Hackers Turn Claude, Qwen and DeepSeek Into AI Agents for Real-World Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Hackers have turned commercial AI models into working parts of a cyberattack operation. The campaign paired AI-directed tasking with familiar methods such as vulnerable public-facing servers, stolen credentials, webshells, and custom remote-access malware.

The operation reached Taiwan’s Kuomintang Party History Archives, Indonesia’s Ministry of Foreign Affairs, and government and education networks in mainland China.

A confirmed breach hit a Fengtai District government environment, exposing administrative and health records, collecting Windows credentials, and deploying implants.

Analysts at Hunt.io identified the activity after examining exposed attacker directories and tracing a shared SOCKS proxy across five connected workspaces.

Pivoting on the shared SOCKS endpoint surfaces (Source - Hunt.io)
Pivoting on the shared SOCKS endpoint surfaces (Source – Hunt.io)

Hunt.io said in a report shared with Cyber Security News (CSN) that the operators linked infrastructure, reusable accounts, SecFlow files, and GLUTTON payload material.

The findings show a practical shift in how intrusions can be managed. AI did not create the underlying security flaws, but it helped divide work, retain context, and coordinate actions at speed.

It reinforces the need for rapid patching, exposure management, credential protection, and review of unusual web-server activity.

Hackers Turn Claude, Qwen and DeepSeek Into AI Agents

The operators used a framework called SecFlow to turn a broad objective into smaller jobs for specialist AI workers.

Claude, Qwen, and DeepSeek profiles could be selected without changing the task interface, allowing the system to assign reconnaissance, exploit testing, data collection, and reporting across a shared workspace.

SecFlow connected those workers to target details, storage, proxy routes, and tool permissions. The setup included private model relays under niestools.com alongside official provider routes.

It gave later workers earlier results, so one target could quickly develop into coordinated activity. The campaign nevertheless remained grounded in conventional intrusion tradecraft.

The campaign targeted government, political, education, consular, healthcare, industrial, commercial, technology, and consumer systems across Asia (Source - Hunt.io)
The campaign targeted government, political, education, consular, healthcare, industrial, commercial, technology, and consumer systems across Asia (Source – Hunt.io)

Workers used public proof-of-concept code, credential testing, vulnerable applications, webshells, and a custom implant named SecBox.

Readers can compare this operating model with earlier Claude DeepSeek intrusion reporting, which documented commercial models embedded in a separate China-linked campaign.

A claimed Apache Shiro success was not supported by the recovered evidence, yet it was carried into later instructions and triggered more than 27 unsuccessful GLUTTON follow-up tests.

AI coordination can therefore multiply an operator’s speed, but it can also spread an early mistake through the entire workflow.

From Exposed Servers to Data Theft

The Fengtai intrusion began through an Office Automation application that accepted uploaded ASPX files.

Attackers used server-side command pages to run Windows commands, map internal systems, attempt privilege escalation, pull LSASS memory and registry hives, query databases, and move data through ordinary HTTP requests.

They also inserted a privileged application account and staged SecBox, a Go-based remote-access and network-pivot tool. The implant could execute commands, transfer files, scan ports, proxy traffic, and use replacement command-and-control routes.

This blend of webshell access and endpoint tools illustrates why web server attacks need monitoring beyond initial exploit alerts.

Elsewhere, an exposed education AI management service disclosed agent settings, secrets, conversations, and student profile data.

The researchers confirmed use of leaked credentials against a production API and an unauthenticated request to create an agent configuration, but did not confirm a full server takeover. This distinction matters for impact assessment.

WorkFlow (Source - Hunt.io)
WorkFlow (Source – Hunt.io)

A separate fake MySQL service targeted unsafe Java object processing, using an outbound database connection to deliver a Linux second stage.

The group also tested Shellshock, Spring4Shell, Ghostcat, Log4Shell, Grafana, Nexus, Nacos, and Shiro paths. Similar risks are explored in AI agents breach government systems, where parallel agents accelerated reconnaissance and credential attacks.

Organizations should patch internet-facing software promptly, remove exposed directories, restrict administrative interfaces, rotate exposed credentials, and inspect web servers for unexpected ASPX, JSP, PHP, or image-based loaders.

Teams should also watch for outbound connections to the listed infrastructure, review authentication and application logs, and validate automated security findings before acting on them.

Guidance on agents rebuilding failed malware tools further underlines why defenders need behavior-based detection, not only static signatures.

Network segmentation and least-privilege access can further limit the damage if a public application is compromised. Exercises also shorten containment time.

