China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models
China-Based AI Companies Conducting Industrial-Scale (TL-2026-2413) is a critical-severity tracked intrusion set, first published 2026-09-09. It is attributed to China AI Distillation Campaign (China) with high confidence, affects Anthropic Claude Model Family, maps to 16 MITRE ATT&CK / ATLAS techniques (AML.T0008, AML.T0024, AML.T0024.002), and is covered by 9 detection rules and 4 indicators of compromise.
Key facts for TL-2026-2413
- Threat ID
- TL-2026-2413
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-09-09
- Last reviewed
- 2026-09-09
- Attribution
- China AI Distillation Campaign
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- technology, artificial-intelligence, national-security, defense, government administration
- Target regions
- North America, East Asia, Global
- Detection rules
- 9
- Indicators of compromise
- 4
Malware and tooling in China-Based AI Companies Conducting Industrial-Scale
Malware and tooling: sub2api, xray and sing-box proxy tooling
NSA, CISA, and FBI jointly warn that six China-based AI companies—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—are conducting coordinated, state-adjacent industrial-scale model distillation campaigns against U.S. frontier AI providers (Anthropic, OpenAI, Google DeepMind, xAI) since at least late 2024, using gray-market proxy infrastructure, fraudulent accounts, and automated routing to extract billions of tokens of proprietary capabilities for competing model training.
How China-Based AI Companies Conducting Industrial-Scale works
On September 8, 2026, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) jointly released Cybersecurity Advisory AA26-251A, revealing that six China-based artificial intelligence companies have been conducting coordinated, industrial-scale malicious knowledge distillation campaigns against U.S. frontier AI model providers since at least late 2024, likely with Chinese government awareness. The advisory represents the most comprehensive U.S. government attribution of AI model intellectual property theft to date, co-signed by three agencies at the highest level of interagency coordination.
The campaign targets four major U.S. AI model families: Anthropic's Claude variants (including Claude 3.7, Sonnet 4, Sonnet 4.5, Opus 4.1, Opus 4.5, Opus 4.8, Sonnet 4.5 Thinking, Fable 5, Haiku 4.5, and Claude Code), OpenAI's GPT series (GPT-3 through GPT-5.5, including GPT-4o, GPT-4 Mini/Nano, GPT-5 Pro/Codex/Mini, GPT-5.1/5.2, and GPT-5.5), Google DeepMind's Gemini models (Gemini 1, 2, 2.5 Pro/Flash, and Gemini 3 Pro), and xAI's Grok models (Grok 3 Mini, Grok 4, Grok Code Fast-1). Six Chinese entities each targeted specific capabilities for their own competing models: DeepSeek extracted reasoning, optimization, and censorship-safe training data for R1 and V3; Moonshot AI extracted Claude Fable 5 and GPT-4o outputs for Kimi-K3 and Kimi-K2 (Anthropic detected over 3.4 million exchanges); Alibaba targeted software engineering, customer service dialogue, and image/character creation for Qwen; MiniMax extracted CoT reasoning, RL, SFT, and software engineering for M2 and attempted prompt injections against Claude Code; StepFun targeted coding and agentic functions for Step 4; and Z.AI extracted billions of tokens of GPT-5.5 and Claude Opus 4.8 data for CoT reasoning development. Anthropic alone detected over 16 million exchanges from approximately 24,000 fraudulent accounts.
The attack infrastructure relies on a sophisticated multi-layer evasion ecosystem. At the core are gray-market API proxies known as 'transfer stations'—overseas servers that forward API requests from within China, bypassing geographic restrictions and accepting payment in RMB via WeChat or Alipay at 70-90% below official pricing. An estimated 73,000 servers participate in this ecosystem, running open-source proxy tooling (xray, sing-box, VLESS, Shadowsocks) and model routing software (sub2api). The CISPA Helmholtz Center for Information Security found that 45.8% of these proxy services silently substituted requested models with cheaper or open-source alternatives—one 'GPT-5' endpoint was powered by GLM-4-9B, achieving only 37% of expected MedQA benchmark performance. Proxy operators monetize through three revenue streams: markup on access (credit farming, subscription carving, fraud), model swapping and token inflation (delivering cheaper models than advertised), and log harvesting as the primary product—every prompt and response passing through a transfer station is captured as a distillation dataset.
