Chinese-speaking operator AI-orchestrated intrusion campaign targeting government and financial systems
Campaign
Summary
Hide ▲
Show ▼
A Chinese-speaking operator is running an AI-orchestrated intrusion campaign that automates attacks against government and financial systems across multiple countries. The operation uses Anthropic Claude Code, Alibaba Qwen, DeepSeek, and SecFlow to divide reconnaissance, exploitation, collection, and reporting across specialist agents. Named targets include systems in Afghanistan, Thailand, Taiwan, the U.S., Indonesia, mainland China, and Vietnam. The task-splitting workflow and repeated intrusion chain point to an active, scalable campaign rather than isolated probing.
Related Happenings
Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure
Campaign
H score17
First: 19.08.2026 20:50
Last: 19.08.2026 20:50
Sources 1
About this happening:
The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...
Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure
CampaignAbout this happening: The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor Meta
H score62
First: 14.08.2026 10:30
Last: 14.08.2026 10:30
Sources 1
About this happening:
Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score62
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Suspected China-linked AI-assisted intrusion campaign targeting government and financial systems
Campaign
H score35
First: 16.07.2026 14:17
Last: 16.07.2026 14:17
Sources 1
About this happening:
A suspected China-linked intrusion campaign is using Anthropic Claude Code and DeepSeek to automate intrusions and credential harvesting across government and financ...
Suspected China-linked AI-assisted intrusion campaign targeting government and financial systems
CampaignAbout this happening: A suspected China-linked intrusion campaign is using Anthropic Claude Code and DeepSeek to automate intrusions and credential harvesting across government and financ...
NCSC introduces Cyber Shield national AI defense program
Public Sector Action
H score27
First: 08.07.2026 11:10
Last: 08.07.2026 11:10
Sources 1
About this happening:
The NCSC introduced Cyber Shield, a national agentic AI defense capability aimed at strengthening protection for UK critical technology systems. The program is int...
NCSC introduces Cyber Shield national AI defense program
Public Sector ActionAbout this happening: The NCSC introduced Cyber Shield, a national agentic AI defense capability aimed at strengthening protection for UK critical technology systems. The program is int...
Timeline
-
10.09.2026 20:47 2 articles · 1h ago
Chinese-speaking operator AI-orchestrated intrusion campaign targeting government and financial systems
Initial DisclosureBy July 2026, the intrusion workflow was already using SecFlow to coordinate AI agents across government and financial targets. The early phase centered on task division, automated exploitation, and follow-on access expansion across multiple countries.
Show sources
- ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories — thehackernews.com — 10.09.2026 20:47
- ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories — thehackernews.com — 10.09.2026 20:47