Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries
In June 2026, infrastructure pivoting from TencShell C2 nodes revealed an active intrusion campaign utilizing AI language models for attack automation. Thirteen Hong Kong-based servers across four ASNs exposed an open directory containing victim source code, custom exploits, operational logs, and cloned login pages with notes in Simplified Chinese. The operation employed Claude Code for execution and DeepSeek-v4-pro for attack logic, targeting government systems in Afghanistan, Thailand, and Taiwan, along with reconnaissance against U.S. government portals. The campaign also pursued financial services firms across Europe, Australia, and Asia. Attackers deployed TencShell implants, webshells, and custom exploits including SQL injection and Laravel deserialization attacks, successfully compromising administrative systems and exfiltrating sensitive data including citizen complaints and government employee information.
AI Analysis
Technical Summary
This intrusion campaign, active as of June 2026, involves suspected Chinese operators using AI-powered tools—Claude Code for execution and DeepSeek-v4-pro for attack logic—to automate and orchestrate attacks against government and financial sectors across multiple countries. The attackers deployed TencShell implants and webshells, leveraging custom exploits such as SQL injection and Laravel deserialization vulnerabilities to gain administrative access and exfiltrate sensitive information. Evidence was uncovered on multiple Hong Kong-based servers revealing operational artifacts and victim data. The campaign includes reconnaissance against U.S. government portals and targets financial firms in Europe, Australia, and Asia. The operation uses supply chain targeting and phishing tactics as part of its attack vectors.
Potential Impact
Successful exploitation allowed attackers to compromise administrative systems of government entities and financial firms, leading to exfiltration of sensitive data including citizen complaints and government employee information. The campaign's use of custom exploits and webshell implants indicates a high level of operational capability and persistence. The exposure of victim source code and operational logs on attacker infrastructure suggests significant operational security lapses by the threat actors but also indicates the breadth and depth of the compromise. The targeting of multiple countries and sectors highlights the campaign's broad impact potential.
Mitigation Recommendations
No official patch or remediation guidance is provided in the available information. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Defenders should monitor for indicators related to TencShell implants, webshells, and the specific exploit techniques mentioned (SQL injection, Laravel deserialization). Given the use of AI-powered automation, enhanced detection of anomalous execution patterns and network traffic associated with Claude Code and DeepSeek tools is recommended. Organizations in the affected sectors and regions should review access controls, audit logs, and implement protections against the identified exploit techniques. Phishing defenses should be strengthened to mitigate initial access vectors. Note that this is an active campaign; timely threat intelligence updates are critical.
Affected Countries
Afghanistan, Thailand, Taiwan, United States, Australia
Indicators of Compromise
- ip: 112.213.124.159
- ip: 134.122.200.153
- ip: 134.122.200.154
- ip: 134.122.200.155
- ip: 192.229.115.229
- ip: 45.64.52.242
- ip: 192.238.134.166
- ip: 112.213.124.132
- hash: 90b7b2c6f3d05234dc55678243039d7e51f0d54190239e5234a0005533337dc8
- ip: 112.213.124.163
- hash: 050b84a0d6105a98f443f0165368cc1c
- hash: 4da236de055bfaf08ee21fb6b88442b4
- hash: 1cac633d290a876fc1ead63c58de48575b67b1fc
- hash: 66049dd42a29dde7481d5ca2951efec27214ce15
- hash: 03f26cbfa3ca15fcb43f512aa4041732beeec267f9d1dc74a11f7b0bb32e86bb
- hash: 2954639be599f23c2229a9743aba09a1d9d11bf2becc62bf353384437db37dee
- hash: 64107e3e0a333f685d1be6386426223a030c4126ac7c295aa7b1d54c508bbace
- hash: 643de2a1cf9148b896efecf560c9476fa56118ec477c4e15eb5c2da4b318061f
- hash: ad1a0b3e22a10a2bd680b773b178a0d3824cfcbdf3551016f3d052a0b823079f
- ip: 134.122.200.114
- ip: 134.122.200.115
- ip: 134.122.200.116
- ip: 192.163.167.10
- ip: 192.163.167.5
- ip: 192.163.167.6
- ip: 192.163.167.7
- ip: 192.229.115.230
- ip: 38.55.105.143
- ip: 45.64.52.245
- ip: 45.64.52.246
Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries
Description
In June 2026, infrastructure pivoting from TencShell C2 nodes revealed an active intrusion campaign utilizing AI language models for attack automation. Thirteen Hong Kong-based servers across four ASNs exposed an open directory containing victim source code, custom exploits, operational logs, and cloned login pages with notes in Simplified Chinese. The operation employed Claude Code for execution and DeepSeek-v4-pro for attack logic, targeting government systems in Afghanistan, Thailand, and Taiwan, along with reconnaissance against U.S. government portals. The campaign also pursued financial services firms across Europe, Australia, and Asia. Attackers deployed TencShell implants, webshells, and custom exploits including SQL injection and Laravel deserialization attacks, successfully compromising administrative systems and exfiltrating sensitive data including citizen complaints and government employee information.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This intrusion campaign, active as of June 2026, involves suspected Chinese operators using AI-powered tools—Claude Code for execution and DeepSeek-v4-pro for attack logic—to automate and orchestrate attacks against government and financial sectors across multiple countries. The attackers deployed TencShell implants and webshells, leveraging custom exploits such as SQL injection and Laravel deserialization vulnerabilities to gain administrative access and exfiltrate sensitive information. Evidence was uncovered on multiple Hong Kong-based servers revealing operational artifacts and victim data. The campaign includes reconnaissance against U.S. government portals and targets financial firms in Europe, Australia, and Asia. The operation uses supply chain targeting and phishing tactics as part of its attack vectors.