The advisory identifies four novel TTPs not yet catalogued in MITRE ATLAS: (1) regional restriction evasion and subscription exploitation, including bulk procurement of enterprise accounts shared across developer teams with tiered budget management; (2) centralized request routing infrastructure providing model/provider abstraction, real-time health monitoring, centralized quota enforcement, automated sanitization, and automated failover between pathways during blocking attempts; (3) automated request metadata sanitization at the infrastructure layer, systematically stripping organizational identifiers; and (4) systematic quota and cost optimization, including pathway selection prioritizing cost-efficiency and cache optimization versus task diversity balancing. Additionally, entities used chain-of-thought reasoning extraction via prompts instructing models to articulate internal reasoning, direct and indirect prompt injection (AML.T0051), and jailbreak techniques (AML.T0054). MiniMax demonstrated aggressive adaptation by pivoting nearly half its traffic to newly released Claude models within 24 hours of availability. DeepSeek employed synchronized traffic across accounts with shared payment methods for load balancing and generated censorship-safe alternatives to politically sensitive queries.
The advisory recommends three immediate actions: comprehensive detection and mitigation using behavioral monitoring systems, classifiers, and fingerprinting techniques to identify anomalous API usage patterns (24/7 sustained throughput without human variation, immediate maximum subscription utilization, consistent quota exhaustion); deployment of targeted response changes including differential privacy noise injection and downgraded model responses for high-confidence malicious distillation requests without informing suspected distillers; and establishment of cross-organization intelligence sharing across model providers, cloud platforms, and API aggregators to correlate distributed campaign activity. The U.S. government assesses that models built through illicit distillation are unlikely to retain safety safeguards, creating downstream risks around bioweapons development, malicious cyber activities, and erosion of U.S. technological leadership in artificial intelligence.
MITRE ATT&CK / ATLAS techniques used in TL-2026-2413
resource-development
AML.T0008 Acquire Infrastructure
exfiltration
AML.T0024 Exfiltration via AI Inference API
Exfiltration
AML.T0024.002 Exfiltration via AI Inference API: Extract AI Model; T1048 Exfiltration Over Alternative Protocol
Initial Access
AML.T0040 AI Model Inference API Access; T1078 Valid Accounts
ai-attack-staging
AML.T0042 Verify Attack
Impact
AML.T0048 External Harms
Execution
AML.T0051 LLM Prompt Injection
defense-evasion
AML.T0054 LLM Jailbreak
Defense Evasion
Command and Control
T1090.003 Multi-hop Proxy; T1572 Protocol Tunneling
Collection
Resource Development
T1583 Acquire Infrastructure; T1583.003 Acquire Infrastructure: Virtual Private Server
Affected products and versions in China-Based AI Companies Conducting Industrial-Scale
- Anthropic — Claude Model Family
Vulnerable versions: Claude 3.7 / Sonnet 3.7; Claude Sonnet 4; Sonnet 4.5; Claude Opus 4.1; Opus 4.5; Opus 4.8; Claude Sonnet 4.5 Thinking; Claude Fable 5; Claude Haiku 4.5; Claude Code - OpenAI — GPT Model Family
Vulnerable versions: GPT-3; GPT-4; GPT-4o; GPT-4 Mini; GPT-4 Nano; GPT-oss-20b; GPT-5; GPT-5 Mini; GPT-5 Pro; GPT-5 Codex - Google DeepMind — Gemini Model Family
Vulnerable versions: Gemini 1; Gemini 2; Gemini 2.5 Pro Preview; Gemini 2.5 Flash Preview; Gemini 2.5 Flash; Gemini 2.5 Flash-Image; Gemini 2.5 Pro; Gemini 3 Pro - xAI — Grok Model Family
Vulnerable versions: Grok 3 Mini; Grok 4; Grok Code Fast-1
Remediation for China-Based AI Companies Conducting Industrial-Scale
Immediate actions
- Implement behavioral detection systems for anomalous API usage patterns (24/7 sustained throughput without human variation, immediate maximum subscription utilization, consistent quota exhaustion)
- Deploy multi-classifier distillation detection with behavioral fingerprinting across accounts and API pathways
- Strengthen identity verification for new accounts and enterprise subscription tiers
- Begin cross-organization intelligence sharing with other AI labs, cloud providers, and API aggregators
- Monitor subscription-to-usage ratios and flag accounts with enterprise-scale throughput on individual subscriptions
- Detect coordinated pathway switching in response to pricing or rate limit changes
Workarounds
- Serve less sophisticated models to systematically suspicious accounts without notifying the actor
- Vary response changes across requests to complicate quality evaluation for distillers
- Reduce reasoning depth in responses to anomalous queries
- Implement prompt instruction and formatting guardrails (XML tags, separating instructions from user prompts)
- Block known third-party aggregator endpoints and proxy IP ranges associated with transfer stations
- Use predictive AI adversarial input detection (AML.M0015) and AI telemetry logging (AML.M0024)
Longer-term hardening
- Apply differential privacy with calibrated noise injection to prevent reconstruction of training data signals
- Deploy pre- and post-training interventions including adversarial training and safety training against distillation
- Implement downgraded model responses for high-confidence malicious distillation requests
- Establish automated infrastructure for multi-pathway correlation across cloud providers, aggregators, and model providers
- Advocate for and implement export controls on advanced AI chips and model weights
- Develop industry-wide AI distillation detection frameworks with shared behavioral indicator databases
- Build production-grade chain-of-thought elicitation detection systems
Timeline of China-Based AI Companies Conducting Industrial-Scale
- DeepSeek begins organized distillation campaigns against U.S. frontier AI models; earliest known activity of the industrial-scale campaign
- DeepSeek releases the R1 model, trained in part via outputs extracted through malicious distillation of Claude and GPT reasoning capabilities
- Moonshot AI begins widespread distillation campaign targeting Claude Fable 5 and GPT-4o for Kimi-K3 and Kimi-K2 models; DeepSeek's primary distillation window closes
- Alibaba conducts targeted distillation against Claude-4, Claude Opus, Claude Sonnet, and GPT-5 to improve the Qwen family's software engineering and dialogue capabilities
- MiniMax conducts distillation against Claude Code, Claude Sonnet 4, Claude Opus, and Gemini variants for the M2 model; attempts prompt injections against Claude Code to trick it into behaving as a MiniMax product
- MiniMax demonstrates aggressive real-time adaptation, redirecting nearly half of its traffic to newly released Claude models within 24 hours of availability
- StepFun conducts distillation targeting Claude Opus, Sonnet, Haiku, and GPT-5 variants for the Step 4 model's coding and agentic functions
- Google reports that Gemini models have been increasingly targeted by distillation attacks, with one campaign creating over 100,000 prompts targeting non-English reasoning
- OpenAI sends letter to U.S. House Select Committee on Strategic Competition warning about DeepSeek's ongoing distillation efforts and calling for stronger export controls
- Anthropic publishes detailed report exposing three Chinese AI labs (DeepSeek, Moonshot, MiniMax) running industrial-scale distillation campaigns, documenting 16 million+ exchanges from 24,000+ fraudulent accounts using hydra cluster architectures
- CISPA publishes 'Real Money, Fake Models' study finding 45.8% of 17 tested API proxy services silently substitute requested models with cheaper alternatives; one 'GPT-5' endpoint was actually GLM-4-9B
- Z.AI completes large-scale distillation of billions of tokens of GPT-5.5 and Claude Opus 4.8 data for chain-of-thought reasoning development
- NSA, CISA, and FBI release joint Cybersecurity Advisory AA26-251A, formally attributing industrial-scale distillation campaigns to six named China-based AI companies acting with likely Chinese government awareness
Sources cited for China-Based AI Companies Conducting Industrial-Scale
- CISA Advisory AA26-251A: China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
- SecurityWeek: US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities
- Anthropic Blog: Detecting and Preventing Distillation Attacks
- Bloomberg: US Says Alibaba, DeepSeek Have Systematically Siphoned AI Models
- Chinatalk Media: How to Buy Cheap Claude Tokens in China—The Transfer Station Economy
- Infrawatch: 73,000 Servers Selling Western Frontier AI Into China—Transfer Stations
- CISPA: Real Money, Fake Models (arXiv 2603.01919)
- Tom's Hardware: Chinese Grey Market Sells Claude API Access at 90% Off Through Proxy Networks
- TechCrunch: Anthropic accuses Chinese AI labs of mining Claude as US debates AI chip exports
- OpenAI Letter to U.S. House Select Committee on Strategic Competition (Feb 12, 2026)
- Google Threat Intelligence Blog: Distillation Attacks Against Gemini Models
- MITRE ATLAS: AML.T0024.002 - Extract AI Model via Exfiltration via AI Inference API
More in threat intel
- Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass
- Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence Group Q3 2026 AI Threat Tracker)
- ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport Manager 12.44 (UAT-10820)
- OpenAI GPT-6 Astra Reaches 'Critical' Cybersecurity Capability Threshold; Attempted Supply-Chain Attacks and Scope Violations Found in Safety Testing
- Invisible Unicode Tag Characters Used to Evade Phishing Detection in Financial Scam Campaign
Detection coverage for TL-2026-2413
As of 2026-09-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2413 across Splunk SPL, Microsoft KQL and Sigma, covering 4 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.