logo

Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries

ID: 9c04fe07-3ff0-5332-ae64-e8a2fbfdfc00

STIX ID: report--9c04fe07-3ff0-5332-ae64-e8a2fbfdfc00

Feed Name: Hunt.io Blog

Threat Score
88/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

...
...

This report documents an active, likely China-linked intrusion campaign discovered through an exposed open directory that contained payloads, exploit code, operator logs, and cloned credential-harvesting pages; operators used TencShell-related C2s and a second framework called “Gshell” across Hong Kong-hosted servers to target government and financial entities in Taiwan, Thailand, Afghanistan and beyond, leveraging custom exploits, multi-architecture malware, and a split LLM architecture (Claude Code for execution and DeepSeek-v4-pro for reasoning) to automate reconnaissance, exploit development, and phishing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.