Hunt.io Details Suspected China-Linked Campaign Using Claude Code and DeepSeek Against Government Systems

Summary
Hunt.io researchers uncovered suspected China-linked intrusions against government systems in Afghanistan, Thailand and Taiwan, alongside financial-sector targeting. Exposed logs show Claude Code and DeepSeek-v4-pro supporting reconnaissance, exploit development and, in
Key points
- An exposed directory on Hong Kong-hosted infrastructure contained victim source code, exploit scripts, malware, phishing-page clones and operator logs.
- Researchers documented compromises of government systems in Afghanistan and Thailand and two Taiwanese organizations; activity against U.S. government portals was reconnaissance and phishing preparation, not confirmed intrusion.
- Attack methods included SQL injection, authentication bypass, a Laravel deserialization exploit, and abuse of exposed cloud credentials and tokens.
- The Thailand breach exposed government employees’ names, national ID numbers and positions; the Afghan compromise exposed citizen complaints, source code and application credentials.
- Recovered logs show Claude Code managing execution and sessions while DeepSeek-v4-pro handled reasoning, attack logic and script generation.
- The researchers found Linux/ARM malware variants and infrastructure associated with TencShell, plus a suspected second C2 framework called Gshell.
- The researchers assess the activity as consistent with China-based operators but do not attribute it to a specific group.
Article Details
- Attack Vectors
- Operators exploited SQL injection against a Taiwanese chemical company's website, extracted source code and database information, and staged cloned pages for credential harvesting.
- Hardcoded Supabase anon keys and Azure Logic App SAS tokens in publicly accessible JavaScript enabled access to a Taiwanese manufacturer's backend cloud infrastructure and compromise of cloud service accounts.
- SQLMap-assisted SQL injection bypassed authentication on a Thai government administrative system. Operators accessed its admin panel and deployed a GIF polyglot web shell.
- After obtaining credentials from an Afghan government application's exposed source code, operators developed a Python exploit targeting Laravel deserialization to achieve remote code execution.
- An attacker-developed CORS exploit page extracted WordPress administrator account data from a payment processing platform.
- Operators staged cloned U.S. government pages, including a completed login-page clone, but the article reports no confirmed U.S. intrusion or client-side credential-stealing code.
- Defensive Notes
- The article gives no explicit mitigation instructions. It cautions that ARL, Vshell, and DeepAudit have legitimate uses and that their presence alone does not establish malicious activity.
- The researchers did not confirm that the recovered Linux/ARM implants are TencShell builds or that the proposed Gshell framework delivered malware.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 112[.]213[.]124[.]132 | Malware-delivery server and suspected C2 hub hosting an open directory of intrusion materials. |
| IPV4 | 112[.]213[.]124[.]159 | Linked malware-delivery server hosting an open directory and an attacker-developed CORS exploit page. |
| IPV4 | 112[.]213[.]124[.]163 | Linked malware-delivery server identified through shared infrastructure fingerprints. |
| IPV4 | 134[.]122[.]200[.]114 | Listed as a Gshell certificate-match server. |
| IPV4 | 134[.]122[.]200[.]115 | Listed as a Gshell certificate-match server. |
