03-09-2026
Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asia
https://hunt.io/blog/chinese-operator-secflow-claude-qwen-deepseek-asia
Report completeness: High
Threats:
Secflow_tool
Glutton
Shellshock_vuln
Spring4shell
Ghostcat
Log4shell_vuln
Supply_chain_technique
Winrm_tool
Secbox_tool
Yamux_tool
Dead_drop_technique
Nmap_tool
Nuclei_tool
Credential_dumping_technique
Victims:
Government, Education, Political party archives, Industrial systems, Telecommunications
Industry:
Telco, Healthcare, Education, Government
Geo:
Vietnamese, Indonesia, Taiwanese, Taiwan, Afghan, Vietnam, China, Indonesian, Asia, Chinese
CVEs:
CVE-2020-1938 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- apache geode (1.12.0)
- apache tomcat (<7.0.100, <8.5.51, <9.0.31)
CVE-2024-4956 [Vulners]
CVSS V3.1: 7.5,
Vulners: Exploitation: True
CVE-2021-44228 [Vulners]
CVSS V3.1: 10.0,
Vulners: Exploitation: True
Soft:
- siemens 6bk1602-0aa12-0tp0_firmware (<2.7.0)
CVE-2021-29441 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- alibaba nacos (<1.4.1)
CVE-2014-6271 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- gnu bash (le4.3)
CVE-2021-43798 [Vulners]
CVSS V3.1: 7.5,
Vulners: Exploitation: True
Soft:
- grafana (<8.0.7, <8.1.8, <8.2.7, 8.0.0, 8.3.0)
CVE-2016-4437 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- apache aurora (<0.18.1)
- apache shiro (<1.2.5)
CVE-2022-22965 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- vmware spring_framework (<5.2.20, <5.3.18)
TTPs:
Tactics: 8
Technics: 12
IOCs:
IP: 16
File: 19
Command: 1
Url: 6
Path: 3
Hash: 25
Soft:
Claude, Claude Code, DeepSeek, Qwen, MySQL, Linux, Nacos, OpenAI, NET Framework, NET Core, have more...
Algorithms:
aes, base64, aes-256-cbc, aes-256-gcm, xor
Functions:
shell_exec
Win API:
CreateProcessW, CreateProcessWithTokenW, NET
Languages:
php, golang, java, javascript
Links:
https://github.com/Wei-Shaw/sub2api