China-Linked Hackers Weaponize Claude Code and DeepSeek in Government Intrusion Campaign
ID: 17c14048-83f9-5359-b377-234cda97f5ee
STIX ID: report--17c14048-83f9-5359-b377-234cda97f5ee
Feed Name: GBHackers
A suspected China-linked campaign operating a cluster of Hong Kong-hosted servers used TencShell and related implants to compromise government and industry targets in Afghanistan, Thailand, Taiwan and perform reconnaissance against US entities; operators exposed stolen source code, credentials and sensitive databases and weaponized LLMs (Anthropic Claude Code and DeepSeek-v4-pro) to automate exploitation, payload generation, and phishing development, with multiple indicators of compromise and hashes provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
