Chinese-Speaking Hackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Systems
ID: bcdaaae8-1ee6-558b-b4fc-ddbed377da46
STIX ID: report--bcdaaae8-1ee6-558b-b4fc-ddbed377da46
Feed Name: GBHackers
The report outlines a China-speaking intrusion cluster that used an AI-agent orchestration framework (SecFlow) wired to multiple LLM backends (Claude, Qwen, DeepSeek) to automate reconnaissance, exploitation and post-exploitation against targets in Taiwan, Indonesia, mainland China and Vietnam. Operators leveraged public exploits (Shellshock, Ghostcat, Spring4Shell, Log4Shell, Shiro, etc.), webshells (GLUTTON), a Go-based implant (SecBox) and credential theft to obtain command execution, harvest LSASS/SAM/SYSTEM data and exfiltrate government and health-related files; investigators recovered shared SOCKS proxy infrastructure and multiple open directories serving as C2/payload stores and provided IOCs and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
