Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign

Chinese-Speaking Operator "Nie" Uses SecFlow AI (TL-2026-2325), also tracked as SecFlow, is a high-severity advanced persistent threat campaign, first published 2026-09-04. It is attributed to Nie (China) with medium confidence, affects GNU Bash, references 8 CVEs (CVE-2014-6271, CVE-2020-1938, CVE-2022-22965), maps to 17 MITRE ATT&CK techniques (T1003, T1021, T1027), and is covered by 9 detection rules and 29 indicators of compromise.

Key facts for TL-2026-2325

Threat ID
TL-2026-2325
Also known as
SecFlow
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-09-04
Last reviewed
2026-09-04
Attribution
Nie
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, political, education, health, industrial
Target regions
taiwan, indonesia, china, vietnam
Detection rules
9
Indicators of compromise
29

Malware and tooling in Chinese-Speaking Operator "Nie" Uses SecFlow AI

Malware and tooling: Glutton, SecBox, SecFlow, Sub2API

Hunt.io identified a Chinese-speaking threat actor operating under the handle "Nie" (infrastructure family niestools.com) running a custom AI-agent orchestration framework, SecFlow, that interchangeably drives Claude, Qwen, and DeepSeek models through private proxy relays to automate reconnaissance, exploitation, and post-exploitation across government, education, and industrial targets in Taiwan, Indonesia, China, and Vietnam. The operator combined eight known n-day web vulnerabilities, ASPX/PHP/JSP webshells, the PNG-steganographic GLUTTON webshell framework, and a cross-platform C2 implant ("SecBox") to exfiltrate LSASS memory, registry hives, OA records, and AI-platform secrets, and is the second AI-orchestrated intrusion campaign Hunt.io has documented within roughly two months.

How Chinese-Speaking Operator "Nie" Uses SecFlow AI works

In a report published September 3, 2026, Hunt.io documented a Chinese-speaking threat actor operating the handle "Nie" who built a private AI-agent orchestration layer called SecFlow. SecFlow wraps Anthropic's Claude Agent Client Protocol (@agentclientprotocol/claude-agent-acp) and Alibaba's Qwen-Code runtime (@qwen-code/qwen-code) to let an operator swap between five model profiles -- claude-acp, deepseek-v4-pro, deepseek-v4-pro-anthropic, deepseek-v4-pro-official, and qwen-code -- without changing the task interface. Requests are routed through operator-controlled reverse proxies (claude.niestools.com, deepseek.niestools.com) rather than official vendor APIs, and a companion chatgpt.niestools.com endpoint exposed an open-source Sub2API gateway (Wei-Shaw/sub2api) used to pool and redistribute upstream LLM subscriptions. SecFlow's own configuration corpus (SKILL.md, references/vuln-types/*, references/reporting/*) encodes a full offensive workflow -- initialization, reconnaissance, exploitation, post-exploitation, and report generation -- covering file upload, command injection, template injection, SQL injection, Java deserialization, SSRF/cloud metadata, authentication bypass, and known-CVE playbooks.

Operationally, the actor chained eight n-day vulnerabilities -- Shellshock (CVE-2014-6271), Ghostcat (CVE-2020-1938), Spring4Shell (CVE-2022-22965), an Apache Shiro default-key deserialization flaw (CVE-2016-4437), a Grafana plugin path-traversal (CVE-2021-43798), a Sonatype Nexus Repository path-traversal (CVE-2024-4956), a Nacos AuthFilter bypass (CVE-2021-29441), and Log4Shell (CVE-2021-44228) -- along with a fake MySQL server (fakeserver_new.py) that returned malicious deserialization payloads to any Java client that connected to it, and Java class-based command-interpreter invocation, to obtain initial footholds. Confirmed victims include Taiwan's Kuomintang Party History Archives (via Shellshock against /gs32/kmt/index.htm), Indonesia's Ministry of Foreign Affairs (PHP webshells disguised as WordPress core/plugin files, AES-256-CBC-encrypted command channel), a Fengtai District, China government Office Automation (OA) environment, and industrial hosts in Da Nang, Vietnam.

