logo

China-Linked Hackers Weaponize Claude Code and DeepSeek in Government Intrusion Campaign

ID: 17c14048-83f9-5359-b377-234cda97f5ee

STIX ID: report--17c14048-83f9-5359-b377-234cda97f5ee

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

Author: Mayura Kathir

...
...

A suspected China-linked campaign operating a cluster of Hong Kong-hosted servers used TencShell and related implants to compromise government and industry targets in Afghanistan, Thailand, Taiwan and perform reconnaissance against US entities; operators exposed stolen source code, credentials and sensitive databases and weaponized LLMs (Anthropic Claude Code and DeepSeek-v4-pro) to automate exploitation, payload generation, and phishing development, with multiple indicators of compromise and hashes provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.