Full Report
Chinese-speaking threat operators have been observed using Claude, Qwen and DeepSeek-powered AI agents as operational components in a second intrusion campaign targeting government, political, education and industrial organizations across Asia. The campaign is distinct from an earlier operation reported in July that used Claude Code and DeepSeek against government and financial-sector targets. In this newer…
Analysis Summary
# Threat Actor: Chinese-speaking Threat Operators (Unnamed Cluster)
## Attribution & Identity
* **Actor Identification:** Chinese-speaking threat operators.
* **Aliases/Associated Groups:** Currently unnamed, but distinct from a separate July campaign that utilized Claude Code and DeepSeek.
* **Known Associations:** Linked to an earlier July 2026 operation targeting government and financial sectors, though this current activity represents a "second intrusion campaign."
## Activity Summary
Researchers have identified a new intrusion campaign (reported September 2026) involving the use of AI agents as operational components. This activity is characterized by a "newer cluster" of infrastructure, notably linked through a shared SOCKS proxy endpoint. The campaign targets various sectors across Asia, demonstrating an evolution in the actor's use of Large Language Models (LLMs) for offensive operations.
## Tactics, Techniques & Procedures
* **AI-Enabled Operations:** Use of AI agents powered by Claude, Qwen, and DeepSeek as core operational components to facilitate intrusions.
* **Proxying Traffic:** Utilization of SOCKS5 proxies to obfuscate origin and manage command-and-control (C2) traffic.
* **Infrastructure Reuse:** Observed using shared file-content patterns across multiple servers.
* **MITRE ATT&CK IDs:**
* **T1090.003** (Proxy: Multi-hop Proxy - related to SOCKS proxy usage)
* **T1588.007** (Obtain Capabilities: Artificial Intelligence - specifically AI agents/LLMs)
## Targeting
* **Sectors:** Government, Political organizations, Education, Industrial, and Finance (in earlier campaigns).
* **Geography:** Asia (Wide-ranging).
* **Victims:** Specific organizations were not named in the brief, but the scope includes critical state and educational infrastructure.
## Tools & Infrastructure
* **Malware/Tools:**
* **GhostSocks:** Malware associated with the SOCKS5 proxy infrastructure.
* **AI Models:** Claude (Anthropic), Qwen (Alibaba), and DeepSeek.
* **Claude Code:** Previously observed in the July campaign.
* **Infrastructure:**
* **SOCKS Proxy Endpoint:** 103.45.65[.]93:35888
* **Scale:** Infrastructure identified via 120 file-content matches across five different servers.
## Implications
This campaign signals a strategic shift in Chinese-speaking threat actor operations toward the integration of AI agents. By leveraging LLMs like Qwen and DeepSeek, these actors are likely increasing their operational tempo, automating complex task chains, and potentially lowering the barrier for sophisticated social engineering or code generation. The targeting of political and educational sectors in Asia suggests a focus on long-term espionage and regional influence.
## Mitigations
* **AI Usage Monitoring:** Organizations should monitor for unauthorized access to or traffic from API endpoints associated with Claude, Qwen, and DeepSeek within their environments.
* **Proxy Detection:** Implement network monitoring to identify and block traffic to known malicious SOCKS proxies, specifically the identified IP 103.45.65[.]93.
* **Behavioral Analysis:** Focus on detecting AI-generated content in phishing attempts and monitoring for high-frequency automated interactions that characterize AI-driven agents.
* **Infrastructure Hardening:** Regularly audit server file-content for the specific matches and signatures associated with this actor's deployment patterns.