The Fengtai OA intrusion illustrates the full kill chain: a FileManage upload handler allowed an ASPX webshell (cmd.aspx) to be planted; Windows discovery commands (whoami, hostname, tasklist, sc query) enumerated the host; ASPX-to-SQL bridges (sqldump.aspx, sql6.aspx) reached internal Oracle and MSSQL (via xp_cmdshell) tiers; ASPX implementations of Potato-style privilege-escalation techniques (potato.aspx/potato3.aspx/potato4.aspx/potato4r.aspx) abused Windows print, EFSRPC, and LSARPC token-coercion primitives with CreateProcessWithTokenW to reach SYSTEM; a pre-existing 75.8 MB LSASS dump found in an OA attachment store was split into 37 blocks and pulled out over an authenticated SOCKS5 relay via down.aspx (plain) and downx.aspx (XOR key 0xAA); extract.aspx then mined the dump for password-hash material alongside separately harvested SAM/SYSTEM registry hives; sqldump.aspx/sql6.aspx exfiltrated 822 OA user records and doc_helper.aspx/doc_view_666b2dde.aspx exfiltrated 949 attachments (~1.28 GB) of government and health records; the operator also inserted a new privileged OA account for durable access; and dl_e6.aspx/launchfw.aspx retrieved a second-stage implant (c22.exe, staged as fw.exe) from 158.247.234.124:18000 and launched it via Process.Start()/WMI Win32_Process.Create.

The recovered GLUTTON webshell framework hides executable bytecode inside PNG pixel data (row-major R/G/B channel bytes XORed against the 16-byte ASCII key "d0c41072a0dc784c" and terminated by a 0xFF 0x88 0x00 marker), generates JSPX/ASP.NET/SOAP/.NET-Core-Razor server-side loaders in raw, "confusion" (CDATA-obfuscated), and Unicode-JSPX variants, and exposes a Model Context Protocol (MCP) interface (glutton-mcp.md) offering full target management, file operations, shell execution, process control, database access, port-forwarding, and payload-generation tools. The separately recovered SecBox implant is a cross-platform (Windows/Linux) backdoor that impersonates a "System Configuration Utility" (internal name syscfg), communicates over TCP/TLS/WebSocket/KCP/QUIC multiplexed with Yamux, and resolves replacement C2 endpoints via a Dead Drop Resolver that decrypts AES-256-GCM blobs fetched from Pastebin/GitHub to yield comma-separated TCP, WebSocket, and TryCloudflare (trycloudflare.com) fallback routes -- letting the operator rotate infrastructure (129.211.184.149, 158.247.234.124:18000, 207.148.109.245:18000) without redeploying binaries. A separate compromise of an unauthenticated Chinese education-sector AI platform's management backend exposed 23 AI agent configurations, 14 API secret credentials (including Dify application keys and a Coze private key), internal service addresses, and 104 AI chatbot conversation logs containing structured student-profile data (names, student numbers, advisers, departments, grades, majors) -- and the same management endpoint accepted an unauthenticated configuration-write request, creating a supply-chain/tampering risk to the platform's production AI agents.

Attribution rests on the recovered handle "Nie," which appears in a SOCKS proxy credential (103.45.65.93:35888), in SecFlow's own agent-skill tasking metadata, in GLUTTON MCP binary build paths (C:\Users ie\.cargo\..., /Users/nie/Project/glutton/...), and as the basis for the niestools.com domain family. Hunt.io consolidated five open directories sharing the same SOCKS endpoint, 120 cross-workspace file-content matches, reused SecFlow/GLUTTON artifacts and accounts, and a direct payload-hosting link between the fake-MySQL deserialization host and the second-stage implant host. This is the second AI-orchestrated intrusion campaign Hunt.io has documented in roughly two months, following a June 2026 campaign (discovered while pivoting on TencShell C2 infrastructure) that paired Claude Code with DeepSeek-v4-pro against government and financial-sector targets in Afghanistan, Thailand, and Taiwan, with reconnaissance of 5,890+ government hosts across ten countries.

MITRE ATT&CK techniques used in TL-2026-2325

Credential Access

T1003 OS Credential Dumping; T1552 Unsecured Credentials

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1078 Valid Accounts

Execution

T1059 Command and Scripting Interpreter

Discovery

T1082 System Information Discovery

Command and Control

T1090 Proxy; T1572 Protocol Tunneling

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Privilege Escalation

T1134 Access Token Manipulation

Collection

T1213 Data from Information Repositories

Persistence

T1505 Server Software Component

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1587 Develop Capabilities

Reconnaissance

T1595 Active Scanning

Affected products and versions in Chinese-Speaking Operator "Nie" Uses SecFlow AI

  • GNU — Bash
    Vulnerable versions: prior to the CVE-2014-6271 fix (Shellshock)
    Fixed in: patched bash releases post-September 2014
  • Apache Software Foundation — Tomcat
    Vulnerable versions: 9.0.0.M1-9.0.31; 8.5.0-8.5.51; 7.0.0-7.0.100 (Ghostcat)
    Fixed in: 9.0.31+; 8.5.51+; 7.0.100+
  • VMware / Spring — Spring Framework
    Vulnerable versions: 5.3.0-5.3.17; 5.2.0-5.2.19 (Spring4Shell)
    Fixed in: 5.3.18+; 5.2.20+
  • Apache Software Foundation — Shiro
    Vulnerable versions: prior to 1.2.5 (default rememberMe key)
    Fixed in: 1.2.5+
  • Grafana Labs — Grafana
    Vulnerable versions: 8.0.0-beta1 through 8.3.0
    Fixed in: 8.3.1+
  • Sonatype — Nexus Repository
    Vulnerable versions: prior to 3.68.1
    Fixed in: 3.68.1+
  • Alibaba — Nacos
    Vulnerable versions: prior to 1.4.1
    Fixed in: 1.4.1+
  • Apache Software Foundation — Log4j
    Vulnerable versions: 2.0-beta9 through 2.14.1 (Log4Shell)
    Fixed in: 2.17.1+

Remediation for Chinese-Speaking Operator "Nie" Uses SecFlow AI

Patches

  • Bash: apply the CVE-2014-6271 (Shellshock) fix, functions bundled in the environment must not be defined via trailing exported function syntax
  • Apache Tomcat: upgrade past 9.0.31 / 8.5.51 / 7.0.100 to remediate Ghostcat (CVE-2020-1938) or disable the AJP connector if unused
  • Spring Framework: upgrade to 5.3.18+/5.2.20+ for Spring4Shell (CVE-2022-22965); ensure JDK < 9 data-binding hardening is applied
  • Apache Shiro: upgrade to 1.2.5+ to remove the hardcoded default rememberMe AES key (CVE-2016-4437)
  • Grafana: upgrade to 8.3.1+ for the plugin path-traversal fix (CVE-2021-43798)
  • Sonatype Nexus Repository: upgrade to 3.68.1+ for the path-traversal fix (CVE-2024-4956)
  • Alibaba Nacos: upgrade to 1.4.1+ to close the AuthFilter User-Agent bypass (CVE-2021-29441)
  • Apache Log4j: upgrade to 2.17.1+ for Log4Shell (CVE-2021-44228); remove JndiLookup class from older deployments that cannot be upgraded immediately

Immediate actions

  • Block the identified operator infrastructure at perimeter/proxy/DNS: 81.70.240.170, 43.99.61.170, 152.42.200.25, 129.211.184.149, 159.223.64.67, 103.45.65.93, 43.162.217.10, 158.247.234.124, 207.148.109.245, 211.159.155.240, and the niestools.com domain family
  • Hunt for the named ASPX webshell filenames (cmd.aspx, down.aspx, downx.aspx, extract.aspx, sqldump.aspx, sql6.aspx, doc_helper.aspx, doc_view_666b2dde.aspx, dl_e6.aspx, dl_v11.aspx, dl_icn.aspx, launchfw.aspx, potato4.aspx) and the PHP webshell paths mimicking WordPress core/plugin files under wp-content/ and wp-includes/
  • Audit any Java application accepting attacker-controlled MySQL connections or wire-protocol input for unsafe deserialization (fake MySQL server pattern) and restrict outbound access from database service accounts
  • Rotate credentials for any OA/application accounts created outside normal provisioning workflows and review recently added privileged accounts
  • Restrict or monitor outbound connections to *.trycloudflare.com and unexpected long-lived TCP/WebSocket sessions from server subnets
  • Rotate and scope-restrict any exposed AI-agent platform secrets (Dify application keys, Coze keys) and lock down unauthenticated management-plane endpoints on internal AI/LLM-gateway deployments

Workarounds

  • Where immediate patching of Log4j/Shiro/Nacos/Nexus/Grafana is not possible, disable or restrict the vulnerable feature (JNDI lookups, rememberMe cookie processing, AJP connector, plugin install path, repository browsing) and place a WAF rule in front of the affected endpoint
  • Disable direct internet exposure of internal database/OA management interfaces and require VPN/reverse-proxy authentication in front of file-manage/upload handlers

Longer-term hardening

  • Deploy EDR/behavioral detection tuned to Potato-family token-impersonation chains (CreateProcessWithTokenW following spoolsv/EFSRPC/LSARPC activity) and LSASS access from non-security-tool processes
  • Implement network egress controls and SOCKS5/tunneling detection to catch dead-drop-resolver-style C2 rotation via Pastebin/GitHub lookups
  • Enforce authentication and network segmentation on any internal AI-agent orchestration or LLM-gateway management planes (Sub2API-style aggregators, MCP servers) so configuration and secrets endpoints are never internet-reachable
  • Establish a patch-currency SLA for internet-facing Java/web middleware (Tomcat, Spring, Shiro, Grafana, Nexus, Nacos, Log4j) given this actor's demonstrated n-day exploitation breadth
  • Add PNG/image-carried payload detection (statistical anomalies in RGB channel entropy) to web application firewalls protecting file-upload and asset-serving endpoints

CVEs associated with Chinese-Speaking Operator "Nie" Uses SecFlow AI

CVE-2014-6271, CVE-2020-1938, CVE-2022-22965, CVE-2016-4437, CVE-2021-43798, CVE-2024-4956, CVE-2021-29441, CVE-2021-44228

Weaknesses (CWE) in Chinese-Speaking Operator "Nie" Uses SecFlow AI

CWE-78, CWE-22, CWE-94, CWE-502, CWE-287

Timeline of Chinese-Speaking Operator "Nie" Uses SecFlow AI

  • Hunt.io discovers a related AI-orchestrated intrusion campaign while pivoting on TencShell C2 infrastructure, uncovering an open directory (2,431 files, 80 subdirectories) tied to a Claude Code + DeepSeek-v4-pro operator targeting government and financial systems in Afghanistan, Thailand, and Taiwan.
  • An unauthenticated Chinese education-sector AI platform management backend is accessed, exposing 23 AI agent configurations, 14 API secret credentials, and 104 AI chatbot conversations containing student-profile data.
  • 822 OA user account records and 949 attachments (~1.28 GB) of government and health records are exfiltrated from the Fengtai OA system; a new privileged OA account is created for persistent access.
  • At the Fengtai OA environment, a pre-existing 75.8 MB LSASS memory dump is located, split into 37 blocks, and exfiltrated over an authenticated SOCKS5 relay; SAM/SYSTEM registry hives are separately collected.
  • Industrial hosts in Da Nang, Vietnam are identified among the operator's target set.
  • Indonesia's Ministry of Foreign Affairs is compromised via PHP webshells disguised as WordPress core/plugin files with an AES-256-CBC-encrypted command channel.
  • Taiwan's Kuomintang Party History Archives is compromised via a Shellshock (CVE-2014-6271) exploit against /gs32/kmt/index.htm.
  • Hunt.io identifies the SecFlow-orchestrated intrusion campaign, including compromise of a Fengtai District, China government Office Automation (OA) environment.
  • Hunt.io publishes its findings on the SecFlow/GLUTTON campaign after disclosing details to national CERTs under TLP:AMBER; the report is identified as the second AI-orchestrated intrusion campaign Hunt.io has documented within roughly two months.
  • Secondary outlets, including SecurityAffairs, publish coverage summarizing the Hunt.io report.

Sources cited for Chinese-Speaking Operator "Nie" Uses SecFlow AI

More in apt

Detection coverage for TL-2026-2325

As of 2026-09-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2325 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats