China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models

China-Based AI Companies Conducting Industrial-Scale (TL-2026-2413) is a critical-severity tracked intrusion set, first published 2026-09-09. It is attributed to China AI Distillation Campaign (China) with high confidence, affects Anthropic Claude Model Family, maps to 16 MITRE ATT&CK / ATLAS techniques (AML.T0008, AML.T0024, AML.T0024.002), and is covered by 9 detection rules and 4 indicators of compromise.

Key facts for TL-2026-2413

Threat ID
TL-2026-2413
Severity
CRITICAL
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-09-09
Last reviewed
2026-09-09
Attribution
China AI Distillation Campaign
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
technology, artificial-intelligence, national-security, defense, government administration
Target regions
North America, East Asia, Global
Detection rules
9
Indicators of compromise
4

Malware and tooling in China-Based AI Companies Conducting Industrial-Scale

Malware and tooling: sub2api, xray and sing-box proxy tooling

NSA, CISA, and FBI jointly warn that six China-based AI companies—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—are conducting coordinated, state-adjacent industrial-scale model distillation campaigns against U.S. frontier AI providers (Anthropic, OpenAI, Google DeepMind, xAI) since at least late 2024, using gray-market proxy infrastructure, fraudulent accounts, and automated routing to extract billions of tokens of proprietary capabilities for competing model training.

How China-Based AI Companies Conducting Industrial-Scale works

On September 8, 2026, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) jointly released Cybersecurity Advisory AA26-251A, revealing that six China-based artificial intelligence companies have been conducting coordinated, industrial-scale malicious knowledge distillation campaigns against U.S. frontier AI model providers since at least late 2024, likely with Chinese government awareness. The advisory represents the most comprehensive U.S. government attribution of AI model intellectual property theft to date, co-signed by three agencies at the highest level of interagency coordination.

The campaign targets four major U.S. AI model families: Anthropic's Claude variants (including Claude 3.7, Sonnet 4, Sonnet 4.5, Opus 4.1, Opus 4.5, Opus 4.8, Sonnet 4.5 Thinking, Fable 5, Haiku 4.5, and Claude Code), OpenAI's GPT series (GPT-3 through GPT-5.5, including GPT-4o, GPT-4 Mini/Nano, GPT-5 Pro/Codex/Mini, GPT-5.1/5.2, and GPT-5.5), Google DeepMind's Gemini models (Gemini 1, 2, 2.5 Pro/Flash, and Gemini 3 Pro), and xAI's Grok models (Grok 3 Mini, Grok 4, Grok Code Fast-1). Six Chinese entities each targeted specific capabilities for their own competing models: DeepSeek extracted reasoning, optimization, and censorship-safe training data for R1 and V3; Moonshot AI extracted Claude Fable 5 and GPT-4o outputs for Kimi-K3 and Kimi-K2 (Anthropic detected over 3.4 million exchanges); Alibaba targeted software engineering, customer service dialogue, and image/character creation for Qwen; MiniMax extracted CoT reasoning, RL, SFT, and software engineering for M2 and attempted prompt injections against Claude Code; StepFun targeted coding and agentic functions for Step 4; and Z.AI extracted billions of tokens of GPT-5.5 and Claude Opus 4.8 data for CoT reasoning development. Anthropic alone detected over 16 million exchanges from approximately 24,000 fraudulent accounts.

The attack infrastructure relies on a sophisticated multi-layer evasion ecosystem. At the core are gray-market API proxies known as 'transfer stations'—overseas servers that forward API requests from within China, bypassing geographic restrictions and accepting payment in RMB via WeChat or Alipay at 70-90% below official pricing. An estimated 73,000 servers participate in this ecosystem, running open-source proxy tooling (xray, sing-box, VLESS, Shadowsocks) and model routing software (sub2api). The CISPA Helmholtz Center for Information Security found that 45.8% of these proxy services silently substituted requested models with cheaper or open-source alternatives—one 'GPT-5' endpoint was powered by GLM-4-9B, achieving only 37% of expected MedQA benchmark performance. Proxy operators monetize through three revenue streams: markup on access (credit farming, subscription carving, fraud), model swapping and token inflation (delivering cheaper models than advertised), and log harvesting as the primary product—every prompt and response passing through a transfer station is captured as a distillation dataset.

