Hunt.io Links Agentic LLMs to Campaign Against Government Entities, But Attribution Remains Uncertain
Anthropic
DeepSeek
Hunt.io has published a study of a likely Chinese cyberespionage campaign, unique for traces of agentic AI usage, specifically Claude Code and DeepSeek-v4-pro. The investigation pivoted from the TencShell C2 cluster and uncovered an open directory with 2,431 files, including victim source code, logs, web shells, and scanned government hosts. While Hunt.io attributes the campaign to presumed Chinese operators with moderate confidence, it does not prove complete AI autonomy or link it to specific state groups.
In July 2026, Hunt.io published an analysis of a suspected Chinese cyberespionage campaign. Investigators found an open directory on a server in a Hong Kong infrastructure cluster, containing 2,431 files such as victim source code, operation logs, web shells, and exploitation scripts. Unusually, logs revealed persistent sessions of Claude Code 2.1.165 from 8 to 12 June 2026, with Claude Code handling agentic tasks and shell commands, while DeepSeek-v4-pro was used for reasoning and script refinement. However, Hunt.io cautions that this does not implicate the model vendors, and public data does not allow reliable attribution to a specific group; the assessment of Chinese origin is based on language, infrastructure, and targets, rated as moderately probable. The campaign used multiple initial access vectors, including SQL injection against a Taiwanese chemical company and a Thai state service, and exposed secrets in JavaScript files of a Taiwanese telecom equipment maker. The attackers also prepared phishing pages, including clones of WordPress login pages for US entities. Hunt.io emphasizes that while these AI tools increase operational tempo, they do not change the fundamental attack surface issues like open directories, leaked keys, and SQL injection. The report also draws parallels with Anthropic's November 2025 disclosure of campaign GTG-1002, but notes that linking both to the same actor is not supported by evidence.
- Abbreviations
- C2 = Command and Control — командный центр
- SHA-256 = Secure Hash Algorithm 256-bit — алгоритм хеширования
- TLS = Transport Layer Security — протокол безопасности
- SSH = Secure Shell — протокол удалённого доступа
- ARP = Address Resolution Protocol — протокол разрешения адресов
- DNS = Domain Name System — система доменных имён
- CT = Certificate Transparency — прозрачность сертификатов
- HTTP = Hypertext Transfer Protocol — протокол передачи гипертекста
- IP = Internet Protocol — интернет-протокол
- Jira = Jira (no expansion, product name) — Jira
- VPN = Virtual Private Network — виртуальная частная сеть
- SQL = Structured Query Language — язык структурированных запросов
- WAF = Web Application Firewall — межсетевой экран для веб-приложений
- MIME = Multipurpose Internet Mail Extensions — многоцелевые расширения интернет-почты
- IOC = Indicator of Compromise — индикатор компрометации
- TI = Threat Intelligence — разведка угроз
- LLM = Large Language Model — большая языковая модель
- RCE = Remote Code Execution — удалённое выполнение кода
- ARM = Advanced RISC Machine — архитектура ARM
- x86 = x86 architecture — архитектура x86
- CORS = Cross-Origin Resource Sharing — совместное использование ресурсов между источниками
- GitLab = GitLab (product name) — GitLab
- SAS = Shared Access Signature — подпись общего доступа
- SAST = Static Application Security Testing — статическое тестирование безопасности приложений
Source: Habr — хаб ИИ —
original
