China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations Against Government, Supply-Chain, and Financial Targets — Threadlinqs Intelligence
As of 2026-07-18, China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations Against Government, Supply-Chain, and Financial Targets is a high-severity apt threat attributed to Unattributed China-Linked Threat Actor (TencShell (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 57 indicators of compromise.
Threat ID: TL-2026-1354 · Severity: HIGH · CVSS: 9.8 · Status: ACTIVE · Category: APT
Updated: 2026-07-18 · revalidated 1× · latest source
Attribution: Unattributed China-Linked Threat Actor (TencShell · China · ESPIONAGE
A suspected China-linked threat actor operating infrastructure tied to the previously documented TencShell/Rshell malware cluster is running an active, multi-region espionage campaign that
Between June 8 and June 12, 2026, researchers documented active working environments belonging to a suspected China-linked threat actor that had staged 2,431 files across 80 subdirectories on an exposed Hong Kong-hosted server (112.213.124.132). The directory contained PHP/JSP web shells, database dumps, custom exploit scripts, cloned government login pages, phishing templates, Linux/ARM malware samples, and operator activity logs written in Simplified Chinese.
The operation's defining characteristic is a deliberate AI division of labor: Claude Code was tasked with agentic tool interaction — processing interactive bash environments, executing commands, maintaining session persistence, managing parallel tasks, and constructing phishing pages — while DeepSeek-v4-pro handled higher-order attack reasoning, exploit adaptation, and evasion-logic/script generation. This mirrors the pattern Anthropic disclosed in November 2025, when it disrupted what it assessed with high confidence was the first largely AI-orchestrated cyber espionage campaign by a Chinese state-sponsored group, in which Claude Code executed an estimated 80-90% of campaign activity (reconnaissance, exploit development, credential harvesting, data categorization, and documentation) with only 4-6 human decision points per operation, at a request rate of multiple per second.
The server's exposed services — SSH (222), a malware download endpoint (1111), DeepAudit (3000), ARL/Attack Reconnaissance Lighthouse (5003), Vshell C2 (8084), and a secondary service (8888) — align with a broader 13-server Hong Kong-hosted infrastructure set (VMISS Inc., MEGA-II IDC, CTG Server Limited, Antbox Networks) sharing matching HTTP headers. This activity and toolset (Vshell/Rshell-family Go implants, Tencent-themed C2 path impersonation) tie the operator to the TencShell cluster Cato CTRL first documented in April-May 2026 against a global manufacturing customer, where the implant used a first-stage dropper with a spoofed User-Agent, a masqueraded .woff web-font resource, in-memory Donut shellcode execution, and Registry Run-key persistence (OneDriveHealthTask) to establish a SOCKS5-capable, screen-capture-enabled backdoor.
Observed victimology in the June 2026 wave spans eight Taiwanese chemical/manufacturing supply-chain firms (SQL injection), Thai government employee databases (GIF-polyglot web shell persistence, SQLMap-automated exfiltration), Afghan citizen-complaint public applications, U.S. public-sector infrastructure including NASA subdomains, the D.C. Council, and Delaware County, and multi-region financial payment-processing platforms in Europe, Australia, and Asia reached via CORS misconfiguration and deserialization RCE against Laravel applications.
Weaknesses (CWE)
CWE-89, CWE-502, CWE-346, CWE-434, CWE-798, CWE-942, CWE-306
Target sectors: government administration, supply-chain, manufacturing, finance, chemical, public-sector
Target regions: taiwan, thailand, afghanistan, united states of america, Europe, australia, hong kong
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 57 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
8 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
APT, HIGH, threat intelligence, cybersecurity, CVE-2021-43503, T1595, T1583, T1584.001, T1190, T1566, T1059.003, T1106, T1547.001, T1505.003, T1098