Researchers uncovered an active cyber espionage campaign tied to TencShell infrastructure in which suspected China-linked operators used commercial AI tools as live components of intrusions against government targets in Afghanistan, Thailand, Taiwan, and the United States, while also targeting financial services organizations across Europe, Australia, and Asia. Evidence recovered from an exposed directory on 112.213.124[.]132 included victim source code, phishing pages, exploit scripts, malware, and operator logs, alongside a CLAUDE.md file that documented a split workflow: Claude Code handled execution, persistence, automation, and phishing-page iteration, while DeepSeek-v4-pro was used for reasoning, exploit adaptation, evasion logic, and script generation.
Investigators linked the activity to a broader cluster of 13 Hong Kong-based servers across four ASNs and found overlap with both TencShell and a possible parallel framework called Gshell. The campaign used techniques including SQL injection, deserialization-based RCE, CORS exploitation, credential harvesting, phishing infrastructure, and webshell deployment, with one key node reportedly hosting ARL, DeepAudit, Vshell, and thousands of stolen or operational files. Researchers said the combination of Simplified Chinese artifacts, infrastructure patterns, and victimology strongly indicates a China-based state-aligned threat actor, marking a notable shift from AI-assisted research to direct operational use of commercial AI systems during hands-on attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Investigators tied the operation to known TencShell command-and-control infrastructure and identified a broader cluster of 13 Hong Kong-based servers, with overlapping evidence suggesting a second framework called Gshell operated alongside it. Based on Simplified Chinese artifacts, infrastructure patterns, and targeting priorities, the activity was assessed as consistent with a China-linked or China-based state-aligned threat actor, though no specific group was named.
Analysis of the recovered logs and infrastructure showed the operators used Claude Code for execution, persistence, automation, and phishing-page iteration, while DeepSeek-v4-pro handled reasoning, exploit adaptation, evasion logic, and script generation. The campaign targeted government entities in Afghanistan, Thailand, Taiwan, and the United States, alongside financial services organizations across Europe, Australia, and Asia.
Researchers uncovered an active intrusion campaign in June 2026 after pivoting from known TencShell command-and-control infrastructure to an exposed open directory on 112.213.124[.]132. The exposed directory contained victim source code, exploit scripts, phishing pages, malware, and operator logs tied to the operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecyberaccord.com
Open sourcecybersecuritynews.com
Open sourcehunt.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.