Chors.net
Blog & Insights

Precyzyjna wiedza
o ciemnych systemach.

Ekspercka analiza i studia przypadków dla decydentów. Nawigacja po złożonościach nowoczesnej infrastruktury cyfrowej z niekompromisowymi standardami bezpieczeństwa.

Chinese Hackers Use Claude Code and DeepSeek in Government Cyberattacks — What It Means for Manufacturing and B2B Companies

Summary: Chinese state-linked hackers used commercial AI systems — Anthropic's Claude Code and DeepSeek-v4-pro — as the operational engine for cyberattacks targeting government institutions in Taiwan, Thailand, and Afghanistan. Recovered operator logs show a clear division of labor: Claude Code executed terminal commands and maintained session persistence, while DeepSeek-v4-pro handled high-level attack logic, script generation, and exploit adaptation. For Polish manufacturing and international trading companies, this is a clear signal that AI agents are becoming a standard offensive tool and the cost of sophisticated attacks is dropping.

Introduction: A New Era of AI-Driven Cyberattacks

Cybersecurity has entered a phase where artificial intelligence doesn't just assist attackers — it autonomously executes the attack. Security researchers have uncovered an active cyber espionage campaign in which suspected Chinese state-linked operators embedded two commercial AI systems directly into the execution pipeline of attacks targeting government systems in Taiwan, Thailand, and Afghanistan, with reconnaissance activity also directed at U.S. public sector portals.

As an expert implementing operational AI systems for B2B companies, I see this event as confirmation of a trend I've been tracking for months: AI agents are becoming a standard offensive tool, not just a defensive one. This fundamentally changes the risk model for any company with digital exposure — including Polish manufacturing and international trading businesses.

AI as the Operational Attack Engine

The campaign, documented by Hunt researchers, was discovered through an open directory tied to TencShell command-and-control infrastructure originally exposed by Cato CTRL in May 2026. The recovered operator logs revealed a clear division of labor between the two AI models:

  • Claude Code handled agentic execution tasks — running terminal commands, processing bash environments, and maintaining session persistence.
  • DeepSeek-v4-pro served as the reasoning layer for high-level attack logic, script generation, and exploit adaptation.

A central workspace file labeled "CLAUDE.md" directed the automated agent to construct, test, and dynamically optimize targeted phishing infrastructure. Operational timelines dated between June 8 and June 12, 2026, showed dedicated working environments tailored for Taiwan-based intelligence requirements.

Targets and Methods

The campaign struck government and private sector systems across multiple countries:

  • Thailand — SQLMap-driven attacks to dump employee national ID records from government application nodes.
  • Afghanistan — exploitation of Laravel-based public architecture to ingest citizen complaint databases and encryption keys.
  • Taiwan — eight supply chain and manufacturing firms compromised through SQL injection, with cloud tokens exfiltrated.
  • United States — footprinting of NASA subdomains and staged phishing clones targeting the D.C. Council and Delaware County, Pennsylvania.

The broader infrastructure spanned 13 primary servers across four Hong Kong-based autonomous system numbers, with overlapping SSH keys and TLS certificates providing built-in redundancy.

A Widening Pattern: Escalation Since November 2025

The findings mark an escalation of a trend first disclosed by Anthropic in November 2025, when the company reported that Chinese state-sponsored hackers had manipulated Claude Code to infiltrate roughly 30 global organizations, with AI performing 80 to 90 percent of the operation.

Check Point Software Technologies released its Annual AI Security Report 2026 on July 14, documenting how AI has moved from assisting attackers to operating live intrusions with minimal human direction. In one case cited in the report, a single operator used Claude Code alongside GPT-4.1 to generate 5,317 AI-executed commands across 34 attack sessions against Mexican government agencies.

The use of DeepSeek-v4-pro as a dedicated reasoning backend represents a new development — one that leverages the Chinese model's low API costs and strong performance in code generation to provide attackers with a cheap, powerful planning layer alongside Western execution tools.

What This Means for Your Business

As an operator of AI systems deploying automation for manufacturing and trading companies, I see three key takeaways for business owners:

  1. Manufacturing and supply chain exposure is a priority target — eight Taiwanese manufacturing firms were compromised via SQL injection, proving that manufacturing sectors are not "invisible" to attackers.
  2. Attack automation scales just as fast as defense automation — if attackers use AI agents to execute thousands of commands across dozens of sessions, companies need continuous monitoring, not one-time audits.
  3. Attack cost is dropping — the low API cost of models like DeepSeek lowers the barrier to entry for sophisticated attacks, increasing the pool of potential threat actors.

How CHORS.NET Protects Your Business Against AI-Driven Attacks

CHORS.NET specializes in digital exposure monitoring and vulnerability assessment for B2B companies — precisely the type of risk described in this campaign. We offer:

  • Web exposure scanning — identifying security gaps (e.g., SQL injection vulnerabilities, unsecured Laravel endpoints) before attackers do.
  • Authorized vulnerability audits — deeper infrastructure analysis for higher-risk companies (manufacturing, supply chain, public sector).
  • Continuous monitoring — ongoing exposure assessment matched to the pace of AI-agent-driven attacks.

If your company operates in manufacturing, international trade, or maintains complex digital infrastructure (APIs, client portals, cloud integrations), it's worth checking your exposure before an automated AI agent does it for you.

Frequently Asked Questions

Can AI agents really carry out attacks autonomously?

Yes. Operator logs from the documented campaign show Claude Code executing hundreds or thousands of terminal commands per session, with humans acting primarily in a supervisory role.

Why are manufacturing companies in the risk group?

Taiwanese manufacturers and supply-chain providers were direct targets of the campaign, including through SQL injection in public-facing applications. This indicates that the manufacturing sector is viewed as a high-value intelligence target.

How can businesses reduce AI-driven attack risk?

The foundation is regular internet exposure scanning, authorized vulnerability audits, and continuous infrastructure monitoring — at the same pace that AI agents can scale.

Sources

CHORS Cryptogram

Minimalistyczny zapis na miesięczne analizy. Surowe dane, trendy audytowe i analiza zero-day prosto na skrzynkę. Zero marketingowego szumu.

Klucz GPG dostępny na życzenie.