The advisory identifies four novel TTPs not yet catalogued in MITRE ATLAS: (1) regional restriction evasion and subscription exploitation, including bulk procurement of enterprise accounts shared across developer teams with tiered budget management; (2) centralized request routing infrastructure providing model/provider abstraction, real-time health monitoring, centralized quota enforcement, automated sanitization, and automated failover between pathways during blocking attempts; (3) automated request metadata sanitization at the infrastructure layer, systematically stripping organizational identifiers; and (4) systematic quota and cost optimization, including pathway selection prioritizing cost-efficiency and cache optimization versus task diversity balancing. Additionally, entities used chain-of-thought reasoning extraction via prompts instructing models to articulate internal reasoning, direct and indirect prompt injection (AML.T0051), and jailbreak techniques (AML.T0054). MiniMax demonstrated aggressive adaptation by pivoting nearly half its traffic to newly released Claude models within 24 hours of availability. DeepSeek employed synchronized traffic across accounts with shared payment methods for load balancing and generated censorship-safe alternatives to politically sensitive queries.

The advisory recommends three immediate actions: comprehensive detection and mitigation using behavioral monitoring systems, classifiers, and fingerprinting techniques to identify anomalous API usage patterns (24/7 sustained throughput without human variation, immediate maximum subscription utilization, consistent quota exhaustion); deployment of targeted response changes including differential privacy noise injection and downgraded model responses for high-confidence malicious distillation requests without informing suspected distillers; and establishment of cross-organization intelligence sharing across model providers, cloud platforms, and API aggregators to correlate distributed campaign activity. The U.S. government assesses that models built through illicit distillation are unlikely to retain safety safeguards, creating downstream risks around bioweapons development, malicious cyber activities, and erosion of U.S. technological leadership in artificial intelligence.

MITRE ATT&CK / ATLAS techniques used in TL-2026-2413

resource-development

AML.T0008 Acquire Infrastructure

exfiltration

AML.T0024 Exfiltration via AI Inference API

Exfiltration

AML.T0024.002 Exfiltration via AI Inference API: Extract AI Model; T1048 Exfiltration Over Alternative Protocol

Initial Access

AML.T0040 AI Model Inference API Access; T1078 Valid Accounts

ai-attack-staging

AML.T0042 Verify Attack

Impact

AML.T0048 External Harms

Execution

AML.T0051 LLM Prompt Injection

defense-evasion

AML.T0054 LLM Jailbreak

Defense Evasion

T1036 Masquerading

Command and Control

T1090.003 Multi-hop Proxy; T1572 Protocol Tunneling

Collection

T1119 Automated Collection

Resource Development

T1583 Acquire Infrastructure; T1583.003 Acquire Infrastructure: Virtual Private Server

Affected products and versions in China-Based AI Companies Conducting Industrial-Scale

  • Anthropic — Claude Model Family
    Vulnerable versions: Claude 3.7 / Sonnet 3.7; Claude Sonnet 4; Sonnet 4.5; Claude Opus 4.1; Opus 4.5; Opus 4.8; Claude Sonnet 4.5 Thinking; Claude Fable 5; Claude Haiku 4.5; Claude Code
  • OpenAI — GPT Model Family
    Vulnerable versions: GPT-3; GPT-4; GPT-4o; GPT-4 Mini; GPT-4 Nano; GPT-oss-20b; GPT-5; GPT-5 Mini; GPT-5 Pro; GPT-5 Codex
  • Google DeepMind — Gemini Model Family
    Vulnerable versions: Gemini 1; Gemini 2; Gemini 2.5 Pro Preview; Gemini 2.5 Flash Preview; Gemini 2.5 Flash; Gemini 2.5 Flash-Image; Gemini 2.5 Pro; Gemini 3 Pro
  • xAI — Grok Model Family
    Vulnerable versions: Grok 3 Mini; Grok 4; Grok Code Fast-1

