Hunan University Students Expose Multinational Government Cyber Attacks Using AI

On Thursday, September 10, the American artificial intelligence company Anthropic released its latest threat report, exposing a persistent network espionage operation codenamed “GTG-10007” and accusing seven Chinese AI companies of engaging in “illegal distillation” of its Claude model.

The report revealed that the operation was mainly initiated by Chinese Mandarin-speaking operators from Changsha, Hunan Province, China, including university students from the Computer and Communication Engineering School of a university in Hunan. Hackers used Anthropic’s AI model Claude as an “orchestration layer” to launch sophisticated attacks on government networks worldwide.

Specifically mentioned in the report, one of the Hunan university students involved had interned at the Chinese cybersecurity giant Sangfor and actively applied for an offensive network operation position at another cybersecurity firm, QiAnXin, during the operation.

The GTG-10007 hacker group deployed Claude as an automated brain to coordinate reconnaissance and intrusion attempts on government networks in the Middle East, Europe, and Southeast Asia, while conducting vulnerability research on mainstream endpoint security products and developing attack tools.

Of particular note, the group constructed an automated hacker toolkit and parallel workflow, enabling vulnerability research and intelligence collection platforms to operate around the clock even when operators are offline or away from the computer.

In addition to the network attacks by the GTG-10007 group, the report also revealed accounts with ties to the Chinese Communist Party using Claude to generate propaganda content in local languages, posing as recruiters targeting Uighurs in Syria for recruitment and intelligence penetration. They also utilized AI to generate multilingual social media content for cross-border network influence operations.

Furthermore, the report detailed for the first time the specifics of the “illegal distillation” by Chinese companies – secretly extracting Claude’s capabilities to train their competitive models. Anthropic named Alibaba, Moonshot AI, DeepSeek, SmartSpectrum AI, Xiaomi, SenseTime, and MiniMax as the seven Chinese AI labs involved. Moonshot AI, for example, launched nearly 300,000 requests through 5,380 fake accounts in just 10 days; between May and July, interactions related to it reached as high as 23 million times.

Anthropic stated that the company has completely banned the relevant accounts involved and shared threat intelligence with public and private security agencies to curb the misuse of large language models for national-level network attacks and intelligence collection.