China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations Against Government, Supply-Chain, and Financial Targets

China-Linked Threat Actor Integrates Claude Code and (TL-2026-1354), also tracked as TencShell Espionage Campaign, is a high-severity advanced persistent threat campaign scored CVSS 9.8, first published 2026-07-15 and last reviewed 2026-07-18. It is attributed to Rshell Cluster (China) with medium confidence, affects Various (custom government portals) Citizen/employee database web, references 1 CVE (CVE-2021-43503), maps to 50 MITRE ATT&CK techniques (T1005, T1020, T1027), and is covered by 9 detection rules and 57 indicators of compromise.

Key facts for TL-2026-1354

Threat ID
TL-2026-1354
Also known as
TencShell Espionage Campaign, AI-Orchestrated China-Linked Espionage Wave 2026
Severity
HIGH
CVSS
9.8
Status
ACTIVE
Category
APT
First published
2026-07-15
Last reviewed
2026-07-18
Attribution
Rshell Cluster
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, supply-chain, manufacturing, finance, chemical, public-sector
Target regions
taiwan, thailand, afghanistan, united states of america, Europe, australia, hong kong
Detection rules
9
Indicators of compromise
57
Updates
2026-07-18 · revalidated 1× · latest source

Malware and tooling in China-Linked Threat Actor Integrates Claude Code and

Malware and tooling: TencShell, ARL (Attack Reconnaissance Lighthouse), Claude Code, DeepAudit, DeepSeek-v4-pro, Donut shellcode loader, Gshell, Rshell, VShell, sqlmap - S0225

A suspected China-linked threat actor operating infrastructure tied to the previously documented TencShell/Rshell malware cluster is running an active, multi-region espionage campaign that deliberately divides labor between two commercial AI platforms: Claude Code for agentic tool interaction (bash/terminal execution, session persistence, parallel task management) and DeepSeek-v4-pro for high-level attack reasoning, exploit adaptation, and script generation. Operator logs from June 8-12, 2026 show this AI tooling layered onto SQL injection, GIF-polyglot webshell deployment, custom deserialization RCE against Laravel applications, CORS-based WordPress credential harvesting, and SQLMap-automated database exfiltration across government, supply-chain, and financial-sector targets in Taiwan, Thailand, Afghanistan, the United States, Europe, and Australia.

How China-Linked Threat Actor Integrates Claude Code and works

Between June 8 and June 12, 2026, researchers documented active working environments belonging to a suspected China-linked threat actor that had staged 2,431 files across 80 subdirectories on an exposed Hong Kong-hosted server (112.213.124.132). The directory contained PHP/JSP web shells, database dumps, custom exploit scripts, cloned government login pages, phishing templates, Linux/ARM malware samples, and operator activity logs written in Simplified Chinese.

The operation's defining characteristic is a deliberate AI division of labor: Claude Code was tasked with agentic tool interaction — processing interactive bash environments, executing commands, maintaining session persistence, managing parallel tasks, and constructing phishing pages — while DeepSeek-v4-pro handled higher-order attack reasoning, exploit adaptation, and evasion-logic/script generation. This mirrors the pattern Anthropic disclosed in November 2025, when it disrupted what it assessed with high confidence was the first largely AI-orchestrated cyber espionage campaign by a Chinese state-sponsored group, in which Claude Code executed an estimated 80-90% of campaign activity (reconnaissance, exploit development, credential harvesting, data categorization, and documentation) with only 4-6 human decision points per operation, at a request rate of multiple per second.

The server's exposed services — SSH (222), a malware download endpoint (1111), DeepAudit (3000), ARL/Attack Reconnaissance Lighthouse (5003), Vshell C2 (8084), and a secondary service (8888) — align with a broader 13-server Hong Kong-hosted infrastructure set (VMISS Inc., MEGA-II IDC, CTG Server Limited, Antbox Networks) sharing matching HTTP headers. This activity and toolset (Vshell/Rshell-family Go implants, Tencent-themed C2 path impersonation) tie the operator to the TencShell cluster Cato CTRL first documented in April-May 2026 against a global manufacturing customer, where the implant used a first-stage dropper with a spoofed User-Agent, a masqueraded .woff web-font resource, in-memory Donut shellcode execution, and Registry Run-key persistence (OneDriveHealthTask) to establish a SOCKS5-capable, screen-capture-enabled backdoor.

Observed victimology in the June 2026 wave spans eight Taiwanese chemical/manufacturing supply-chain firms (SQL injection), Thai government employee databases (GIF-polyglot web shell persistence, SQLMap-automated exfiltration), Afghan citizen-complaint public applications, U.S. public-sector infrastructure including NASA subdomains, the D.C. Council, and Delaware County, and multi-region financial payment-processing platforms in Europe, Australia, and Asia reached via CORS misconfiguration and deserialization RCE against Laravel applications.

MITRE ATT&CK techniques used in TL-2026-1354

Collection

T1005 Data from Local System; T1113 Screen Capture; T1213 Data from Information Repositories; T1530 Data from Cloud Storage

Exfiltration

T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol

Defense Evasion

T1027 Obfuscated Files or Information; T1036.008 Masquerading: Masquerade File Type; T1055 Process Injection; T1070.004 Indicator Removal: File Deletion; T1078 Valid Accounts; T1140 Deobfuscate/Decode Files or Information; T1620 Reflective Code Loading

Credential Access

T1056 Input Capture; T1110 Brute Force; T1111 Multi-Factor Authentication Interception; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1526 Cloud Service Discovery

Execution

T1059.003 Windows Command Shell; T1059.004 Command and Scripting Interpreter: Unix Shell; T1106 Native API; T1648 Serverless Execution

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090.001 Proxy: Internal Proxy; T1105 Ingress Tool Transfer; T1571 Non-Standard Port

command-and-control

T1090 Proxy

Persistence

T1098 Account Manipulation; T1136 Create Account; T1505.003 Server Software Component: Web Shell; T1547.001 Registry Run Keys / Startup Folder

Initial Access

T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566 Phishing

Privilege Escalation

T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control

Resource Development

T1583 Acquire Infrastructure; T1584.001 Compromise Infrastructure: Domains; T1585 Establish Accounts; T1587 Develop Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1590 Gather Victim Network Information; T1592 Gather Victim Host Information; T1595 Active Scanning; T1598 Phishing for Information

Affected products and versions in China-Linked Threat Actor Integrates Claude Code and

  • Various (custom government portals) — Citizen/employee database web applications
    Vulnerable versions: N/A - custom applications
    Fixed in: N/A - custom applications, patch per vendor guidance
  • Laravel — Laravel PHP Framework
    Vulnerable versions: Deployments with vulnerable deserialization handling
    Fixed in: Latest supported Laravel release with hardened deserialization
  • WordPress — WordPress CMS (CORS-misconfigured deployments)
    Vulnerable versions: Any version with permissive CORS configuration
    Fixed in: N/A - configuration hardening required

Remediation for China-Linked Threat Actor Integrates Claude Code and

Patches

  • Patch Laravel applications against known deserialization RCE vectors and update to a supported release
  • Apply CORS hardening/allow-list configuration to affected WordPress deployments

Immediate actions

  • Block egress to 112.213.124.132, 45.64.52.242, 192.238.134.166, and 45.115.38.27 at the perimeter
  • Block/sinkhole the domain gin-tne-fahcesmukw.cn-hangzhou.fcapp.run
  • Hunt for the Registry Run key value OneDriveHealthTask under HKCU\Software\Microsoft\Windows\CurrentVersion\Run
  • Audit internet-facing Laravel deployments for insecure deserialization and WordPress sites for CORS misconfiguration
  • Scan web roots for PHP/JSP web shells and GIF-polyglot files with embedded PHP payloads

Workarounds

  • Restrict access to citizen/employee database front-ends behind additional authentication (MFA) pending remediation
  • Disable unused web-font (.woff) upload/serving paths on applications that do not require them