Indicators of compromise (IoCs):-

Type Indicator Description
IP address 81.70.240[.]170 Exposed SecFlow workspace, AI execution host, SSH jump host, and egress point
IP address 43.99.61[.]170 Java/CAS exploitation workspace containing GLUTTON tooling and JNDI listener
IP address 152.42.200[.]25 Shellshock and credential-testing workspace with callback listener
IP address 129.211.184[.]149 Payload-distribution, command-and-control, and post-exploitation store
IP address 159.223.64[.]67 Fake MySQL deserialization server, scanner, and callback tooling host
Network endpoint 129.211.184[.]149:64288 Primary SecBox command-and-control endpoint embedded in Windows builds
Network endpoint 129.211.184[.]149:8443 SecBox controller backend and payload-distribution service
Network endpoint 158.247.234[.]124:18000 SecBox dead-drop-resolver TCP and WebSocket redirector
Network endpoint 207.148.109[.]245:18000 Earlier plaintext SecBox dead-drop-resolver redirector
Network endpoint 103.45.65[.]93:35888 Shared authenticated SOCKS5 route
Network endpoint 43.162.217[.]10:35888 Primary authenticated SOCKS5h route configured in SecFlow
IP address 211.159.155[.]240 SecFlow gateway
URL hxxp://129.211.184[.]149:8443/999b4e8c/public/dnc/a6d28ebe?os=<os>&arch=<arch> Linux second-stage payload download endpoint
URL hxxp://158.247.234[.]124:18000/c22.exe Windows payload download endpoint used to stage fw.exe
URL tcp://imported-concerns-listening-typing[.]trycloudflare[.]com:443 Short-lived SecBox dead-drop-resolver TCP route
URL tcp://marriage-step-wave-heavy[.]trycloudflare[.]com:443 Short-lived SecBox dead-drop-resolver TCP route
URL wss://wins-say-charm-social[.]trycloudflare[.]com/c2 Short-lived SecBox secure WebSocket route
URL ws://158.247.234[.]124:18000/ SecBox WebSocket redirector route
Domain .niestools[.]com Operator-controlled domain family used for model relays, AI gateways, proxy management, documentation, and GLUTTON authorization
Domain claude.niestools[.]com Private Claude API relay configured in SecFlow
Domain deepseek.niestools[.]com Private DeepSeek-compatible API relay configured in SecFlow
Domain glutton.niestools[.]com Hardcoded GLUTTON MCP authorization domain
Domain proxy.niestools[.]com Proxy-pool management console
Domain chatgpt.niestools[.]com Sub2API AI gateway host
Domain wiki.niestools[.]com Observed subdomain in the operator-controlled domain family
Filename agent_new.out Windows SecBox-compatible multiprotocol implant
SHA-256 20a8ed7d235cf6419e2d4b1e439595ef96961adaecf3c990c5cd507eb4a74ca4 Hash for agent_new.out
Filename e6475722.exe / v11.exe Windows SecBox payload staged as C:WindowsTempv11.exe
SHA-256 0b3d76cf1ac6648d4cfbe39c8fea67c6b28a361ea6de86a92cc7d54a0181cc9e Hash for e6475722.exe / v11.exe
Filename av2_chk_cn-44.exe and aliases Windows implant with deceptive syscfg.exe internal-name metadata
SHA-256 3c9b2ec423f91642d2d09031d47e50d7ebe77a8b12ec5e393405f85da11a0f6a Hash for av2_chk_cn-44.exe
Filename bf57c009.bin Linux SecBox-compatible implant variant
SHA-256 4ecbdaedf9040dbbb33ce7a96ad961dce0f3ffb2c41285606a27a7c5ab3d2273 Hash for bf57c009.bin
Filename c22.exe / fw.exe / fw_c049574c.exe Windows implant associated with the c22.exe to fw.exe deployment chain
SHA-256 eef30bb6834bf349d1b1f4401aa0b8e73631ea632a884c6498a5b3a9e069d412 Hash for c22.exe / fw.exe / fw_c049574c.exe
Filename cmd.aspx Victim-side HTTP command shell that executes commands through cmd.exe /c
Filename down.aspx Arbitrary-file range reader supporting resumable binary exfiltration
SHA-256 dcd59349bd6cc29e59da5105f2f08f606ece8dfac4e369e052eca1786450f541 Hash for down.aspx
Filename downx.aspx Arbitrary-file reader applying XOR with key 0xAA
SHA-256 135b33b289d481d60fa2527aeae5882d33adcb6756df89ea7684f4af3567b141 Hash for downx.aspx
Filename extract.aspx LSASS-dump scanner for username and NT-hash material
SHA-256 9ef85857ed2b53a23eb41ce5769b4fb5b8b2225404b227a776520771df86706e Hash for extract.aspx
Filename sqldump.aspx Office Automation database reconnaissance and extraction payload
SHA-256 797676d3becc124bb6705ebd76189e8decedae3abf978434d730459133351064 Hash for sqldump.aspx
