INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Chinese Hackers Utilize AI Agents in Multi-Country Cyber Campaign
| 2026-09-03 17:26 MEDIUM MEDIUM AI-ENABLED ATTACK STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A second, separate China-linked campaign was documented by threat intelligence firm [IOC HIDDEN • LOGIN REQUIRED] on September 4, 2026, where commercial AI models were wired into live cyberespionage operations targeting Taiwan's Kuomintang Party archives and government systems in mainland China. The targeted sectors included education and industrial hosts in Vietnam. This attack worked by using a framework called SecFlow that utilized different AI models such as Claude, Qwen, and DeepSeek to automate traditional hacking tasks like scanning for vulnerabilities, testing stolen credentials, deploying webshells, collecting data and evidence, and generating reports. The current status indicates the most damaging breach hit a Fengtai District government Office Automation environment in China, resulting in command execution, collected sensitive information, and deployed multiple Windows implants.
Technical Mitigations AI-generated
• <a href="/auth/login?next=/detail/4GYZcKAB-1kL6CVYv7NC" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a> uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets.
• The framework behind the campaign, called SecFlow by the operators, could use different AI models, including Claude, Qwen, and DeepSeek.
• Researchers reconstructed the entire orchestration system from five exposed open directories left publicly accessible by the operators.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ni•••••.com
ws•••••.run
hu•••••.io
ex•••••.aspx
hxxp://••••••••••••••••••••
9ef858••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
4ecbda••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
79cc58••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
135b33••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign
Pierluigi PaganiniCampaign
Pierluigi Paganini
Target & Sectors
ASEAN
ASEAN
FIVE_EYES
FIVE_EYES
educationeducation
governmentgovernment
Incident Timeline
2026/09/03
A Chinese-speaking operator used AI agents to automate cyberattacks against Asian government, education and industrial targets.
Click on any entity below to view its context and source!
organisation
SecFlow
A Chinese-speaking threat operator deployed an AI orchestration framework called SecFlow to conduct intrusions across Taiwan, Indonesia, China, Vietnam, and Afghanistan.
organisation
Kuomintang Party History Archives
Targets included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam.
organisation
Ministry of Foreign Affairs
Targets included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam.
organisation
SecBox
The most significant compromise affected a Fengtai District government environment, achieving command execution, credential theft, and deployment of SecBox implants.
infrastructure
Windows
“The most extensive compromise hit a Fengtai District government environment, where the operator achieved command execution, collected LSASS and registry hives, accessed government and health records, and deployed multiple Windows implants.
“
Operators achieved Windows command execution through internet-facing web applications, then used ASPX web shells not just to run commands but as a persistent operational backbone: querying internal databases, pulling an LSASS memory dump apart…
Another server-side page, extract.aspx, scanned sections of the memory dump for Windows password-hash material.”
organisation
Claude
The campaign utilized commercial AI models (Claude, Qwen, DeepSeek) as operational components for reconnaissance, exploitation, and data collection.
organisation
Shellshock, Log4Shell
The operator exploited eight CVEs including Shellshock, Log4Shell, and Spring4Shell, deploying steganographic GLUTTON webshells concealed in PNG images.
organisation
PNG
The operator exploited eight CVEs including Shellshock, Log4Shell, and Spring4Shell, deploying steganographic GLUTTON webshells concealed in PNG images.
data_breach
822 OA account records
From there they pulled 822 OA user account records, created a new privileged account of their own for backup access, and walked away with 949 attachments totaling 1.28GB, including a chronic-disease report containing real patient health information.
data_breach
1.28 GB
From there they pulled 822 OA user account records, created a new privileged account of their own for backup access, and walked away with 949 attachments totaling 1.28GB, including a chronic-disease report containing real patient health information.
data_breach
104 complete chatbot conversations
It exposed 23 AI agent configurations, 14 API secret fields containing credentials, and 104 complete chatbot conversations.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
“The most extensive compromise hit a Fengtai District government environment, where the operator achieved command execution, collected LSASS and registry hives, accessed government and health records, and deployed multiple Windows implants.
“
Operators achieved Windows command execution through internet-facing web applications, then used ASPX web shells not just to run commands but as a persistent operational backbone: querying internal databases, pulling an LSASS memory dump apart…
Another server-side page, extract.aspx, scanned sections of the memory dump for Windows password-hash material.”
Metrics
data_breach
822
Oa Account Records
From there they pulled 822 OA user account records, created a new privileged account of their own for backup access, and walked away with 949 attachments totaling 1.28GB, including a chronic-disease report containing real patient health information.
Metrics
data_breach
1
Gb
From there they pulled 822 OA user account records, created a new privileged account of their own for backup access, and walked away with 949 attachments totaling 1.28GB, including a chronic-disease report containing real patient health information.
Metrics
data_breach
104
Complete Chatbot Conversations
It exposed 23 AI agent configurations, 14 API secret fields containing credentials, and 104 complete chatbot conversations.
Intelligence Sources
Security Affairs
2026-09-04
Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign
Security Affairs
AlienVault OTX
2026-09-03
AlienVault OTX
2026-09-04
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:08
Comprehensive Tactical Telemetry
Highly Correlated Entities
17x
organisation
Identified Entity
SecFlow
entity
7x
target region
Target Country
Taiwan, Province of China
country
4x
industry
Targeted Sector
Government
sector
4x
attribution
Attributing Entity
Target Government
authority
2x
timeline
Temporal Reference
September 04, 2026
date
Contextual Telemetry
Context Block
11 METRICS
tactic
Cyber Operation Type
Reconnaissance
tactic
source region
Origin Country
China
country
campaign
Campaign
Campaign
Pierluigi Paganini
operation
infrastructure
Affected Product
Windows
software
data breach
Oa Account Records
822
oa account records
general metric
Attachments
949
attachments
data breach
Gb
1
gb
general metric
Separate Chunks
37
separate chunks
general metric
Ai Agent Configurations
23
ai agent configurations
general metric
Secret Fields
14
secret fields
data breach
Complete Chatbot Conversations
104
complete chatbot conversations
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.