Hunt.io Details Suspected China-Linked Campaign Using Claude Code and DeepSeek Against Government Systems

· Original article ↗

Summary

Hunt.io researchers uncovered suspected China-linked intrusions against government systems in Afghanistan, Thailand and Taiwan, alongside financial-sector targeting. Exposed logs show Claude Code and DeepSeek-v4-pro supporting reconnaissance, exploit development and, in

Key points

  • An exposed directory on Hong Kong-hosted infrastructure contained victim source code, exploit scripts, malware, phishing-page clones and operator logs.
  • Researchers documented compromises of government systems in Afghanistan and Thailand and two Taiwanese organizations; activity against U.S. government portals was reconnaissance and phishing preparation, not confirmed intrusion.
  • Attack methods included SQL injection, authentication bypass, a Laravel deserialization exploit, and abuse of exposed cloud credentials and tokens.
  • The Thailand breach exposed government employees’ names, national ID numbers and positions; the Afghan compromise exposed citizen complaints, source code and application credentials.
  • Recovered logs show Claude Code managing execution and sessions while DeepSeek-v4-pro handled reasoning, attack logic and script generation.
  • The researchers found Linux/ARM malware variants and infrastructure associated with TencShell, plus a suspected second C2 framework called Gshell.
  • The researchers assess the activity as consistent with China-based operators but do not attribute it to a specific group.

Article Details

Attack Vectors
  • Operators exploited SQL injection against a Taiwanese chemical company's website, extracted source code and database information, and staged cloned pages for credential harvesting.
  • Hardcoded Supabase anon keys and Azure Logic App SAS tokens in publicly accessible JavaScript enabled access to a Taiwanese manufacturer's backend cloud infrastructure and compromise of cloud service accounts.
  • SQLMap-assisted SQL injection bypassed authentication on a Thai government administrative system. Operators accessed its admin panel and deployed a GIF polyglot web shell.
  • After obtaining credentials from an Afghan government application's exposed source code, operators developed a Python exploit targeting Laravel deserialization to achieve remote code execution.
  • An attacker-developed CORS exploit page extracted WordPress administrator account data from a payment processing platform.
  • Operators staged cloned U.S. government pages, including a completed login-page clone, but the article reports no confirmed U.S. intrusion or client-side credential-stealing code.
Defensive Notes
  • The article gives no explicit mitigation instructions. It cautions that ARL, Vshell, and DeepAudit have legitimate uses and that their presence alone does not establish malicious activity.
  • The researchers did not confirm that the recovered Linux/ARM implants are TencShell builds or that the proposed Gshell framework delivered malware.

Indicators of compromise

TypeIndicatorContext
IPV4112[.]213[.]124[.]132Malware-delivery server and suspected C2 hub hosting an open directory of intrusion materials.
IPV4112[.]213[.]124[.]159Linked malware-delivery server hosting an open directory and an attacker-developed CORS exploit page.
IPV4112[.]213[.]124[.]163Linked malware-delivery server identified through shared infrastructure fingerprints.
IPV4134[.]122[.]200[.]114Listed as a Gshell certificate-match server.
IPV4134[.]122[.]200[.]115Listed as a Gshell certificate-match server.
IPV4134[.]122[.]200[.]116Listed as a Gshell certificate-match server.
IPV4134[.]122[.]200[.]153Listed as suspected TencShell infrastructure.
IPV4134[.]122[.]200[.]154Listed as suspected TencShell infrastructure.
IPV4134[.]122[.]200[.]155Listed as suspected TencShell infrastructure.
IPV4192[.]163[.]167[.]10Listed as a Gshell certificate-match server.
IPV4192[.]163[.]167[.]5Listed as a Gshell certificate-match server.
IPV4192[.]163[.]167[.]6Listed as a Gshell certificate-match server.
IPV4192[.]163[.]167[.]7Listed as a Gshell certificate-match server.
IPV4192[.]229[.]115[.]229Listed as suspected TencShell infrastructure and observed presenting a Gshell-identifying certificate.
IPV4192[.]229[.]115[.]230Listed as suspected TencShell infrastructure and observed presenting a Gshell-identifying certificate.
IPV4192[.]238[.]134[.]166Listed as suspected TencShell infrastructure.
IPV438[.]55[.]105[.]143Server from which researchers recovered a related Linux/x86 malware sample; static analysis indicated a possible C2 endpoint.
IPV445[.]64[.]52[.]242Listed in the TencShell infrastructure table as a Cato Networks IOC.
IPV445[.]64[.]52[.]245Listed as suspected TencShell infrastructure.
IPV445[.]64[.]52[.]246Listed as suspected TencShell infrastructure.
SHA25603f26cbfa3ca15fcb43f512aa4041732beeec267f9d1dc74a11f7b0bb32e86bbHTTP header hash used to identify servers sharing the TencShell C2 fingerprint.
SHA2562954639be599f23c2229a9743aba09a1d9d11bf2becc62bf353384437db37deeReplacement TLS certificate fingerprint observed after the three linked servers reissued their certificates.
SHA25664107e3e0a333f685d1be6386426223a030c4126ac7c295aa7b1d54c508bbaceShared SSH host-key fingerprint linking three servers in the intrusion infrastructure.
SHA256643de2a1cf9148b896efecf560c9476fa56118ec477c4e15eb5c2da4b318061fHash of a Linux/x86 malware sample retrieved from the listed delivery server.
SHA25690b7b2c6f3d05234dc55678243039d7e51f0d54190239e5234a0005533337dc8Hash listed for Linux/ARM implant files retrieved from three malware-delivery servers.
SHA256ad1a0b3e22a10a2bd680b773b178a0d3824cfcbdf3551016f3d052a0b823079fTLS certificate fingerprint observed on three linked attacker-used servers; the certificate uses project defaults.

MITRE ATT&CK

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles