GTG-10007 is a suspected Chinese-linked cyber-espionage group characterized as an exploit-development and vulnerability-research operation. The group used AI-assisted parallel agent workflows as an engineering and orchestration layer for foreign-government network reconnaissance, vulnerability research, exploit development, malware development, intrusion attempts, and intelligence-collection platform development. Its activity included reconnaissance against foreign-government networks in the Middle East, Europe, and Southeast Asia. GTG-10007 identified multiple previously unknown vulnerabilities affecting a major security product, developed working exploits for several network and security-appliance families, and used exploit code against government organizations. The group targeted approximately 50 organizations in government, education, retail, energy, technology, health care, financial services, and manufacturing; confirmed compromises included an education-technology company, a retailer, and a Southeast Asian government agency.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked espionage activity using Claude to coordinate intrusion and reconnaissance operations, autonomous vulnerability research, exploit development, malware development, and intelligence collection. The group targeted about 50 organizations across public- and private-sector industries and confirmed compromises of an education-technology firm, retailer, and Southeast Asian government agency.
A Chinese-linked activity cluster using parallel AI-agent swarms for reconnaissance and vulnerability research, producing numerous candidate zero-day vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.