CyberSecurityNews

Hackers Turn Claude, Qwen and DeepSeek Into AI Agents for Real-World Cyberattacks


Hackers have turned commercial AI models into working parts of a cyberattack operation. The campaign paired AI-directed tasking with familiar methods such as vulnerable public-facing servers, stolen credentials, webshells, and custom remote-access malware.

The operation reached Taiwan’s Kuomintang Party History Archives, Indonesia’s Ministry of Foreign Affairs, and government and education networks in mainland China.

A confirmed breach hit a Fengtai District government environment, exposing administrative and health records, collecting Windows credentials, and deploying implants.

Analysts at Hunt.io identified the activity after examining exposed attacker directories and tracing a shared SOCKS proxy across five connected workspaces.

Pivoting on the shared SOCKS endpoint surfaces (Source – Hunt.io)

Hunt.io said in a report shared with Cyber Security News (CSN) that the operators linked infrastructure, reusable accounts, SecFlow files, and GLUTTON payload material.

The findings show a practical shift in how intrusions can be managed. AI did not create the underlying security flaws, but it helped divide work, retain context, and coordinate actions at speed.

It reinforces the need for rapid patching, exposure management, credential protection, and review of unusual web-server activity.

Hackers Turn Claude, Qwen and DeepSeek Into AI Agents

The operators used a framework called SecFlow to turn a broad objective into smaller jobs for specialist AI workers.

Claude, Qwen, and DeepSeek profiles could be selected without changing the task interface, allowing the system to assign reconnaissance, exploit testing, data collection, and reporting across a shared workspace.

SecFlow connected those workers to target details, storage, proxy routes, and tool permissions. The setup included private model relays under niestools.com alongside official provider routes.

It gave later workers earlier results, so one target could quickly develop into coordinated activity. The campaign nevertheless remained grounded in conventional intrusion tradecraft.

The campaign targeted government, political, education, consular, healthcare, industrial, commercial, technology, and consumer systems across Asia (Source - Hunt.io)
The campaign targeted government, political, education, consular, healthcare, industrial, commercial, technology, and consumer systems across Asia (Source – Hunt.io)

Workers used public proof-of-concept code, credential testing, vulnerable applications, webshells, and a custom implant named SecBox.

Readers can compare this operating model with earlier Claude DeepSeek intrusion reporting, which documented commercial models embedded in a separate China-linked campaign.

A claimed Apache Shiro success was not supported by the recovered evidence, yet it was carried into later instructions and triggered more than 27 unsuccessful GLUTTON follow-up tests.

AI coordination can therefore multiply an operator’s speed, but it can also spread an early mistake through the entire workflow.

From Exposed Servers to Data Theft

The Fengtai intrusion began through an Office Automation application that accepted uploaded ASPX files.

Attackers used server-side command pages to run Windows commands, map internal systems, attempt privilege escalation, pull LSASS memory and registry hives, query databases, and move data through ordinary HTTP requests.

They also inserted a privileged application account and staged SecBox, a Go-based remote-access and network-pivot tool. The implant could execute commands, transfer files, scan ports, proxy traffic, and use replacement command-and-control routes.

This blend of webshell access and endpoint tools illustrates why web server attacks need monitoring beyond initial exploit alerts.

Elsewhere, an exposed education AI management service disclosed agent settings, secrets, conversations, and student profile data.

The researchers confirmed use of leaked credentials against a production API and an unauthenticated request to create an agent configuration, but did not confirm a full server takeover. This distinction matters for impact assessment.

WorkFlow (Source - Hunt.io)
WorkFlow (Source – Hunt.io)

A separate fake MySQL service targeted unsafe Java object processing, using an outbound database connection to deliver a Linux second stage.

The group also tested Shellshock, Spring4Shell, Ghostcat, Log4Shell, Grafana, Nexus, Nacos, and Shiro paths. Similar risks are explored in AI agents breach government systems, where parallel agents accelerated reconnaissance and credential attacks.

Organizations should patch internet-facing software promptly, remove exposed directories, restrict administrative interfaces, rotate exposed credentials, and inspect web servers for unexpected ASPX, JSP, PHP, or image-based loaders.

Teams should also watch for outbound connections to the listed infrastructure, review authentication and application logs, and validate automated security findings before acting on them.

Guidance on agents rebuilding failed malware tools further underlines why defenders need behavior-based detection, not only static signatures.