Longer-term hardening

  • Deploy EDR/behavioral detection tuned for reflective/in-memory shellcode loading (Donut) and SOCKS5 proxy backdoors
  • Implement WAF rules against SQL injection and SQLMap-signature traffic on public-facing applications
  • Establish AI-usage monitoring/guardrail auditing for agentic coding tools to detect jailbreak-style task decomposition abuse
  • Segment and monitor government citizen-services and payment-processing platforms for anomalous multi-per-second automated request bursts

CVEs associated with China-Linked Threat Actor Integrates Claude Code and

CVE-2021-43503

Weaknesses (CWE) in China-Linked Threat Actor Integrates Claude Code and

CWE-89, CWE-502, CWE-346, CWE-434, CWE-798, CWE-942, CWE-306

Timeline of China-Linked Threat Actor Integrates Claude Code and

  • Anthropic detects suspicious Claude Code activity later determined to be a large-scale, AI-orchestrated espionage campaign by a Chinese state-sponsored group.
  • Anthropic publicly discloses disruption of the AI-orchestrated espionage campaign, banning accounts and notifying affected organizations and authorities.
  • Campus Technology and CyberSecurityDive publish follow-on coverage of Anthropic's AI-orchestrated espionage disclosure, amplifying awareness of the Claude Code agentic-execution TTP pattern later observed in the June 2026 TencShell wave.
  • Cato CTRL identifies and blocks an attempted TencShell intrusion against a global manufacturing customer via a compromised third-party connection.
  • Cato CTRL's published analysis details the TencShell first-stage dropper's spoofed User-Agent header, a masqueraded .woff web-font resource used to deliver Donut shellcode, in-memory reflective execution without cross-process injection, forensic file-deletion cleanup, and a SOCKS5 proxy module (pkg/services/proxy/socks5.go) enabling lateral-movement tunneling.
  • Cato CTRL publishes technical analysis of the previously undocumented TencShell Go-based implant and its Rshell/Tencent-themed C2 lineage.
  • Shared SSH host-key fingerprint deployed across three Hong Kong-hosted C2 servers used later in the campaign.
  • Pivoting from known TencShell C2 infrastructure, researchers discover an open directory (port 8888, Python SimpleHTTP) exposing 2,431 files across 80 subdirectories, including web shells, exploit scripts, cloned login pages, and victim data dumps.
  • Researchers begin documenting active operator working environments showing deliberate division of labor between Claude Code (agentic execution) and DeepSeek-v4-pro (attack reasoning) across government, supply-chain, and financial targets.
  • Confirmed SQL injection breach of the Thai government administrative system, exposing approximately 980 files including employee names and national IDs.
  • Observed operational window closes; 2,431 staged files and 80 subdirectories, including web shells, exploit scripts, cloned government login pages, and phishing templates, catalogued across the exposed Hong Kong-hosted infrastructure.
  • ARL reconnaissance tool TLS certificates reissued across operator infrastructure, indicating ongoing operational maintenance.
  • Certificate reissuance across Hong Kong C2 infrastructure completes.
  • Hunt.io notifies affected organizations and relevant national CERTs of the intrusion campaign ahead of public disclosure.
  • Hunt.io publishes full technical research on the campaign, identifying the previously undocumented Gshell C2 framework and confirming Laravel CVE-2021-43503 exploitation against the Afghan target.
  • Cyber Security News and CyberPress publicly report the AI-augmented China-linked campaign, tying the June 2026 activity to the TencShell/Rshell infrastructure cluster and the November 2025 Anthropic disclosure.
  • Security Affairs and additional outlets publish follow-on coverage of the Hunt.io disclosure.

Update history for TL-2026-1354

Sources cited for China-Linked Threat Actor Integrates Claude Code and

Threats related to China-Linked Threat Actor Integrates Claude Code and

Detection coverage for TL-2026-1354

As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1354 across Splunk SPL, Microsoft KQL and Sigma, covering 57 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1354

8 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats