Hackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Networks
Brief
The activity is separate from an earlier campaign involving Chinese-speaking operators, but shows a similar pattern: commercial AI models were used as operational tools during real intrusions.
The actors targeted Taiwan’s Kuomintang Party History Archives, Indonesia’s Ministry of Foreign Affairs, government systems in mainland China, and industrial organizations in Vietnam.
Researchers linked five exposed attacker workspaces by tracing a shared SOCKS proxy endpoint .
The infrastructure contained SecFlow, an AI orchestration framework that assigned reconnaissance, exploitation, data collection, and reporting tasks to specialized AI workers.
AI Agents Attack Governments
SecFlow allowed operators to switch between Claude, Qwen, and DeepSeek models without changing the task workflow. The agents received target details, proxy routes, tools, shared storage, and reporting instructions.