Filename sql6.aspx Base64-encoded arbitrary SQL interface
SHA-256 af6404a125d1e4eb67425ec17f2abeec7242fb6f7377de739e47cb7f5d147eee Hash for sql6.aspx
Filename doc_helper.aspx / doc_view_666b2dde.aspx Duplicate file-management webshells enabling arbitrary file operations
SHA-256 053c8dfb147262aaedf0d9cdce631ad73cfd5b1a808114c12bbe5adfe4796302 Hash for doc_helper.aspx and doc_view_666b2dde.aspx
Filename dl_e6.aspx Loader that copies e6475722.exe to C:WindowsTempv11.exe and attempts execution
SHA-256 80d778c9d9e44896f08b1a196254527e39da4e8ce5edebf8d296b7dec6b7b3e0 Hash for dl_e6.aspx
Filename dl_v11.aspx Downloader that copies e6475722.exe to C:WindowsTempv11.exe
SHA-256 f7c233df3423912296a4e78dd1fa7a1f6412606177336be0762961c93e8fae3c Hash for dl_v11.aspx
Filename dl_icn.aspx Downloader that retrieves c22.exe and writes it as C:WindowsTempfw.exe
SHA-256 548df87041ea2cbe99fc519fd89c5b7cdfe935d87a803a80a5f747aa9f076091 Hash for dl_icn.aspx
Filename launchfw.aspx Loader that downloads c22.exe as fw.exe and executes it through Process.Start and WMI
SHA-256 79cc5855375b5c840bae8263dc3dc5a9fd9cbd7920ab4ed65d407fd830d3eda1 Hash for launchfw.aspx
Filename potato4.aspx EFSRPC named-pipe token-impersonation and privilege-escalation payload
SHA-256 a407f540f4eb0c8fae5cd83fa6e210df6c4ed7fca6aedb6ebc5efbf031989ac4 Hash for potato4.aspx
Filename cb1_glutton.bin Primary Tomcat or Undertow GLUTTON injector
SHA-256 00759d29178baabcbe9682a953c64e179fd24d86dac0d6abdc8e5070216923f2 Hash for cb1_glutton.bin
Filename cb1_glutton_wl.bin WebLogic or CAS ticket-interception GLUTTON variant
SHA-256 f51ab15a89155ce4d3bcd0a65cf6a3ccf62115f502e0863c19baf93d11c57acc Hash for cb1_glutton_wl.bin
Filename cb1_redis_glutton.bin Redis-assisted GLUTTON payload writer
SHA-256 853222ffdcc74dd606f6ff79ff353ce3626d50e54e9aa1a87fb03e2121e82aaf Hash for cb1_redis_glutton.bin
Filename MethodInvoker.class Tomcat or Undertow in-memory filter component
SHA-256 218d8508c2035c78b49d33e087e33643f4f906af5694be68cf939f17fa4b5ffd Hash for MethodInvoker.class
Filename confusion_d0c41072a0dc784c.jsp Obfuscated JSP loader for PNG-carried in-memory payloads
SHA-256 2deac4ab60f6cb1bb65fa4df5dbd9dcf7b7bc27e16bea55c3ddbe47154720277 Hash for confusion_d0c41072a0dc784c.jsp
Filename confusion_d0c41072a0dc784c_nodejs.html Obfuscated Node.js loader for PNG-carried in-memory payloads
SHA-256 e6ee24c6775867714d1e4b586d75c0168e61ba49b36e0a29b73cbc925df6ae47 Hash for confusion_d0c41072a0dc784c_nodejs.html
Filename CommonsBeanutils1.bin Java deserialization payload used to download a second-stage implant
SHA-256 1c00ce5354c91a9db878e2b4db750c2a74140e0d15aeac9b8cecf4599598b736 Hash for CommonsBeanutils1.bin
Filename CommonsCollections6.bin Java deserialization callback and second-stage downloader payload
SHA-256 27fae1b7be68b0c27c5dad33aaed9de5b38406fb20b971757b6be386e3ffc7a6 Hash for CommonsCollections6.bin
Filename Spring1.bin Spring gadget-chain downloader delivered through the fake MySQL workflow
SHA-256 77f5b5321e2f5c18b3c610e50084b98201fb6214e13665cc49da5afbf3f49611 Hash for Spring1.bin
Filename fakeserver_new.py Fake MySQL-compatible service used for deserialization-based initial access
Filename xor_bd.py XOR-encoded webshell client used against an Indonesian Foreign Ministry URI
Filename deploy_all.sh Script used to deploy PHP webshells masquerading as WordPress files
File path wp-content/plugins/class-wp-settings.php PHP webshell masquerading as a WordPress plugin file
File path wp-content/cache/cache-main.php PHP webshell masquerading as a WordPress cache file
File path wp-content/uploads/maintenance-check.php PHP webshell masquerading as a WordPress maintenance file
File path wp-includes/class-wp-l10n.php PHP webshell masquerading as a WordPress core file
XOR key d0c41072a0dc784c Recovered repeating key used by GLUTTON PNG-carried webshell loaders
Byte sequence FF 88 00 Payload-end marker searched by GLUTTON PNG-carried loaders

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

The post Hackers Turn Claude, Qwen and DeepSeek Into AI Agents for Real-World Cyberattacks appeared first on Cyber Security News.