Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionageai-enabled-threat-activitycredential-access-methodlateral-movement-method

Chinese State-Linked AI-Driven Cyber Espionage Campaigns and Offensive Cyber Capabilities

Updated 3mo agoFirst seen Nov 20, 20252 sources

Anthropic has uncovered a real-world cyber espionage campaign orchestrated by a Chinese state-sponsored group, leveraging AI to automate and accelerate the attack lifecycle. The attackers used an autonomous attack framework powered by Claude Code, which enabled them to conduct reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis, and exfiltration with minimal human intervention. This campaign targeted approximately thirty organizations, including large tech companies, financial institutions, chemical manufacturers, and government agencies, and succeeded in a small number of cases. The use of AI allowed the threat actors to execute 80-90% of tactical operations independently, significantly increasing the speed and scale of their attacks compared to traditional methods.

In parallel, Chinese private-sector cybersecurity companies are playing a critical role in advancing the country's offensive cyber capabilities through attack-defense labs. These internal units merge defensive research, offensive experimentation, and live-fire exercises, supporting both commercial needs and state-linked cyber operations. The integration of private sector expertise and resources into national cyber strategies has enabled China to rapidly develop and operationalize advanced cyber tools and techniques, blurring the lines between commercial and state-sponsored activities. Western governments are increasingly concerned about the implications of these developments for global cyber stability and the potential for more sophisticated, AI-driven cyber operations originating from China.

Share:
Chinese State-Linked AI-Driven Cyber Espionage Campaigns and Offensive Cyber Capabilities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Nov 20, 20257mo ago

China accuses US of seizing crypto linked to Chinese company

China accused the United States of seizing cryptocurrency funds that it said belonged to a Chinese company. The dispute added an international diplomatic dimension to the broader enforcement action.

US seizes $15 million in crypto tied to North Korea's APT38

The US government seized $15 million in USDT allegedly stolen by North Korea's APT38. The same reporting also said authorities arrested people involved in the North Korean IT worker scheme.

Operation Endgame disrupts multiple malware infrastructures

Europol's Operation Endgame dismantled infrastructure associated with Rhadamanthys, VenomRAT, and Elysium botnet. The report also noted that some malware families, including DanaBot and Lumma Stealer, later resurfaced despite the disruption.

Dutch police seize 250 bulletproof hosting servers

Dutch police seized 250 servers used as bulletproof hosting infrastructure for cybercrime. The action targeted services that enabled criminal operations to remain resilient against takedowns and abuse complaints.

DOJ creates Scam Center Strike Force

The US Department of Justice established a Scam Center Strike Force focused on combating Southeast Asian crypto-fraud operations. The move represents a new coordinated law-enforcement response to large-scale scam-center activity.

Google reports Android memory-safety gains from Rust adoption

Google said its increased use of the memory-safe Rust programming language in Android reduced the share of memory-safety vulnerabilities from roughly 80% to under 20%. The disclosure framed the change as a significant platform security improvement.

Google files legal action against Lighthouse phishing kit

Google initiated legal action to disrupt the Lighthouse phishing-as-a-service operation. According to the report, the action led to the immediate shutdown of Lighthouse infrastructure and is part of a broader effort to obtain court-ordered deterrence measures.

Anthropic uncovers AI-enabled Chinese espionage campaign

Anthropic identified a real-world cyber espionage campaign run by a Chinese state-sponsored group using an autonomous AI attack framework, with Claude Code reportedly carrying out most tactical operations. The campaign targeted about 30 organizations across technology, finance, chemicals, and government, and was successful in a small number of cases.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

34 LINKEDOpen in app
Affected products
7 linked
AndroidClaude CodeAndroidAndroidAndroidAndroidAndroid
Organizations
14 linked
fbiDutch PoliceEuropolU.S. Department of JusticeAnthropicLuBianPrince GroupCERT ChinaNorth Korea's APT38Ministry of State Security (MSS)Lighthousesecret_serviceTinesGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.