| IPV4 | 134[.]122[.]200[.]116 | Listed as a Gshell certificate-match server. |
| IPV4 | 134[.]122[.]200[.]153 | Listed as suspected TencShell infrastructure. |
| IPV4 | 134[.]122[.]200[.]154 | Listed as suspected TencShell infrastructure. |
| IPV4 | 134[.]122[.]200[.]155 | Listed as suspected TencShell infrastructure. |
| IPV4 | 192[.]163[.]167[.]10 | Listed as a Gshell certificate-match server. |
| IPV4 | 192[.]163[.]167[.]5 | Listed as a Gshell certificate-match server. |
| IPV4 | 192[.]163[.]167[.]6 | Listed as a Gshell certificate-match server. |
| IPV4 | 192[.]163[.]167[.]7 | Listed as a Gshell certificate-match server. |
| IPV4 | 192[.]229[.]115[.]229 | Listed as suspected TencShell infrastructure and observed presenting a Gshell-identifying certificate. |
| IPV4 | 192[.]229[.]115[.]230 | Listed as suspected TencShell infrastructure and observed presenting a Gshell-identifying certificate. |
| IPV4 | 192[.]238[.]134[.]166 | Listed as suspected TencShell infrastructure. |
| IPV4 | 38[.]55[.]105[.]143 | Server from which researchers recovered a related Linux/x86 malware sample; static analysis indicated a possible C2 endpoint. |
| IPV4 | 45[.]64[.]52[.]242 | Listed in the TencShell infrastructure table as a Cato Networks IOC. |
| IPV4 | 45[.]64[.]52[.]245 | Listed as suspected TencShell infrastructure. |
| IPV4 | 45[.]64[.]52[.]246 | Listed as suspected TencShell infrastructure. |
| SHA256 | 03f26cbfa3ca15fcb43f512aa4041732beeec267f9d1dc74a11f7b0bb32e86bb | HTTP header hash used to identify servers sharing the TencShell C2 fingerprint. |
| SHA256 | 2954639be599f23c2229a9743aba09a1d9d11bf2becc62bf353384437db37dee | Replacement TLS certificate fingerprint observed after the three linked servers reissued their certificates. |
| SHA256 | 64107e3e0a333f685d1be6386426223a030c4126ac7c295aa7b1d54c508bbace | Shared SSH host-key fingerprint linking three servers in the intrusion infrastructure. |
| SHA256 | 643de2a1cf9148b896efecf560c9476fa56118ec477c4e15eb5c2da4b318061f | Hash of a Linux/x86 malware sample retrieved from the listed delivery server. |
| SHA256 | 90b7b2c6f3d05234dc55678243039d7e51f0d54190239e5234a0005533337dc8 | Hash listed for Linux/ARM implant files retrieved from three malware-delivery servers. |
| SHA256 | ad1a0b3e22a10a2bd680b773b178a0d3824cfcbdf3551016f3d052a0b823079f | TLS certificate fingerprint observed on three linked attacker-used servers; the certificate uses project defaults. |
MITRE ATT&CK
T1071.001 · Web ProtocolsThe recovered Linux/ARM implant beaconed over WebSocket to port 4081 on the identified C2 hub.T1078 · Valid AccountsOperators used recovered credentials to access an Afghan government application's data and leveraged exposed cloud credentials against a Taiwanese manufacturer's backend accounts.T1110 · Brute ForceRecovered material documented password brute-forcing against reconnaissance targets and failed brute-force attempts against billing platforms.T1190 · Exploit Public-Facing ApplicationOperators exploited SQL injection in Taiwanese and Thai web systems and developed a Laravel deserialization exploit for an Afghan government application.T1505.003 · Web ShellAfter gaining access to a Thai government admin panel, operators deployed a GIF polyglot web shell for persistent command execution through GET parameters.T1552.001 · Credentials In FilesOperators found hardcoded cloud-access tokens in publicly accessible JavaScript and recovered application credentials from exposed source code.T1595 · Active ScanningOperators scanned more than 5,890 government hosts and used scripts for DNS enumeration, adjacent-IP discovery, and HTTP service fingerprinting.