Network segmentation and least-privilege access can further limit the damage if a public application is compromised. Exercises also shorten containment time.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
IP address81.70.240[.]170Exposed SecFlow workspace, AI execution host, SSH jump host, and egress point
IP address43.99.61[.]170Java/CAS exploitation workspace containing GLUTTON tooling and JNDI listener
IP address152.42.200[.]25Shellshock and credential-testing workspace with callback listener
IP address129.211.184[.]149Payload-distribution, command-and-control, and post-exploitation store
IP address159.223.64[.]67Fake MySQL deserialization server, scanner, and callback tooling host
Network endpoint129.211.184[.]149:64288Primary SecBox command-and-control endpoint embedded in Windows builds
Network endpoint129.211.184[.]149:8443SecBox controller backend and payload-distribution service
Network endpoint158.247.234[.]124:18000SecBox dead-drop-resolver TCP and WebSocket redirector
Network endpoint207.148.109[.]245:18000Earlier plaintext SecBox dead-drop-resolver redirector
Network endpoint103.45.65[.]93:35888Shared authenticated SOCKS5 route
Network endpoint43.162.217[.]10:35888Primary authenticated SOCKS5h route configured in SecFlow
IP address211.159.155[.]240SecFlow gateway
URLhxxp://129.211.184[.]149:8443/999b4e8c/public/dnc/a6d28ebe?os=&arch=Linux second-stage payload download endpoint
URLhxxp://158.247.234[.]124:18000/c22.exeWindows payload download endpoint used to stage fw.exe
URLtcp://imported-concerns-listening-typing[.]trycloudflare[.]com:443Short-lived SecBox dead-drop-resolver TCP route
URLtcp://marriage-step-wave-heavy[.]trycloudflare[.]com:443Short-lived SecBox dead-drop-resolver TCP route
URLwss://wins-say-charm-social[.]trycloudflare[.]com/c2Short-lived SecBox secure WebSocket route
URLws://158.247.234[.]124:18000/SecBox WebSocket redirector route
Domain.niestools[.]comOperator-controlled domain family used for model relays, AI gateways, proxy management, documentation, and GLUTTON authorization
Domainclaude.niestools[.]comPrivate Claude API relay configured in SecFlow
Domaindeepseek.niestools[.]comPrivate DeepSeek-compatible API relay configured in SecFlow
Domainglutton.niestools[.]comHardcoded GLUTTON MCP authorization domain
Domainproxy.niestools[.]comProxy-pool management console
Domainchatgpt.niestools[.]comSub2API AI gateway host
Domainwiki.niestools[.]comObserved subdomain in the operator-controlled domain family
Filenameagent_new.outWindows SecBox-compatible multiprotocol implant
SHA-25620a8ed7d235cf6419e2d4b1e439595ef96961adaecf3c990c5cd507eb4a74ca4Hash for agent_new.out
Filenamee6475722.exe / v11.exeWindows SecBox payload staged as C:WindowsTempv11.exe
SHA-2560b3d76cf1ac6648d4cfbe39c8fea67c6b28a361ea6de86a92cc7d54a0181cc9eHash for e6475722.exe / v11.exe
Filenameav2_chk_cn-44.exe and aliasesWindows implant with deceptive syscfg.exe internal-name metadata
SHA-2563c9b2ec423f91642d2d09031d47e50d7ebe77a8b12ec5e393405f85da11a0f6aHash for av2_chk_cn-44.exe
Filenamebf57c009.binLinux SecBox-compatible implant variant
SHA-2564ecbdaedf9040dbbb33ce7a96ad961dce0f3ffb2c41285606a27a7c5ab3d2273Hash for bf57c009.bin
Filenamec22.exe / fw.exe / fw_c049574c.exeWindows implant associated with the c22.exe to fw.exe deployment chain
SHA-256eef30bb6834bf349d1b1f4401aa0b8e73631ea632a884c6498a5b3a9e069d412Hash for c22.exe / fw.exe / fw_c049574c.exe
Filenamecmd.aspxVictim-side HTTP command shell that executes commands through cmd.exe /c
Filenamedown.aspxArbitrary-file range reader supporting resumable binary exfiltration
SHA-256dcd59349bd6cc29e59da5105f2f08f606ece8dfac4e369e052eca1786450f541Hash for down.aspx
Filenamedownx.aspxArbitrary-file reader applying XOR with key 0xAA
SHA-256135b33b289d481d60fa2527aeae5882d33adcb6756df89ea7684f4af3567b141Hash for downx.aspx
Filenameextract.aspxLSASS-dump scanner for username and NT-hash material
SHA-2569ef85857ed2b53a23eb41ce5769b4fb5b8b2225404b227a776520771df86706eHash for extract.aspx
Filenamesqldump.aspxOffice Automation database reconnaissance and extraction payload
