b3d76cf1ac6648d4cfbe39c8fea67c6b28a361ea6de86a92cc7d54a0181cc9e | Hash for e6475722.exe / v11.exe |
| Filename | av2_chk_cn-44.exe and aliases | Windows implant with deceptive syscfg.exe internal-name metadata |
| SHA-256 | 3c9b2ec423f91642d2d09031d47e50d7ebe77a8b12ec5e393405f85da11a0f6a | Hash for av2_chk_cn-44.exe |
| Filename | bf57c009.bin | Linux SecBox-compatible implant variant |
| SHA-256 | 4ecbdaedf9040dbbb33ce7a96ad961dce0f3ffb2c41285606a27a7c5ab3d2273 | Hash for bf57c009.bin |
| Filename | c22.exe / fw.exe / fw_c049574c.exe | Windows implant associated with the c22.exe to fw.exe deployment chain |
| SHA-256 | eef30bb6834bf349d1b1f4401aa0b8e73631ea632a884c6498a5b3a9e069d412 | Hash for c22.exe / fw.exe / fw_c049574c.exe |
| Filename | cmd.aspx | Victim-side HTTP command shell that executes commands through cmd.exe /c |
| Filename | down.aspx | Arbitrary-file range reader supporting resumable binary exfiltration |
| SHA-256 | dcd59349bd6cc29e59da5105f2f08f606ece8dfac4e369e052eca1786450f541 | Hash for down.aspx |
| Filename | downx.aspx | Arbitrary-file reader applying XOR with key 0xAA |
| SHA-256 | 135b33b289d481d60fa2527aeae5882d33adcb6756df89ea7684f4af3567b141 | Hash for downx.aspx |
| Filename | extract.aspx | LSASS-dump scanner for username and NT-hash material |
| SHA-256 | 9ef85857ed2b53a23eb41ce5769b4fb5b8b2225404b227a776520771df86706e | Hash for extract.aspx |
| Filename | sqldump.aspx | Office Automation database reconnaissance and extraction payload |
| SHA-256 | 797676d3becc124bb6705ebd76189e8decedae3abf978434d730459133351064 | Hash for sqldump.aspx |
| Filename | sql6.aspx | Base64-encoded arbitrary SQL interface |
| SHA-256 | af6404a125d1e4eb67425ec17f2abeec7242fb6f7377de739e47cb7f5d147eee | Hash for sql6.aspx |
| Filename | doc_helper.aspx / doc_view_666b2dde.aspx | Duplicate file-management webshells enabling arbitrary file operations |
| SHA-256 | 053c8dfb147262aaedf0d9cdce631ad73cfd5b1a808114c12bbe5adfe4796302 | Hash for doc_helper.aspx and doc_view_666b2dde.aspx |
| Filename | dl_e6.aspx | Loader that copies e6475722.exe to C:WindowsTempv11.exe and attempts execution |
| SHA-256 | 80d778c9d9e44896f08b1a196254527e39da4e8ce5edebf8d296b7dec6b7b3e0 | Hash for dl_e6.aspx |
| Filename | dl_v11.aspx | Downloader that copies e6475722.exe to C:WindowsTempv11.exe |
| SHA-256 | f7c233df3423912296a4e78dd1fa7a1f6412606177336be0762961c93e8fae3c | Hash for dl_v11.aspx |
| Filename | dl_icn.aspx | Downloader that retrieves c22.exe and writes it as C:WindowsTempfw.exe |
| SHA-256 | 548df87041ea2cbe99fc519fd89c5b7cdfe935d87a803a80a5f747aa9f076091 | Hash for dl_icn.aspx |
| Filename | launchfw.aspx | Loader that downloads c22.exe as fw.exe and executes it through Process.Start and WMI |
| SHA-256 | 79cc5855375b5c840bae8263dc3dc5a9fd9cbd7920ab4ed65d407fd830d3eda1 | Hash for launchfw.aspx |
| Filename | potato4.aspx | EFSRPC named-pipe token-impersonation and privilege-escalation payload |
