Trusted Design

Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asia

概要

A Chinese-speaking threat operator deployed an AI orchestration framework called SecFlow to conduct intrusions across Taiwan, Indonesia, China, Vietnam, and Afghanistan. The campaign utilized commercial AI models (Claude, Qwen, DeepSeek) as operational components for reconnaissance, exploitation, and data collection. The most significant compromise affected a Fengtai District government environment, achieving command execution, credential theft, and deployment of SecBox implants. Additional confirmed breaches included a Chinese education AI platform and university campus systems. The operator exploited eight CVEs including Shellshock, Log4Shell, and Spring4Shell, deploying steganographic GLUTTON webshells concealed in PNG images. Infrastructure was linked through the handle 'Nie' and associated domains under niestools.com, with operations routed through authenticated SOCKS proxies. Targets included government offices, political organizations, educational institutions, and telecommunications infrastructure.

Created: 2026-09-04

Indicators

Indicatorsは見つかっていない。

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

事実ベースの脅威アクターは見つかりませんでした。

このPulseに関連する脅威アクター (推論ベース)

推論ベースの脅威アクターは見つかりませんでした。

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る