INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Chinese Hackers Utilize AI Agents in Multi-Country Cyber Campaign

| 2026-09-03 17:26 MEDIUM MEDIUM AI-ENABLED ATTACK STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A second, separate China-linked campaign was documented by threat intelligence firm [IOC HIDDEN • LOGIN REQUIRED] on September 4, 2026, where commercial AI models were wired into live cyberespionage operations targeting Taiwan's Kuomintang Party archives and government systems in mainland China. The targeted sectors included education and industrial hosts in Vietnam. This attack worked by using a framework called SecFlow that utilized different AI models such as Claude, Qwen, and DeepSeek to automate traditional hacking tasks like scanning for vulnerabilities, testing stolen credentials, deploying webshells, collecting data and evidence, and generating reports. The current status indicates the most damaging breach hit a Fengtai District government Office Automation environment in China, resulting in command execution, collected sensitive information, and deployed multiple Windows implants.
Technical Mitigations AI-generated
• <a href="/auth/login?next=/detail/4GYZcKAB-1kL6CVYv7NC" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a> uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets. • The framework behind the campaign, called SecFlow by the operators, could use different AI models, including Claude, Qwen, and DeepSeek. • Researchers reconstructed the entire orchestration system from five exposed open directories left publicly accessible by the operators.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ni•••••.com
ws•••••.run
hu•••••.io
ex•••••.aspx
hxxp://••••••••••••••••••••
9ef858••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
4ecbda••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
79cc58••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
135b33••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign Pierluigi PaganiniCampaign Pierluigi Paganini
Target & Sectors
ASEAN ASEAN FIVE_EYES FIVE_EYES educationeducation governmentgovernment
Incident Timeline
‎2026/09/03
A Chinese-speaking operator used AI agents to automate cyberattacks against Asian government, education and industrial targets.
organisation SecFlow
organisation Kuomintang Party History Archives
organisation Ministry of Foreign Affairs
organisation SecBox
infrastructure Windows
organisation Claude
organisation Shellshock, Log4Shell
organisation PNG
data_breach 822 OA account records
data_breach 1.28 GB
data_breach 104 complete chatbot conversations
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
data_breach
822
Oa Account Records
Metrics
data_breach
1
Gb
Metrics
data_breach
104
Complete Chatbot Conversations