// ClaudeHIGH
Security researchers uncovered an active cyber espionage campaign discovered in June 2026 where suspected China-linked threat actors used Claude Code and DeepSeek-v4-pro as operational components during intrusions targeting government organizations in Afghanistan, Thailand, and Taiwan. Exposed infrastructure contained victim source code, exploit tools, phishing templates, and operator logs. Claude Code was reportedly used to execute commands, maintain persistent sessions, manage parallel tasks, and build phishing pages as part of the split-model workflow.
- Suspected Chinese Hackers Use Claude Code and DeepSeek to Breach(opens in a new tab)
- Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaig(opens in a new tab)
- Chinese Hackers Embed Claude Code and DeepSeek in AI-Powered Gov(opens in a new tab)
// Get alerts for Claude