AI-Powered Cyber Espionage Campaign Targets Government Entities in Asia
In June 2026, security researchers uncovered an active cyber espionage campaign leveraging AI models Claude Code and DeepSeek-v4-pro to compromise government organizations in Afghanistan, Thailand, and Taiwan. The operation, linked to suspected China-aligned threat actors, was identified after analysts traced infrastructure associated with TencShell, a Go-based implant previously flagged by Cato CTRL for similar activity.
The investigation began with an exposed server (112.213.124[.]132), which contained a trove of malicious assets, including victim source code, exploit tools, phishing templates, operator logs, and malware samples all documented in Simplified Chinese. The threat actors employed a split-model workflow: DeepSeek-v4-pro handled attack reasoning, exploit adaptation, and script generation, while Claude Code managed command execution, persistent sessions, and phishing page development. This marks the second documented case of suspected China-linked operators using Claude Code in cyber operations, following a November 2025 disclosure by Anthropic.
The campaign’s infrastructure, primarily hosted in Hong Kong by providers like VMISS Inc., MEGA-II IDC, CTG Server Limited, and Antbox Networks Limited, included 13 servers sharing a unique HTTP header fingerprint. The exposed server hosted multiple services, such as:
- SSH (port 222222)
- Malware download service (port 111111111111)
- DeepAudit (port 300030003000) – a legitimate open-source tool repurposed for reconnaissance
- ARL (port 500350035003) – another open-source tool used for malicious scanning
- Vshell (port 808480848084) – command-and-control software
- Open HTTP directory (port 888888888888) – containing 2,431 files and 80 subdirectories, including web shells, database dumps, exploit scripts, and cloned government login pages
The directory also revealed Linux malware compiled for ARM systems, designed to steal cloud access keys, enterprise credentials, and Tencent QQ/IM data, while enabling file exfiltration. Researchers identified shared SSH host keys and default ARL TLS certificates across three servers, indicating coordinated infrastructure. Additionally, a potential second C2 framework, "Gshell," was detected, with overlapping servers suggesting the operators use multiple frameworks in tandem.
The campaign underscores the growing use of AI-driven tools in state-sponsored cyber operations, blending legitimate software with custom malware to evade detection and enhance attack efficiency.
Source: https://cyberpress.org/ai-powered-hackers-breach-governments/
Government of Taiwan TPRM report: https://www.rankiteo.com/company/office-of-the-president-r-o-c-taiwan
Government of Thailand TPRM report: https://www.rankiteo.com/company/taiwan-government
Government of Afghanistan TPRM report: https://www.rankiteo.com/company/mofa-afg
"id": "mofofftai1784103925",
"linkid": "mofa-afg, office-of-the-president-r-o-c-taiwan, taiwan-government",
"type": "Cyber Attack",
"date": "6/2026",
"severity": "100",
"impact": "8",
"explanation": "Attack that could bring to a war"
{'affected_entities': [{'industry': 'Public Sector',
'location': 'Afghanistan',
'type': 'Government'},
{'industry': 'Public Sector',
'location': 'Thailand',
'type': 'Government'},
{'industry': 'Public Sector',
'location': 'Taiwan',
'type': 'Government'}],
'attack_vector': ['AI-driven tools', 'Phishing', 'Malware', 'Exploit scripts'],
'data_breach': {'data_exfiltration': True,
'file_types_exposed': ['Web shells',
'Exploit scripts',
'Cloned government login pages'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Cloud access keys',
'Enterprise credentials',
'Tencent QQ/IM data',
'Source code',
'Database dumps']},
'date_detected': '2026-06',
'description': 'In June 2026, security researchers uncovered an active cyber '
'espionage campaign leveraging AI models Claude Code and '
'DeepSeek-v4-pro to compromise government organizations in '
'Afghanistan, Thailand, and Taiwan. The operation, linked to '
'suspected China-aligned threat actors, was identified after '
'analysts traced infrastructure associated with TencShell, a '
'Go-based implant previously flagged by Cato CTRL for similar '
'activity. The campaign employed a split-model workflow where '
'DeepSeek-v4-pro handled attack reasoning, exploit adaptation, '
'and script generation, while Claude Code managed command '
'execution, persistent sessions, and phishing page '
'development.',
'impact': {'data_compromised': ['Cloud access keys',
'Enterprise credentials',
'Tencent QQ/IM data',
'Victim source code',
'Database dumps'],
'systems_affected': ['Government systems',
'ARM-based Linux systems']},
'investigation_status': 'Ongoing',
'motivation': 'Cyber Espionage',
'post_incident_analysis': {'root_causes': ['Use of AI-driven tools for attack '
'reasoning and execution',
'Exposed server with malicious '
'assets',
'Repurposed legitimate tools for '
'reconnaissance']},
'references': [{'source': 'Cato CTRL'},
{'source': 'Anthropic (November 2025 disclosure)'}],
'threat_actor': 'Suspected China-aligned threat actors',
'title': 'AI-Powered Cyber Espionage Campaign Targets Government Entities in '
'Asia',
'type': 'Cyber Espionage'}