Hunt Intelligence, Inc. research team identified five exposed open directories revealing a campaign using an orchestration framework called SecFlow to coordinate Claude, Qwen, and DeepSeek AI workers across intrusions targeting government, education, consular, and healthcare systems in Asia.
Public source
Publisher name
Public post
🇨🇳 🤖 𝗡𝗘𝗪 𝗥𝗘𝗦𝗘𝗔𝗥𝗖𝗛: 𝗖𝗵𝗶𝗻𝗲𝘀𝗲-𝗦𝗽𝗲𝗮𝗸𝗶𝗻𝗴 𝗢𝗽𝗲𝗿𝗮𝘁𝗼𝗿 𝗨𝘀𝗲𝘀 𝗔𝗜 𝗔𝗴𝗲𝗻𝘁𝘀 𝘁𝗼 𝗧𝗮𝗿𝗴𝗲𝘁 𝗚𝗼𝘃𝗲𝗿𝗻𝗺𝗲𝗻𝘁 𝗮𝗻𝗱 𝗘𝗱𝘂𝗰𝗮𝘁𝗶…
Company
Hunt Intelligence, Inc.
Unmask Hidden Threats. Track. Investigate. Take Action.
- Industry
- Technology, Information and Internet
- Location
- Remote, US
- Company size
- 11–50 employees
About Hunt Intelligence, Inc.
Hunt.io is a service that provides threat intelligence data about observed network scanning and cyberattacks. This data is collected by a worldwide distributed network of sensors. All interactions with sensors are registered, analyzed, and used to create network host profiles.
See moreLatest activity
Latest activity from Hunt Intelligence, Inc.
6 signals
Customers & Market
Hunt Intelligence, Inc. is part of the investigation on Threat Hunting Labs.
Research & Knowledge
Hunt Intelligence, Inc. filtered providers by Russia and found JSC TIMEWEB at the top of the 30-day view with 162 C2s alongside IOC and open-directory activity.
Research & Knowledge
Hunt Intelligence, Inc. parsed the campaign logs of a Hetzner box to find 3,562 distinct Redis servers compromised out of 12,966 targeted across two separate runs.
Discover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
Palo Alto Networks Unit 42
Palo Alto Networks Unit 42 investigated a breach where a threat actor deployed autonomous AI agents to execute an intrusion in under 10 hours.
Research & Knowledge
PathScience
PathScience published a report detailing commercial AI models being used as operational components inside active intrusions across government, education, and consular systems in Asia, featuring an orchestration framework built by an operator coordinating Claude, Qwen, and DeepSeek workers across five workspaces.
Research & Knowledge
Palo Alto Networks
Palo Alto Networks Unit 42 published an investigation revealing how a threat actor used frontier AI models to compress two weeks of complex intrusion tradecraft into less than 10 hours.
Research & Knowledge
AIMF Security
AIMF Security published research by GreyNoise documenting a campaign involving 824 attacker IP spoofing 13 AI crawler identities from 8 companies generating millions of requests targeting credentials and development files.
Research & Knowledge
VulnCheck