Malware
HSEWH-Ur1111 on 112.213.124[.]132 triggered the download of a previously unreported Linux/ARM 32-bit binary, HSEWH-Ur. The Golang-compiled, statically linked executable beacons over WebSocket to port 4081 on the same host,TencShellIn June 2026, a pivot from known TencShell C2 infrastructure led us to an open directory exposing an active intrusion campaign. TencShell is a Go-based implant derived from the open-source Rshell framework, first
Vendors
Antbox Networks Limitedand distributed across four autonomous systems: VMISS Inc., MEGA-II IDC, CTG Server Limited, and Antbox Networks Limited. Beyond port 1111, the cluster also exposed services on ports 1212, and 8090.Anthropicattempts, and built the phishing pages used to harvest credentials. That puts this campaign alongside Anthropic's November 2025 disclosure of a China-linked operation that used Claude Code to automate large-scaleCTG Server Limitedall located in Hong Kong and distributed across four autonomous systems: VMISS Inc., MEGA-II IDC, CTG Server Limited, and Antbox Networks Limited. Beyond port 1111, the cluster also exposed services on ports 1212,MEGA-II IDCunreported, are all located in Hong Kong and distributed across four autonomous systems: VMISS Inc., MEGA-II IDC, CTG Server Limited, and Antbox Networks Limited. Beyond port 1111, the cluster also exposed servicesVMISS Inc.previously unreported, are all located in Hong Kong and distributed across four autonomous systems: VMISS Inc., MEGA-II IDC, CTG Server Limited, and Antbox Networks Limited. Beyond port 1111, the cluster also
Products
Azure Logic AppMultinational Telecom & Edge Device Manufacturer: Publicly accessible JavaScript files contained hardcoded Supabase anon keys, and Azure Logic App SAS tokens.Claude CodeWhat caught our attention was the tooling behind it. Claude Code and DeepSeek-v4-pro ran as working parts of the intrusion, not tools off to the side. They handled reasoning for bypass techniques, reworked exploitsDeepSeek-v4-proWhat caught our attention was the tooling behind it. Claude Code and DeepSeek-v4-pro ran as working parts of the intrusion, not tools off to the side. They handled reasoning for bypass techniques, reworked exploitsLaravelExfiltrated source code appeared in two directories: [victim]_git/ and [victim]_git_dump/, revealing a Laravel framework version 5.8.38 installation. Encryption keys, database credentials, and mail handling code wereSupabaseMultinational Telecom & Edge Device Manufacturer: Publicly accessible JavaScript files contained hardcoded Supabase anon keys, and Azure Logic App SAS tokens.WordPressreproduced styling and formatting but was missing its images, while a matching clone of the site's WordPress login page was fully built.
Tools
ARLport 8888. Additionally, the server was flagged as high risk for exposing Asset Reconnaissance Lighthouse (ARL) and a Vshell C2 service.DeepAuditFigure 02: Hunt.io IP profile for 112.213.124[.]132 showing open ports 1111, 3000 (DeepAudit), 5003 (ARL), 8084 (Vshell), and 8888 (open directory).The following ports and services were running on the server at the timeGshell443 and 8083 self-identifying as a separate C2 framework. The subject and issuer fields consist of CN = Gshell Server and O = Gshell C2. We were unable to find prior public reporting documenting a framework underHuntSQLwe pivoted on a HTTP header hash observed on port 1111 of the command and control nodes. Using HuntSQL, we developed a simple query to search for additional servers sharing identical header fingerprints overRshellexposing an active intrusion campaign. TencShell is a Go-based implant derived from the open-source Rshell framework, first documented by Cato CTRL in May 2026 and assessed there as suspected China-linked. ThesqlmapA Thai government administrative system fell victim to a SQL injection exploitation using SQLMap. The attackers achieved authentication bypass and admin panel access, enabling deployment of a GIF polyglot webshell forVShellthe server was flagged as high risk for exposing Asset Reconnaissance Lighthouse (ARL) and a Vshell C2 service.
Countries
AfghanistanActive exploitation of government systems in Afghanistan, Thailand, and Taiwan, with reconnaissance and phishing staging against U.S.Australiafailed password brute-force attempts showed a specific targeting of billing platforms across Europe, Australia, and Asia. The combination of this material alongside the government targeting on the same dedicatedChinaopen-source Rshell framework, first documented by Cato CTRL in May 2026 and assessed there as suspected China-linked. The directory held victim source code, custom exploit scripts, operational logs, and cloned loginTaiwanActive exploitation of government systems in Afghanistan, Thailand, and Taiwan, with reconnaissance and phishing staging against U.S.ThailandActive exploitation of government systems in Afghanistan, Thailand, and Taiwan, with reconnaissance and phishing staging against U.S.United StatesUnited States
Industries
Chemical manufacturingChemical Manufacturing & Trading Company: The company website was successfully attacked via SQL injection. The operators extracted development environment source code and database information, before staging cloned webFinancial ServicesFinancial Services TargetingGovernmentActive exploitation of government systems in Afghanistan, Thailand, and Taiwan, with reconnaissance and phishing staging against U.S.ManufacturingFurther review of the files and subfolders revealed targeting across Taiwanese supply chain and manufacturing sectors. Reconnaissance activity spanned 8 organizations, with varying levels of probing. From what we wereSemiconductorsShippingContainer shipping operatorDNS and subdomain enumeration, password brute-forcingTelecommunicationsprovided a foundation for the activity that followed against both the chemical manufacturer and telecommunications company.