Security1 distinct publisher3 min readPublished
Hunt.io rebuilt the framework from five directories the operators left open, and found the worker roles fixed while the model profile stays a swappable setting, with requests fronted by private proxies instead of vendor APIs.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
SecFlow kept fixed worker roles for reconnaissance, exploitation, collection and reporting, and the model itself was just a profile that could be pointed at Claude, Qwen or DeepSeek without touching the task interface [4]. Requests did not go to the vendors' official APIs. They went through private proxy servers tied to the niestools.com domain [5]. Account-level enforcement by any one provider therefore lands on a proxy and on one profile, and the vendor sees traffic arriving from infrastructure the operators run rather than from the operators themselves.
The intrusion work underneath used conventional techniques. Operators got Windows command execution through internet-facing web applications and used ASPX web shells as a persistent backbone, querying internal databases, pulling an LSASS memory dump in 37 separate blocks over an authenticated SOCKS route with the byte count verified for each block before reassembly, and taking the SAM and SYSTEM registry hives; a page called extract.aspx scanned the dump for password-hash material [8]. Chunking a credential dump defeats size-based egress rules, but 37 authenticated fetches against one web shell path is a countable pattern in web logs.
From the Fengtai District environment the operators took 822 OA user account records, created their own privileged account for backup access, and removed 949 attachments totalling 1.28GB, one of them a chronic-disease report with real patient information [9]. That averages roughly 1.4MB per file [15], which is a document store being emptied, not a database being dumped.
One access route inverted the usual direction of attack. A malicious service impersonating a MySQL server accepted connections from vulnerable Java applications and returned crafted data to trigger unsafe deserialization on the client side [12].
The other AI-specific finding is a configuration failure on the victim side. A Chinese education AI platform left its management backend reachable with no authentication, exposing 23 agent configurations, 14 API secret fields and 104 complete chatbot conversations, some carrying student names, ID numbers, majors and advisers [10]. Hunt.io reports those keys worked against the platform's live production API [11]. Elsewhere the operators obtained root database access to a university campus-card system [13].
Hunt.io frames this as the second separate China-linked campaign to wire commercial models into live operations [1], which puts the documented count at two [14]; the material at hand does not name the earlier one [16]. Two cases establish a pattern forming rather than a standard. What the report does establish is architectural: the orchestration layer is abstracted from the model, and it covers scanning, credential testing, exploit attempts, web shell deployment, collection and report writing [6]. That part is durable. Nothing in it required the models to find new vulnerabilities. A Shellshock and credential-testing node and a Java/CAS workspace did the reaching [3], so the control list for defenders is the one it already was.
Ranked by verification strength, evidence, and original report placement.
Threat intelligence firm Hunt.io documented a second, separate China-linked campaign wiring commercial AI models directly into live cyberespionage operations.
Targets in the campaign included Taiwan's Kuomintang Party archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Vietnam.
Researchers reconstructed the operation through five open directories the operators accidentally left publicly accessible: an AI orchestration host, a Java/CAS exploitation workspace, a fake MySQL deserialization service, a Shellshock and credential-testing node, and a payload-distribution store.
The framework, called SecFlow by its operators, split reconnaissance, exploitation, collection and reporting among specialist workers, and its runtime could switch between Claude, Qwen and DeepSeek profiles without changing the task interface.
Instead of using the models' official APIs, SecFlow routed requests through private proxy servers linked to the niestools.com domain.
The AI models did not break into systems on their own; they automated and organised traditional tasks including vulnerability scanning, credential testing, exploit attempts, web shell deployment, data and evidence collection, and report generation, with the operators building the infrastructure connecting those capabilities to real intrusions.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Model choice is becoming a line item, and the differentiator moved up the stack1 distinct publisher
product
Swapping a frontier API for a self-hosted open-weight model relocates the audit question1 distinct publisher
leadership
Investors Are Pricing Anthropic Like Infrastructure. Check Your Exit Clauses.1 distinct publisher
invest
Anthropic calls Chinese AI distillation 'theft,' citing national security risks1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific to the byte, sourced to one telescope
The artefacts here are the kind you cannot invent casually — 37 blocks with verified byte counts, 822 records, 1.28GB across 949 files, a page named extract.aspx, a proxy domain. That granularity is what lifts the score. What holds it down is that all of it reaches us through a single Security Affairs write-up of a single Hunt.io report, with the report itself not in front of us, no victim confirming a breach, and no second researcher who has looked at the same directories.
Real intrusions, one observer
Attacker-side uptake is not hypothetical: a working framework, three commercial models behind one interface, and data actually out the door from a government office system, an education platform and a campus-card database. That is adoption you can point at. But the entire footprint is what one firm found by walking into open directories, and by the reporting's own admission the models organised routine work rather than doing anything a skilled operator could not. Half a picture of a practice that may be far wider or far narrower than these five directories.
Headline runs ahead of its own body
Security Affairs' framing — hackers using AI agents in a multi-country campaign — is the loudest thing in the piece, and the piece then spends a paragraph saying the models broke into nothing on their own. The overstatement is modest and mostly lives in the packaging: 'AI agents' where the substance is task automation behind a swappable model profile, with humans owning the exploitation, the proxies and the persistence. Credit where due, the reporting deflates itself rather than leaving the reader to do it.
The finder sells the finding method
Hunt.io scans for exposed infrastructure for a living, and this campaign was reconstructed precisely because five directories were left open — the research doubles as a demonstration of the product. That is legitimate work with an obvious commercial upside, and it is the only lens available here. Meanwhile the parties with reason to push back, the three model vendors whose profiles were plugged into the framework, are absent from the story; traffic routed through resale proxies never touched their APIs, so they have neither telemetry to offer nor an obvious reason to volunteer any.
Enough to act on, not enough to settle
We would move on the defensive specifics tomorrow — the fake MySQL bait, PNG-channel payloads and open agent consoles are cheap to check and expensive to ignore. We would not yet treat 'China-linked' or 'second campaign' as established, because attribution rests on assertion, the first campaign goes unnamed, and one publisher relaying one firm gives us nothing to triangulate against.