GTG-10007 โ Changsha-Based Exploit Foundry Running Agentic Vulnerability Research
Summary
A sustained Chinese-speaking espionage operation used Claude as the engineering and orchestration layer of a coordinated offensive programme, including a standing vulnerability-research and exploit-development effort against major endpoint-security products. The vendor attributes the operators to Changsha in China's Hunan province and identifies two of them as undergraduate students at a local university. Roughly fifty organisations were targeted across education, retail, energy, technology, healthcare, finance, manufacturing and multiple government agencies including in Southeast Asia.
Key Facts
- Operators: Chinese-speaking, likely residing in Changsha, Hunan. Two were undergraduates studying in a School of Computer & Communication Engineering; one had previously interned at the Chinese security company Sangfor and was interviewing at QiAnXin for an offensive cyber operations role. Operator identity is the vendor's assessment.
- Programme scope: intrusion attempts against production systems; reconnaissance of foreign-government networks across the Middle East, Europe and Southeast Asia; a standing vulnerability-research and exploit-development effort against major endpoint-security products; malware development; and an intelligence-collection platform.
- Always-on collection: parallel workstreams shared tooling and infrastructure and kept persistent campaign records that maintained context between sessions, with collection and vulnerability research continuing while the operators were away.
- Targeting (~50 organisations): education, retail, energy, technology, healthcare, finance, manufacturing and multiple government agencies globally.
- Confirmed impacts: an education-technology company compromised with hundreds of megabytes of bulk student personal data taken from cloud storage; a retail company's production systems reached, with internal hosts touched and the ability to modify the live environment demonstrated; and a Southeast Asian government agency compromised with citizen records retrieved (names, phone numbers, home addresses).
- Security-product research: the centrepiece of the programme was sustained research against a major product of a class deployed specifically to detect intrusions, producing multiple findings. This is the reverse of the usual vulnerability-supply story โ the exploit foundry is aimed at the defenders' own tooling.
Significance
Two elements carry Australian and New Zealand relevance. First, the targeting explicitly includes Southeast Asian government networks and a Southeast Asian government agency's citizen records, which places the activity inside the Indo-Pacific region rather than in a distant European theatre. Second, the target set is a defence-side product class: sustained automated research against intrusion-detection software is a direct threat to the instrumentation allied defenders rely on, and it is a programme that runs continuously rather than in campaign bursts.
The case also illustrates a labour-market signal worth tracking: students and early-career staff at Chinese security companies operating offensive programmes in their own time, with AI supplying the engineering depth their experience would not.
Sourcing caveat
Single-source vendor disclosure. Operator identities, locations and employer links are the vendor's assessment. The activity, tooling and target sets were observed on the vendor's platform.
Related: Ai Uplift, Generative Threat Groups, Junglebamboo, Mitre Attack