logo

Chinese-Speaking Hackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Systems

ID: bcdaaae8-1ee6-558b-b4fc-ddbed377da46

STIX ID: report--bcdaaae8-1ee6-558b-b4fc-ddbed377da46

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-09-04

Date Updated: 2026-09-11

Author: Mayura Kathir

...
...

The report outlines a China-speaking intrusion cluster that used an AI-agent orchestration framework (SecFlow) wired to multiple LLM backends (Claude, Qwen, DeepSeek) to automate reconnaissance, exploitation and post-exploitation against targets in Taiwan, Indonesia, mainland China and Vietnam. Operators leveraged public exploits (Shellshock, Ghostcat, Spring4Shell, Log4Shell, Shiro, etc.), webshells (GLUTTON), a Go-based implant (SecBox) and credential theft to obtain command execution, harvest LSASS/SAM/SYSTEM data and exfiltrate government and health-related files; investigators recovered shared SOCKS proxy infrastructure and multiple open directories serving as C2/payload stores and provided IOCs and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.