| SHA-256 | a407f540f4eb0c8fae5cd83fa6e210df6c4ed7fca6aedb6ebc5efbf031989ac4 | Hash for potato4.aspx |
| Filename | cb1_glutton.bin | Primary Tomcat or Undertow GLUTTON injector |
| SHA-256 | 00759d29178baabcbe9682a953c64e179fd24d86dac0d6abdc8e5070216923f2 | Hash for cb1_glutton.bin |
| Filename | cb1_glutton_wl.bin | WebLogic or CAS ticket-interception GLUTTON variant |
| SHA-256 | f51ab15a89155ce4d3bcd0a65cf6a3ccf62115f502e0863c19baf93d11c57acc | Hash for cb1_glutton_wl.bin |
| Filename | cb1_redis_glutton.bin | Redis-assisted GLUTTON payload writer |
| SHA-256 | 853222ffdcc74dd606f6ff79ff353ce3626d50e54e9aa1a87fb03e2121e82aaf | Hash for cb1_redis_glutton.bin |
| Filename | MethodInvoker.class | Tomcat or Undertow in-memory filter component |
| SHA-256 | 218d8508c2035c78b49d33e087e33643f4f906af5694be68cf939f17fa4b5ffd | Hash for MethodInvoker.class |
| Filename | confusion_d0c41072a0dc784c.jsp | Obfuscated JSP loader for PNG-carried in-memory payloads |
| SHA-256 | 2deac4ab60f6cb1bb65fa4df5dbd9dcf7b7bc27e16bea55c3ddbe47154720277 | Hash for confusion_d0c41072a0dc784c.jsp |
| Filename | confusion_d0c41072a0dc784c_nodejs.html | Obfuscated Node.js loader for PNG-carried in-memory payloads |
| SHA-256 | e6ee24c6775867714d1e4b586d75c0168e61ba49b36e0a29b73cbc925df6ae47 | Hash for confusion_d0c41072a0dc784c_nodejs.html |
| Filename | CommonsBeanutils1.bin | Java deserialization payload used to download a second-stage implant |
| SHA-256 | 1c00ce5354c91a9db878e2b4db750c2a74140e0d15aeac9b8cecf4599598b736 | Hash for CommonsBeanutils1.bin |
| Filename | CommonsCollections6.bin | Java deserialization callback and second-stage downloader payload |
| SHA-256 | 27fae1b7be68b0c27c5dad33aaed9de5b38406fb20b971757b6be386e3ffc7a6 | Hash for CommonsCollections6.bin |
| Filename | Spring1.bin | Spring gadget-chain downloader delivered through the fake MySQL workflow |
| SHA-256 | 77f5b5321e2f5c18b3c610e50084b98201fb6214e13665cc49da5afbf3f49611 | Hash for Spring1.bin |
| Filename | fakeserver_new.py | Fake MySQL-compatible service used for deserialization-based initial access |
| Filename | xor_bd.py | XOR-encoded webshell client used against an Indonesian Foreign Ministry URI |
| Filename | deploy_all.sh | Script used to deploy PHP webshells masquerading as WordPress files |
| File path | wp-content/plugins/class-wp-settings.php | PHP webshell masquerading as a WordPress plugin file |
| File path | wp-content/cache/cache-main.php | PHP webshell masquerading as a WordPress cache file |
| File path | wp-content/uploads/maintenance-check.php | PHP webshell masquerading as a WordPress maintenance file |
| File path | wp-includes/class-wp-l10n.php | PHP webshell masquerading as a WordPress core file |
| XOR key | d0c41072a0dc784c | Recovered repeating key used by GLUTTON PNG-carried webshell loaders |
| Byte sequence | FF 88 00 | Payload-end marker searched by GLUTTON PNG-carried loaders |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

