A Chinese-speaking operator used the SecFlow framework to orchestrate AI agents associated with Claude, Qwen, and DeepSeek in intrusion activity against government, education, industrial, and telecommunications organizations across Asia. The agents automated reconnaissance, testing of known vulnerabilities, credential collection, and reporting, while conventional tooling—including webshells, stolen credentials, custom implants, GLUTTON tooling, and shared SOCKS infrastructure—carried out the intrusions. Researchers linked activity through reused accounts, niestools.com services, SecFlow artifacts, and the recurring handle “Nie.”
The most severe confirmed breach affected a Fengtai District government Office Automation environment, where the operator obtained Windows command execution, captured LSASS memory and registry hives, extracted OA accounts and records, created a privileged application account, exfiltrated government and health data, and deployed the SecBox implant. A Chinese education AI platform’s control and data plane were also compromised; other targets included Taiwan’s Kuomintang archives, Indonesia’s Ministry of Foreign Affairs, Vietnamese organizations, Chinese public-service systems, and an Afghan telecommunications operator. Workflows tested eight known flaws, including Shellshock, Spring4Shell, Ghostcat, Shiro deserialization, Log4Shell, Grafana and Nexus traversal vulnerabilities, and a Nacos authentication bypass, though not all exploitation attempts succeeded.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
Hunt.io published its TLP:AMBER findings after sharing them with relevant national CERTs and delaying public release. The report linked five exposed operator workspaces through shared SOCKS infrastructure, SecFlow and GLUTTON artifacts, reused accounts, payload relationships, and the recurring handle "Nie."
A MySQL-compatible server hosted at 159.223.64[.]67 delivered Java deserialization payloads intended to execute on vulnerable connecting Java clients and download Linux SecBox-compatible implants from 129.211.184[.]149:8443.
An unauthenticated management backend exposed agent configurations, secrets, internal addresses, and 104 complete AI-dialogue records. The operator successfully used exposed Dify, Coze, and other credentials against the production Dify API to obtain 169 conversations and 339 message or query entries, including student information; an unauthenticated agent-configuration write was also confirmed.
The actor deployed the customized Go-based SecBox remote-access and network-pivot implant through ASPX downloaders and loaders. SecBox supported command execution, file transfer, credential and token access, discovery, scanning, SOCKS proxying, port forwarding, and self-removal.
The operator gained server-side Windows command execution through an internet-facing IIS Office Automation FileManage handler, then used webshells for discovery, database access, credential theft, lateral movement, and exfiltration. They collected a roughly 75.8 MB LSASS dump and SAM/SYSTEM hives, extracted 822 OA account records, created an elevated OA application account, and accessed government, health, and patient-related records.
The SecFlow-enabled campaign targeted Taiwan's Kuomintang Party History Archives and Indonesia's Ministry of Foreign Affairs, alongside organizations in other Asian sectors. The reference characterizes these as targets and does not confirm a compromise of either organization.
A Chinese-speaking operator used the SecFlow orchestration framework with Claude, Qwen, and DeepSeek model profiles to automate reconnaissance, exploitation, credential collection, and reporting against organizations across Asia. The activity used conventional exploits and tooling, including tested or staged paths for eight known CVEs.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 51 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcecommunity.gurucul.com
Open sourcesecurityaffairs.com
Open sourcecyberveille.ch
Open sourcehunt.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.