Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries

0
Medium
Published: 07/14/2026 (07/14/2026, 21:17:46 UTC)
Source: AlienVault OTX General

Description

In June 2026, infrastructure pivoting from TencShell C2 nodes revealed an active intrusion campaign utilizing AI language models for attack automation. Thirteen Hong Kong-based servers across four ASNs exposed an open directory containing victim source code, custom exploits, operational logs, and cloned login pages with notes in Simplified Chinese. The operation employed Claude Code for execution and DeepSeek-v4-pro for attack logic, targeting government systems in Afghanistan, Thailand, and Taiwan, along with reconnaissance against U.S. government portals. The campaign also pursued financial services firms across Europe, Australia, and Asia. Attackers deployed TencShell implants, webshells, and custom exploits including SQL injection and Laravel deserialization attacks, successfully compromising administrative systems and exfiltrating sensitive data including citizen complaints and government employee information.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 12:41:37 UTC

Technical Analysis

This intrusion campaign, active as of June 2026, involves suspected Chinese operators using AI-powered tools—Claude Code for execution and DeepSeek-v4-pro for attack logic—to automate and orchestrate attacks against government and financial sectors across multiple countries. The attackers deployed TencShell implants and webshells, leveraging custom exploits such as SQL injection and Laravel deserialization vulnerabilities to gain administrative access and exfiltrate sensitive information. Evidence was uncovered on multiple Hong Kong-based servers revealing operational artifacts and victim data. The campaign includes reconnaissance against U.S. government portals and targets financial firms in Europe, Australia, and Asia. The operation uses supply chain targeting and phishing tactics as part of its attack vectors.

Potential Impact

Successful exploitation allowed attackers to compromise administrative systems of government entities and financial firms, leading to exfiltration of sensitive data including citizen complaints and government employee information. The campaign's use of custom exploits and webshell implants indicates a high level of operational capability and persistence. The exposure of victim source code and operational logs on attacker infrastructure suggests significant operational security lapses by the threat actors but also indicates the breadth and depth of the compromise. The targeting of multiple countries and sectors highlights the campaign's broad impact potential.

Defensive Guidance

No official patch or remediation guidance is provided in the available information. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Defenders should monitor for indicators related to TencShell implants, webshells, and the specific exploit techniques mentioned (SQL injection, Laravel deserialization). Given the use of AI-powered automation, enhanced detection of anomalous execution patterns and network traffic associated with Claude Code and DeepSeek tools is recommended. Organizations in the affected sectors and regions should review access controls, audit logs, and implement protections against the identified exploit techniques. Phishing defenses should be strengthened to mitigate initial access vectors. Note that this is an active campaign; timely threat intelligence updates are critical.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion"]
Adversary
null
Pulse Id
6a56a77a59a4d2b99d9aa87f
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip112.213.124.159
ip134.122.200.153
ip134.122.200.154
ip134.122.200.155
ip192.229.115.229
ip45.64.52.242
ip192.238.134.166
ip112.213.124.132
ip112.213.124.163
ip134.122.200.114
ip134.122.200.115
ip134.122.200.116
ip192.163.167.10
ip192.163.167.5
ip192.163.167.6
ip192.163.167.7
ip192.229.115.230
ip38.55.105.143
ip45.64.52.245
ip45.64.52.246

Hash

ValueDescriptionCopy
hash90b7b2c6f3d05234dc55678243039d7e51f0d54190239e5234a0005533337dc8
hash050b84a0d6105a98f443f0165368cc1c
hash4da236de055bfaf08ee21fb6b88442b4
hash1cac633d290a876fc1ead63c58de48575b67b1fc
hash66049dd42a29dde7481d5ca2951efec27214ce15
hash03f26cbfa3ca15fcb43f512aa4041732beeec267f9d1dc74a11f7b0bb32e86bb
hash2954639be599f23c2229a9743aba09a1d9d11bf2becc62bf353384437db37dee
hash64107e3e0a333f685d1be6386426223a030c4126ac7c295aa7b1d54c508bbace
hash643de2a1cf9148b896efecf560c9476fa56118ec477c4e15eb5c2da4b318061f
hashad1a0b3e22a10a2bd680b773b178a0d3824cfcbdf3551016f3d052a0b823079f

Threat ID: 6a5796db68715ace43de0ce7

Added to database: 07/15/2026, 14:19:07 UTC

Last enriched: 08/14/2026, 12:41:37 UTC

Last updated: 08/28/2026, 15:20:47 UTC

Views: 608

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses