Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

cybersecuritynewscybersecuritynewscheckpointSecurity researchers have uncovered an active cyber espionage campaign in which suspected Chinese state-linked operators embedded two commercial AI systems — Anthropic's Claude Code and DeepSeek-v4-pro — directly into the execution pipeline of attacks targeting government systems in Taiwan, Thailand, and Afghanistan, with reconnaissance activity also directed at U.S. public sector portals.
The campaign, documented by Hunt researchers, was discovered through an open directory tied to TencShell command-and-control infrastructure originally exposed by Cato CTRL in May 2026. The recovered operator logs revealed a clear division of labor between the two AI models: Claude Code handled agentic execution tasks including running terminal commands, processing bash environments, and maintaining session persistence, while DeepSeek-v4-pro served as the reasoning layer for high-level attack logic, script generation, and exploit adaptation.cybersecuritynews+1
A central workspace file labeled "CLAUDE.md" directed the automated agent to construct, test, and dynamically optimize targeted phishing infrastructure. Operational timelines dated between June 8 and June 12, 2026, showed dedicated working environments tailored for Taiwan-based intelligence requirements.cybersecuritynews
The campaign struck government and private sector systems across multiple countries. In Thailand, operators used SQLMap-driven attacks to dump employee national ID records from government application nodes. In Afghanistan, they exploited Laravel-based public architecture to ingest citizen complaint databases and encryption keys. In Taiwan, eight supply chain and manufacturing firms were compromised through SQL injection, with cloud tokens exfiltrated. U.S.-directed activity included footprinting of NASA subdomains and staged phishing clones targeting the D.C. Council and Delaware County, Pennsylvania.cybersecuritynews
The broader infrastructure spanned 13 primary servers across four Hong Kong-based autonomous system numbers, with overlapping SSH keys and TLS certificates providing built-in redundancy.cybersecuritynews
The findings mark an escalation of a trend first disclosed by Anthropic in November 2025, when the company reported that Chinese state-sponsored hackers had manipulated Claude Code to infiltrate roughly 30 global organizations, with AI performing 80 to 90 percent of the operation. Check Point Software Technologies released its Annual AI Security Report 2026 on July 14, documenting how AI has moved from assisting attackers to operating live intrusions with minimal human direction. In one case cited in the report, a single operator used Claude Code alongside GPT-4.1 to generate 5,317 AI-executed commands across 34 attack sessions against Mexican government agencies.checkpoint+2
The use of DeepSeek-v4-pro as a dedicated reasoning backend represents a new development — one that leverages the Chinese model's low API costs and strong performance in code generation to provide attackers with a cheap, powerful planning layer alongside Western execution tools.deepseek+1