Claude, DeepSeek, and Qwen AI agents used to target governments across Asia
The campaign is attributed to a Chinese-speaking attacker with moderate confidence.

Image by Shutterstock
- Hunt.io says Chinese-speaking hackers used Claude, Qwen, and DeepSeek to automate attacks on Asian targets.
- Targets included Taiwan’s Kuomintang archives, Indonesia’s foreign ministry, Chinese government systems, and Vietnam industrial hosts.
- Attackers gathered 822 office automation account records and accessed government, health, and education data.
- Researchers linked five exposed directories but have not identified a specific hacking group.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Chinese-speaking hackers have plugged Claude, Qwen, and DeepSeek into their hacking infrastructure to automate cyberattacks against government and other targets across Asia, according to findings from threat intelligence firm Hunt.io.
Hunt.io describes the operation as separate from the campaign observed in July, when a Chinese-speaking operator embedded Claude Code and DeepSeek into intrusions across four countries.
The new campaign utilized commercial AI models, with targets including Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam.
In total, Hunt.io discovered five exposed directories associated with the campaign. They linked them through shared infrastructure, including a SOCKS proxy endpoint that appeared across the environments. The systems contained common SecFlow and GLUTTON artifacts, reused accounts, and a direct second-stage payload link.
According to the researchers, a Fengtai District government environment was hit hardest, “where the operator achieved command execution, collected LSASS and registry hives, accessed government and health records, and deployed multiple Windows implants. Separate activity exposed a Chinese education AI platform and obtained root database access to a university campus-card system.”
In that compromise, the attackers broke into an internet-facing government Office Automation system via a file-management handler that accepted uploaded ASPX files and returned web-accessible locations.
This allowed the hackers to run server-side tooling inside the application. They eventually transferred a roughly 75.8MB LSASS memory dump containing sensitive authentication material in 37 separate chunks.
They also collected the SAM and SYSTEM registry hives and deployed a server-side page, extract.aspx, that searched the dump for Windows password-hash material.
From there, they gathered 822 OA account records and created a new active OA account with elevated privileges. The OA repository contained 949 attachments totaling approximately 1.28GB.
According to the researchers, recovered material included government workflow and administrative information, selected health-related documents, a chronic-disease report containing patient information, and Windows credential material.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
SecFlow divided the attack into tasks and assigned them to AI agents powered by Claude, Qwen, and DeepSeek for reconnaissance, exploitation, collection, and reporting.
Researchers also discovered an exposed management backend belonging to a Chinese education AI platform.
The campaign is attributed to a Chinese-speaking attacker with moderate confidence, but a specific actor has not been established.
In 2025, a Chinese state-sponsored campaign targeted roughly 30 organizations, including government agencies, using Claude Code.