SHA-256797676d3becc124bb6705ebd76189e8decedae3abf978434d730459133351064Hash for sqldump.aspx
Filenamesql6.aspxBase64-encoded arbitrary SQL interface
SHA-256af6404a125d1e4eb67425ec17f2abeec7242fb6f7377de739e47cb7f5d147eeeHash for sql6.aspx
Filenamedoc_helper.aspx / doc_view_666b2dde.aspxDuplicate file-management webshells enabling arbitrary file operations
SHA-256053c8dfb147262aaedf0d9cdce631ad73cfd5b1a808114c12bbe5adfe4796302Hash for doc_helper.aspx and doc_view_666b2dde.aspx
Filenamedl_e6.aspxLoader that copies e6475722.exe to C:WindowsTempv11.exe and attempts execution
SHA-25680d778c9d9e44896f08b1a196254527e39da4e8ce5edebf8d296b7dec6b7b3e0Hash for dl_e6.aspx
Filenamedl_v11.aspxDownloader that copies e6475722.exe to C:WindowsTempv11.exe
SHA-256f7c233df3423912296a4e78dd1fa7a1f6412606177336be0762961c93e8fae3cHash for dl_v11.aspx
Filenamedl_icn.aspxDownloader that retrieves c22.exe and writes it as C:WindowsTempfw.exe
SHA-256548df87041ea2cbe99fc519fd89c5b7cdfe935d87a803a80a5f747aa9f076091Hash for dl_icn.aspx
Filenamelaunchfw.aspxLoader that downloads c22.exe as fw.exe and executes it through Process.Start and WMI
SHA-25679cc5855375b5c840bae8263dc3dc5a9fd9cbd7920ab4ed65d407fd830d3eda1Hash for launchfw.aspx
Filenamepotato4.aspxEFSRPC named-pipe token-impersonation and privilege-escalation payload
SHA-256a407f540f4eb0c8fae5cd83fa6e210df6c4ed7fca6aedb6ebc5efbf031989ac4Hash for potato4.aspx
Filenamecb1_glutton.binPrimary Tomcat or Undertow GLUTTON injector
SHA-25600759d29178baabcbe9682a953c64e179fd24d86dac0d6abdc8e5070216923f2Hash for cb1_glutton.bin
Filenamecb1_glutton_wl.binWebLogic or CAS ticket-interception GLUTTON variant
SHA-256f51ab15a89155ce4d3bcd0a65cf6a3ccf62115f502e0863c19baf93d11c57accHash for cb1_glutton_wl.bin
Filenamecb1_redis_glutton.binRedis-assisted GLUTTON payload writer
SHA-256853222ffdcc74dd606f6ff79ff353ce3626d50e54e9aa1a87fb03e2121e82aafHash for cb1_redis_glutton.bin
FilenameMethodInvoker.classTomcat or Undertow in-memory filter component
SHA-256218d8508c2035c78b49d33e087e33643f4f906af5694be68cf939f17fa4b5ffdHash for MethodInvoker.class
Filenameconfusion_d0c41072a0dc784c.jspObfuscated JSP loader for PNG-carried in-memory payloads
SHA-2562deac4ab60f6cb1bb65fa4df5dbd9dcf7b7bc27e16bea55c3ddbe47154720277Hash for confusion_d0c41072a0dc784c.jsp
Filenameconfusion_d0c41072a0dc784c_nodejs.htmlObfuscated Node.js loader for PNG-carried in-memory payloads
SHA-256e6ee24c6775867714d1e4b586d75c0168e61ba49b36e0a29b73cbc925df6ae47Hash for confusion_d0c41072a0dc784c_nodejs.html
FilenameCommonsBeanutils1.binJava deserialization payload used to download a second-stage implant
SHA-2561c00ce5354c91a9db878e2b4db750c2a74140e0d15aeac9b8cecf4599598b736Hash for CommonsBeanutils1.bin
FilenameCommonsCollections6.binJava deserialization callback and second-stage downloader payload
SHA-25627fae1b7be68b0c27c5dad33aaed9de5b38406fb20b971757b6be386e3ffc7a6Hash for CommonsCollections6.bin
FilenameSpring1.binSpring gadget-chain downloader delivered through the fake MySQL workflow
SHA-25677f5b5321e2f5c18b3c610e50084b98201fb6214e13665cc49da5afbf3f49611Hash for Spring1.bin
Filenamefakeserver_new.pyFake MySQL-compatible service used for deserialization-based initial access
Filenamexor_bd.pyXOR-encoded webshell client used against an Indonesian Foreign Ministry URI
Filenamedeploy_all.shScript used to deploy PHP webshells masquerading as WordPress files
File pathwp-content/plugins/class-wp-settings.phpPHP webshell masquerading as a WordPress plugin file
File pathwp-content/cache/cache-main.phpPHP webshell masquerading as a WordPress cache file
File pathwp-content/uploads/maintenance-check.phpPHP webshell masquerading as a WordPress maintenance file
File pathwp-includes/class-wp-l10n.phpPHP webshell masquerading as a WordPress core file
XOR keyd0c41072a0dc784cRecovered repeating key used by GLUTTON PNG-carried webshell loaders
Byte sequenceFF 88 00Payload-end marker searched by GLUTTON PNG-carried loaders

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.



Source link