Remediation for China-Based AI Companies Conducting Industrial-Scale

Immediate actions

  • Implement behavioral detection systems for anomalous API usage patterns (24/7 sustained throughput without human variation, immediate maximum subscription utilization, consistent quota exhaustion)
  • Deploy multi-classifier distillation detection with behavioral fingerprinting across accounts and API pathways
  • Strengthen identity verification for new accounts and enterprise subscription tiers
  • Begin cross-organization intelligence sharing with other AI labs, cloud providers, and API aggregators
  • Monitor subscription-to-usage ratios and flag accounts with enterprise-scale throughput on individual subscriptions
  • Detect coordinated pathway switching in response to pricing or rate limit changes

Workarounds

  • Serve less sophisticated models to systematically suspicious accounts without notifying the actor
  • Vary response changes across requests to complicate quality evaluation for distillers
  • Reduce reasoning depth in responses to anomalous queries
  • Implement prompt instruction and formatting guardrails (XML tags, separating instructions from user prompts)
  • Block known third-party aggregator endpoints and proxy IP ranges associated with transfer stations
  • Use predictive AI adversarial input detection (AML.M0015) and AI telemetry logging (AML.M0024)

Longer-term hardening

  • Apply differential privacy with calibrated noise injection to prevent reconstruction of training data signals
  • Deploy pre- and post-training interventions including adversarial training and safety training against distillation
  • Implement downgraded model responses for high-confidence malicious distillation requests
  • Establish automated infrastructure for multi-pathway correlation across cloud providers, aggregators, and model providers
  • Advocate for and implement export controls on advanced AI chips and model weights
  • Develop industry-wide AI distillation detection frameworks with shared behavioral indicator databases
  • Build production-grade chain-of-thought elicitation detection systems

Timeline of China-Based AI Companies Conducting Industrial-Scale

  • DeepSeek begins organized distillation campaigns against U.S. frontier AI models; earliest known activity of the industrial-scale campaign
  • DeepSeek releases the R1 model, trained in part via outputs extracted through malicious distillation of Claude and GPT reasoning capabilities
  • Moonshot AI begins widespread distillation campaign targeting Claude Fable 5 and GPT-4o for Kimi-K3 and Kimi-K2 models; DeepSeek's primary distillation window closes
  • Alibaba conducts targeted distillation against Claude-4, Claude Opus, Claude Sonnet, and GPT-5 to improve the Qwen family's software engineering and dialogue capabilities
  • MiniMax conducts distillation against Claude Code, Claude Sonnet 4, Claude Opus, and Gemini variants for the M2 model; attempts prompt injections against Claude Code to trick it into behaving as a MiniMax product
  • MiniMax demonstrates aggressive real-time adaptation, redirecting nearly half of its traffic to newly released Claude models within 24 hours of availability
  • StepFun conducts distillation targeting Claude Opus, Sonnet, Haiku, and GPT-5 variants for the Step 4 model's coding and agentic functions
  • Google reports that Gemini models have been increasingly targeted by distillation attacks, with one campaign creating over 100,000 prompts targeting non-English reasoning
  • OpenAI sends letter to U.S. House Select Committee on Strategic Competition warning about DeepSeek's ongoing distillation efforts and calling for stronger export controls
  • Anthropic publishes detailed report exposing three Chinese AI labs (DeepSeek, Moonshot, MiniMax) running industrial-scale distillation campaigns, documenting 16 million+ exchanges from 24,000+ fraudulent accounts using hydra cluster architectures
  • CISPA publishes 'Real Money, Fake Models' study finding 45.8% of 17 tested API proxy services silently substitute requested models with cheaper alternatives; one 'GPT-5' endpoint was actually GLM-4-9B
  • Z.AI completes large-scale distillation of billions of tokens of GPT-5.5 and Claude Opus 4.8 data for chain-of-thought reasoning development
  • NSA, CISA, and FBI release joint Cybersecurity Advisory AA26-251A, formally attributing industrial-scale distillation campaigns to six named China-based AI companies acting with likely Chinese government awareness

Sources cited for China-Based AI Companies Conducting Industrial-Scale

More in threat intel

Detection coverage for TL-2026-2413

As of 2026-09-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2413 across Splunk SPL, Microsoft KQL and Sigma, covering 4 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats