TGViewer
CTT Report Hub CTT Report Hub @aptreports · 3.52K subscribers
Post #32151 22
#ParsedReport #CompletenessHigh
03-09-2026

Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asia

https://hunt.io/blog/chinese-operator-secflow-claude-qwen-deepseek-asia

Report completeness: High

Threats:
Secflow_tool
Glutton
Shellshock_vuln
Spring4shell
Ghostcat
Log4shell_vuln
Supply_chain_technique
Winrm_tool
Secbox_tool
Yamux_tool
Dead_drop_technique
Nmap_tool
Nuclei_tool
Credential_dumping_technique

Victims:
Government, Education, Political party archives, Industrial systems, Telecommunications

Industry:
Telco, Healthcare, Education, Government

Geo:
Vietnamese, Indonesia, Taiwanese, Taiwan, Afghan, Vietnam, China, Indonesian, Asia, Chinese

CVEs:
CVE-2020-1938 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- apache geode (1.12.0)
- apache tomcat (<7.0.100, <8.5.51, <9.0.31)

CVE-2024-4956 [Vulners]
CVSS V3.1: 7.5,
Vulners: Exploitation: True

CVE-2021-44228 [Vulners]
CVSS V3.1: 10.0,
Vulners: Exploitation: True
Soft:
- siemens 6bk1602-0aa12-0tp0_firmware (<2.7.0)

CVE-2021-29441 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- alibaba nacos (<1.4.1)

CVE-2014-6271 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- gnu bash (le4.3)

CVE-2021-43798 [Vulners]
CVSS V3.1: 7.5,
Vulners: Exploitation: True
Soft:
- grafana (<8.0.7, <8.1.8, <8.2.7, 8.0.0, 8.3.0)

CVE-2016-4437 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- apache aurora (<0.18.1)
- apache shiro (<1.2.5)

CVE-2022-22965 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- vmware spring_framework (<5.2.20, <5.3.18)


TTPs:
Tactics: 8
Technics: 12

IOCs:
IP: 16
File: 19
Command: 1
Url: 6
Path: 3
Hash: 25

Soft:
Claude, Claude Code, DeepSeek, Qwen, MySQL, Linux, Nacos, OpenAI, NET Framework, NET Core, have more...

Algorithms:
aes, base64, aes-256-cbc, aes-256-gcm, xor

Functions:
shell_exec

Win API:
CreateProcessW, CreateProcessWithTokenW, NET

Languages:
php, golang, java, javascript

Links:
https://github.com/Wei-Shaw/sub2api
hunt.io Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asia Hunt.io identified five exposed directories revealing a SecFlow-orchestrated campaign that used Claude, Qwen, and DeepSeek workers to target government, education, and consular systems across Asia
More from @aptreports
  1. Oct 11, 2026#ParsedReport #ChatGPT #Translated Autotext: (TI Report Analyser + ChatGPT + Auto Translat…
  2. Oct 11, 2026#ParsedReport #GeneratedSchema Generated with GPT-4
  3. Oct 11, 2026#ParsedReport #ExtractedSchema Classified images: code: 2, schema: 1
  4. Oct 11, 2026#ParsedReport #CompletenessLow 09-10-2026 When a Wallet Drainer Asks DNS Where to Go https…
  5. Oct 11, 2026#ParsedReport #ChatGPT #Translated Autotext: (TI Report Analyser + ChatGPT + Auto Translat…
  6. Oct 11, 2026#ParsedReport #GeneratedSchema Generated with GPT-4
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →