🌐 Contexte

Publié le 3 septembre 2026 par Hunt.io, cet article de recherche CTI documente une campagne d’intrusion attribuée à un opérateur sinophone non nommé, distincte d’une précédente campagne publiée en juillet 2026. La divulgation a été faite sous TLP:AMBER aux CERTs nationaux concernés avant publication.

🎯 Cibles identifiées

  • Archives du Parti Kuomintang (KMT) à Taïwan
  • Ministère des Affaires étrangères d’Indonésie
  • Gouvernement du district de Fengtai (Pékin, Chine continentale)
  • Plateforme IA éducative chinoise et système de carte universitaire
  • Systèmes industriels à Da Nang, Vietnam
  • Opérateur télécom afghan (reconnaissance réseau)

🤖 Infrastructure IA offensive : SecFlow

L’opérateur a déployé SecFlow, un framework d’orchestration IA qui répartit les tâches de reconnaissance, exploitation, collecte et reporting entre des workers spécialisés utilisant Claude (ACP), Qwen Code et DeepSeek. Les modèles sont interchangeables sans modifier l’interface de tâche. Des endpoints privés sous niestools.com proxifient le trafic vers les modèles.

🔓 Compromission du gouvernement de Fengtai (la plus étendue)

  • Accès initial via upload de webshells ASPX sur l’application OA (Office Automation) exposée sur Internet
  • Exécution de commandes Windows via cmd.aspx, WMI, CreateProcessW
  • Escalade de privilèges via variantes Potato (EFSRPC, LSARPC, impression Windows)
  • Vol de credentials : dump LSASS (~75,8 Mo) en 37 blocs, ruches SAM/SYSTEM, 822 comptes OA
  • Mouvement latéral vers Oracle et SQL Server via webshells SQL
  • Exfiltration : 949 pièces jointes (~1,28 Go), dossiers administratifs, données de santé (rapport maladies chroniques)
  • Implant déployé : SecBox (Go), masqué en syscfg.exe (System Configuration Utility)

🛠️ Outillage technique

  • SecFlow : orchestrateur IA avec skill External Pentest (SKILL.md), playbooks par type de vulnérabilité
  • GLUTTON : framework de webshells (JSP, ASPX, .NET, Node.js) avec transport stéganographique PNG (XOR key d0c41072a0dc784c, terminateur FF 88 00), obfuscation Unicode/XML
  • SecBox : implant Go multiprotocole (TCP, TLS, WebSocket, KCP, QUIC), multiplexage Yamux, Dead Drop Resolver (Pastebin/GitHub Gist, AES-256-GCM)
  • Fake MySQL : service malveillant déclenchant une désérialisation Java sur les clients vulnérables
  • Webshells : cmd.aspx, down.aspx (XOR 0xAA), sqldump.aspx, potato.aspx, dl_*.aspx, etc.

🔎 CVEs exploitées

  • CVE-2014-6271 (Shellshock) — Archives KMT
  • CVE-2020-1938 (Ghostcat/AJP) — Applications Liuzhou
  • CVE-2022-22965 (Spring4Shell) — Applications Liuzhou
  • CVE-2016-4437 (Shiro désérialisation)
  • CVE-2021-43798 (Grafana path traversal)
  • CVE-2024-4956 (Nexus path traversal)
  • CVE-2021-29441 (Nacos auth bypass)
  • CVE-2021-44228 (Log4Shell)

🔗 Attribution infrastructure

Le handle Nie apparaît dans les credentials SOCKS (103.45.65.93:35888), les chemins de build GLUTTON (C:\Users\nie\.cargo\...), et le domaine niestools.com (subdomains : claude, deepseek, chatgpt, proxy, wiki, glutton). Cinq open directories liés par un endpoint SOCKS partagé ont été identifiés.

📄 Type d’article

Publication de recherche CTI technique détaillée, visant à documenter une campagne active, partager des IoCs exploitables et démontrer l’usage opérationnel de modèles IA commerciaux dans des intrusions offensives.

🧠 TTPs et IOCs détectés

Acteurs de menace

  • Nie (opérateur sinophone non attribué) (unknown) —

TTP

  • T1595 — Active Scanning (Reconnaissance)
  • T1190 — Exploit Public-Facing Application (Initial Access)
  • T1078 — Valid Accounts (Defense Evasion)
  • T1133 — External Remote Services (Initial Access)
  • T1090 — Proxy (Command and Control)
  • T1021.004 — Remote Services: SSH (Lateral Movement)
  • T1003 — OS Credential Dumping (Credential Access)
  • T1552.001 — Unsecured Credentials: Credentials In Files (Credential Access)
  • T1505.003 — Server Software Component: Web Shell (Persistence)
  • T1105 — Ingress Tool Transfer (Command and Control)
  • T1213 — Data from Information Repositories (Collection)
  • T1567 — Exfiltration Over Web Service (Exfiltration)

IOC

⚠️ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 4 septembre 2026 et n’ont pas fait l’objet d’une vérification externe. Un indicateur peut avoir été réattribué depuis : une IP de C2 peut redevenir un service légitime, un domaine sinkholé peut changer de propriétaire. Aucune garantie d’exactitude ni d’actualité — contrôlez leur validité avant tout usage opérationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.

Malware / Outils

  • SecFlow (framework)
  • SecBox (rat)
  • GLUTTON (framework)
  • Claude Code (ACP) (tool)
  • Qwen Code (tool)
  • DeepSeek (tool)
  • Sub2API (tool)
  • cmd.aspx (backdoor)
  • down.aspx (tool)
  • downx.aspx (tool)
  • sqldump.aspx (tool)
  • potato.aspx (tool)
  • fakeserver_new.py (fake MySQL) (tool)
  • CommonsBeanutils1.bin (loader)
  • CommonsCollections6.bin (loader)
  • Spring1.bin (loader)

🟢 Indice de vérification factuelle : 65/100 (haute)

  • ⬜ hunt.io — source non référencée (0pts)
  • ✅ 48961 chars — texte complet (fulltext extrait) (15pts)
  • ✅ 99 IOCs dont des hashes (15pts)
  • ⬜ 0/11 IOCs confirmés externellement (0pts)
  • ✅ 12 TTPs MITRE identifiées (15pts)
  • ✅ date extraite du HTML source (10pts)
  • ✅ acteur(s) identifié(s) : Nie (opérateur sinophone non attribué) (5pts)
  • ✅ 5/5 CVE(s) confirmée(s) (CIRCL) (5pts)

🔗 Source originale : https://hunt.io/blog/chinese-operator-secflow-claude-qwen-deepseek-asia