Potential Impact
Successful exploitation allowed attackers to compromise administrative systems of government entities and financial firms, leading to exfiltration of sensitive data including citizen complaints and government employee information. The campaign's use of custom exploits and webshell implants indicates a high level of operational capability and persistence. The exposure of victim source code and operational logs on attacker infrastructure suggests significant operational security lapses by the threat actors but also indicates the breadth and depth of the compromise. The targeting of multiple countries and sectors highlights the campaign's broad impact potential.
Defensive Guidance
No official patch or remediation guidance is provided in the available information. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Defenders should monitor for indicators related to TencShell implants, webshells, and the specific exploit techniques mentioned (SQL injection, Laravel deserialization). Given the use of AI-powered automation, enhanced detection of anomalous execution patterns and network traffic associated with Claude Code and DeepSeek tools is recommended. Organizations in the affected sectors and regions should review access controls, audit logs, and implement protections against the identified exploit techniques. Phishing defenses should be strengthened to mitigate initial access vectors. Note that this is an active campaign; timely threat intelligence updates are critical.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion"]
- Adversary
- null
- Pulse Id
- 6a56a77a59a4d2b99d9aa87f
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip112.213.124.159 | — | |
ip134.122.200.153 | — | |
ip134.122.200.154 | — | |
ip134.122.200.155 | — | |
ip192.229.115.229 | — | |
ip45.64.52.242 | — | |
ip192.238.134.166 | — | |
ip112.213.124.132 | — | |
ip112.213.124.163 | — | |
ip134.122.200.114 | — | |
ip134.122.200.115 | — | |
ip134.122.200.116 | — | |
ip192.163.167.10 | — | |
ip192.163.167.5 | — | |
ip192.163.167.6 | — | |
ip192.163.167.7 | — | |
ip192.229.115.230 | — | |
ip38.55.105.143 | — | |
ip45.64.52.245 | — | |
ip45.64.52.246 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash90b7b2c6f3d05234dc55678243039d7e51f0d54190239e5234a0005533337dc8 | — | |
hash050b84a0d6105a98f443f0165368cc1c | — | |
hash4da236de055bfaf08ee21fb6b88442b4 | — | |
hash1cac633d290a876fc1ead63c58de48575b67b1fc | — | |
hash66049dd42a29dde7481d5ca2951efec27214ce15 | — | |
hash03f26cbfa3ca15fcb43f512aa4041732beeec267f9d1dc74a11f7b0bb32e86bb | — | |
hash2954639be599f23c2229a9743aba09a1d9d11bf2becc62bf353384437db37dee | — | |
hash64107e3e0a333f685d1be6386426223a030c4126ac7c295aa7b1d54c508bbace | — | |
hash643de2a1cf9148b896efecf560c9476fa56118ec477c4e15eb5c2da4b318061f | — | |
hashad1a0b3e22a10a2bd680b773b178a0d3824cfcbdf3551016f3d052a0b823079f | — |
Threat ID: 6a5796db68715ace43de0ce7
Added to database: 07/15/2026, 14:19:07 UTC
Last enriched: 08/14/2026, 12:41:37 UTC
Last updated: 08/28/2026, 15:20:47 UTC
Views: 608
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.