Back to feed

Hunt.io links Claude, DeepSeek, Qwen to Asian government cyberattacks

2 min
Hunt.io links Claude, DeepSeek, Qwen to Asian government cyberattacks

This digest was compiled by AI from multiple sources — links to the originals are below.

Hunt.io found Chinese-speaking hackers used Claude, Qwen, and DeepSeek to automate attacks on Asian targets, including Taiwan's Kuomintang archives and Indonesia's foreign ministry. Attackers gathered 822 office automation account records and accessed government, health, and education data. Researchers linked five exposed directories but have not identified a specific hacking group.

Key Facts

  • Hunt.io linked five exposed directories through shared infrastructure, including a SOCKS proxy endpoint.
  • A Fengtai District government environment was hit hardest, with command execution, LSASS and registry hive collection, and multiple Windows implants deployed.
  • Attackers transferred a 75.8MB LSASS memory dump in 37 chunks and collected SAM and SYSTEM registry hives.
  • The OA repository contained 949 attachments totaling approximately 1.28GB, including government workflow and health-related documents.
  • Targets included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, and industrial hosts in Da Nang, Vietnam.

Campaign Infrastructure

Hunt.io discovered five exposed directories associated with the campaign. The directories were linked through shared infrastructure, including a SOCKS proxy endpoint that appeared across the environments. The systems contained common SecFlow and GLUTTON artifacts, reused accounts, and a direct second-stage payload link. Researchers have not identified a specific hacking group behind the operation.

Fengtai District Compromise

A Fengtai District government environment was hit hardest, where the operator achieved command execution, collected LSASS and registry hives, accessed government and health records, and deployed multiple Windows implants. Attackers broke into an internet-facing government Office Automation system via a file-management handler that accepted uploaded ASPX files and returned web-accessible locations. They transferred a roughly 75.8MB LSASS memory dump containing sensitive authentication material in 37 separate chunks. They also collected the SAM and SYSTEM registry hives and deployed a server-side page, extract.aspx, that searched the dump for Windows password-hash material. From there, they gathered 822 OA account records and created a new active OA account with elevated privileges.

Data Exfiltration

The OA repository contained 949 attachments totaling approximately 1.28GB. Recovered material included government workflow and administrative information, selected health-related documents, a chronic-disease report containing patient information, and Windows credential material. Separate activity exposed a Chinese education AI platform and obtained root database access to a university campus-card system.

1 source

Time · lag behind first