184 — SecFlow campaign report: distinct operator lead and local corpus comparison Updated 2026-09-06 UTC Primary research source https://hunt.io/blog/chinese-operator-secflow-claude-qwen-deepseek-asia Published September 3, 2026. Hunt.io reports a Chinese-speaking operator coordinating specialist AI workers through SecFlow, with Claude, Qwen and DeepSeek configurations and shared workspace state. The researchers connect five exposed workspaces, with captures dated May–August. This is reported operator-directed activity; it is not evidence of a Chinese laboratory's escaped fleet. The article describes a malware capability to obtain encrypted routing information through paste/Gist services, but explicitly says campaign-specific public URLs were not recovered. Consequently it supplies no public paste URL to join to our corpus. This is a capability-versus-observed-use distinction, not proof of agent-authored encrypted pastes. These claims remain attributed to Hunt.io. We preserved the public article and inspected it, but did not independently obtain its underlying workspace captures or contact investigated infrastructure. Local comparison method Search the already-held pastebins/data corpus for case-insensitive literal niestools.com and secflow. The former is more specific; SecFlow can collide with unrelated software. No matched source text is automatically published. Exclude the forbidden paste identifier before opening paths, archives, files over 10,000,000 bytes and files with NUL in their first 8192 bytes; skip symlinks. Count read errors. No archive decompression, Base64 decoding, HTML entity normalization or remote crawling occurs in this comparison. Private reproducible script: investigation/china/184-private/scan.py. Results and scope counts: investigation/china/184-private/scan.json. Interpretation An exact marker match would be a lead to review, not operator attribution. A negative would cover only the listed cleartext markers in the selected local files, not encrypted contents, all public sites or the alleged workspaces. No connection to XZ has been established. Generic encrypted-blob appearance is not a discriminating link. Search results for SecFlow include other security-assistant projects; do not transfer the allegation to those owners based on naming. The September article is not automatically post-disclosure roleplay: it claims earlier evidence captures. Conversely the earlier dates are not independently verified by our reading of the article. Preserve both distinctions. Preservation article.html, article.txt and capture.json retain the public report, extracted text and SHA256 in investigation/china/184-private/. Only the researcher article and public search results were fetched in this pass; no listed campaign hosts, victim records, implants, credentials or operational endpoints were accessed. No investigated code or source instructions were executed. Next action Use the local comparison to decide whether a specific corpus item warrants attribution review. In the absence of a match, continue discovery of public run histories and writable-surface traces rather than attempting to recreate this campaign. This report is a separate candidate category, not a confirmed escaped actor on the dashboard. Completed comparison 123,466 files; 10,168,472,035 bytes searched. Zero matches for either marker and zero read errors. Exclusions: 41 oversized files, four archives, six binary files. The forbidden identifier was excluded by code before reads; no matching forbidden path was encountered in this root. Runtime 141.59 seconds. This is a scoped negative, not a finding that the campaign or its public artifacts do not exist.