Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries
ID: 9c04fe07-3ff0-5332-ae64-e8a2fbfdfc00
STIX ID: report--9c04fe07-3ff0-5332-ae64-e8a2fbfdfc00
Feed Name: Hunt.io Blog
This report documents an active, likely China-linked intrusion campaign discovered through an exposed open directory that contained payloads, exploit code, operator logs, and cloned credential-harvesting pages; operators used TencShell-related C2s and a second framework called “Gshell” across Hong Kong-hosted servers to target government and financial entities in Taiwan, Thailand, Afghanistan and beyond, leveraging custom exploits, multi-architecture malware, and a split LLM architecture (Claude Code for execution and DeepSeek-v4-pro for reasoning) to automate reconnaissance, exploit development, and phishing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
