A Chinese-speaking hacking group has integrated Claude, Qwen, and DeepSeek AI models into automated attack chains, breaching government systems, political archives, and educational platforms across Asia. The campaign, uncovered by threat intelligence firm Hunt.io, used commercial AI to handle reconnaissance, exploitation, and data theft at scale.
The operation hit targets in Taiwan, Indonesia, mainland China, and Vietnam. Compromised systems included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education networks in mainland China, and industrial hosts in Da Nang. Five exposed directories tied the attacks together through shared infrastructure, reused accounts, and a common SOCKS proxy endpoint.
How the Fengtai government breach unfolded
A Fengtai District government environment sustained the heaviest damage. Attackers broke in through an internet-facing Office Automation system by uploading ASPX files via a file-management handler that returned web-accessible locations. This gave them server-side code execution inside the application.
They extracted a roughly 75.8MB LSASS memory dump containing authentication material, split across 37 chunks. The operators also collected SAM and SYSTEM registry hives, then deployed a server-side page called extract.aspx to pull Windows password-hash material from the dump. From there, they gathered 822 OA account records and created a new privileged account. The OA repository held 949 attachments totaling approximately 1.28GB.
Recovered material included government workflow documents, health-related records, a chronic-disease report with patient information, and Windows credentials.
AI agents divided the labor
The attackers used a tool called SecFlow to break the intrusion into discrete tasks. AI agents powered by Claude, Qwen, and DeepSeek handled reconnaissance, exploitation, collection, and reporting. Hunt.io researchers also found an exposed management backend belonging to a Chinese education AI platform. In a separate compromise, the operators obtained root database access to a university campus-card system.
This campaign is distinct from one observed in July, when a Chinese-speaking operator embedded Claude Code and DeepSeek into intrusions across four countries. The new activity shares infrastructure overlaps but has not been linked to a specific threat actor. Hunt.io attributes it to a Chinese-speaking attacker with moderate confidence.
The findings follow a 2025 campaign in which a Chinese state-sponsored group targeted roughly 30 organizations, including government agencies, using Claude Code.
Why this matters for government security teams
Attackers are now automating entire intrusion phases with off-the-shelf AI models. When an adversary can task an AI agent with parsing LSASS dumps, searching for password hashes, and creating privileged accounts, the speed of post-compromise activity accelerates sharply. Government security teams should review whether their detection engineering accounts for AI-driven tooling that can chain these actions without human pauses. For analysts building defenses against these techniques, AI for Cybersecurity Analysts training covers the detection and response skills that match this threat profile. Broader AI for Government resources can help agencies assess where automated attack patterns intersect with public-sector infrastructure.
Your membership also unlocks: