Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign
Overview
A Chinese cyber espionage campaign has been uncovered, targeting government systems and financial institutions using tools called Claude Code and DeepSeek. Researchers from Hunt.io discovered the ongoing attacks in June 2026 while investigating known command-and-control infrastructure associated with TencShell. Their investigation revealed a single HTTP header fingerprint that led them to 13 servers based in Hong Kong. This incident raises concerns about the security of sensitive government and financial data, highlighting the need for stronger defenses against automated cyber attacks. The use of advanced tools for intrusion efforts indicates a sophisticated level of planning and execution by the attackers.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Government systems, financial firms, TencShell command-and-control infrastructure
- Action Required: Organizations should enhance their network security measures, monitor for unusual traffic patterns, and update intrusion detection systems to identify automated attack tools.
- Timeline: Ongoing since June 2026
Original Article Summary
Chinese actors used Claude Code and DeepSeek to automate attacks that breached government systems and targeted financial firms. Hunt.io researchers stumbled onto an active intrusion campaign in June 2026 while pivoting on known TencShell command-and-control infrastructure. A single HTTP header fingerprint on port 1111 led them to 13 Hong Kong-based servers and, on one of […]
Impact
Government systems, financial firms, TencShell command-and-control infrastructure
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since June 2026
Remediation
Organizations should enhance their network security measures, monitor for unusual traffic patterns, and update intrusion detection systems to identify automated attack tools.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.