Skip to content
The ColumnInvestigation· No. 6884

INVESTIGATION: A leaky Hong Kong server exposes an AI-powered Chinese spy ring

An open directory on a Hong Kong server contained, at the moment of its discovery, 2,431 files and 80 subdirectories : victims' source code, custom exploitation scripts, cloned login pages, operator logs written in…

Premium reading
AI-generatedMadMax
Key takeaways
  1. An open directory on a Hong Kong server contained, at the moment of its discovery, 2,431 files and 80 subdirectories : victims' source code, custom exploitation scripts, cloned login pages, operator logs written in…
  2. An open directory on a Hong Kong server contained, at the moment of its discovery, 2,431 files and 80 subdirectories : victims' source code, custom exploitation scripts, cloned login pages, operator logs written in simplified Chinese, according to a report published by Hunt.io and reported by Security Affairs on July 16, 2026 .
  3. This is not an accidental leak.
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

An open directory on a Hong Kong server contained, at the moment of its discovery, 2,431 files and 80 subdirectories: victims' source code, custom exploitation scripts, cloned login pages, operator logs written in simplified Chinese, according to a report published by Hunt.io and reported by Security Affairs on July 16, 2026. This is not an accidental leak. It is the documented back room of an active intrusion campaign, found by researchers who were looking for something else entirely.

The starting point comes down to an almost trivial technical detail: a unique HTTP header fingerprint on port 1111, spotted by Hunt.io researchers while examining a command-and-control infrastructure nicknamed "TencShell." That fingerprint led, server by server, to thirteen machines based in Hong Kong. A digital fingerprint left behind by mistake forgives nothing; month after month, it tells everything an operator wanted to keep secret. What this discovery reveals goes well beyond a simple inventory of stolen files.

This investigation relies exclusively on the Hunt.io report relayed by Security Affairs on July 16, 2026, with the caution required by a file where precise attribution to a state actor rests on technical indicators, not formal proof of direct government involvement. The Chinese government has not, to date, commented on any element of this specific report.

A discovery born from a technical detail

An HTTP fingerprint's trail to thirteen servers

Hunt.io researchers discovered this intrusion campaign in June 2026, while examining a command-and-control infrastructure linked to Chinese actors. The investigative method itself deserves notice: it was not an outside alert or a victim complaint that triggered the discovery, but systematic work tracing network fingerprints carried out by security researchers.

This unique, and therefore identifiable, HTTP header fingerprint led to thirteen servers based in Hong Kong. The choice of this jurisdiction is not neutral for security researchers who have tracked attack infrastructure linked to Chinese actors for years: Hong Kong offers easy access to international networks while remaining under a jurisdiction close to mainland China.

An open directory that documents the operation from inside

One of these thirteen servers held an open directory, accessible without particular authentication — an operational error that let researchers document the operation from the inside rather than from the outside. This kind of mistake, however rare, turns an investigation of indirect reconstruction into a direct reading of an attacking group's methods.

The contents of this directory paint a precise inventory: exfiltrated victims' source code, custom exploitation scripts adapted to specific targets, cloned login pages built for credential phishing, and operator logs written in simplified Chinese. An operator's log is never written to be read by an outsider; when it is, someone left the door open longer than they meant to.

The documented role of artificial intelligence tools

Claude Code and DeepSeek inside the attack chain

Hunt.io's report specifies that the artificial intelligence tools used in this campaign — Claude Code and DeepSeek — handled part of the reasoning needed to develop bypass techniques against target defenses. This is not an incidental detail in the story of the attack. It is, according to the researchers, an active component of the offensive setup itself.

According to the same researchers, these AI tools also reworked exploits after failed attempts, an automated iterative adjustment process that, in a more traditional attack model, would have required prolonged manual intervention by experienced human operators.

Phishing pages built by the same tools

The same AI tools, still according to Hunt.io, built the phishing pages used to harvest login credentials from targets. The full chain — reconnaissance, evasion, phishing — therefore relies, to varying degrees documented by the researchers, on algorithmic assistance rather than entirely handcrafted work.

This reliance on off-the-shelf AI tools, rather than custom malware entirely written by humans, changes the nature of the risk for defense teams. A tool built to write code faster also writes, without making any moral distinction, attack code faster.

A documented precedent since November 2025

Anthropic's disclosure of a China-linked operation

Hunt.io's report explicitly places this campaign in the continuity of an earlier disclosure: the one published by Anthropic in November 2025 about a China-linked operation that used Claude Code to automate intrusions at scale. This is therefore not an isolated episode, but the documented continuation of a mode of operation already flagged by the very maker of one of the tools involved.

This continuity raises a question the report does not close: the ability of AI tool providers to detect and stop malicious use of their own products once that mode of operation has been publicly documented. Nine months separate Anthropic's first disclosure from this new campaign spotted by Hunt.io.

What this continuity reveals about the scale of the phenomenon

The fact that a second, distinct campaign, using the same categories of tools, could be discovered several months after the first disclosure suggests the method was not neutralized by the publicity given to the original case. On the contrary, it appears to have diversified geographically, now touching targets beyond the initial scope documented by Anthropic.

This persistence, documented by two independent investigations nine months apart, is in itself a more troubling signal than either report taken alone. A method denounced once that resurfaces elsewhere is not an accident; it is proof that it still works.

A geographic reach that extends beyond Asia

The financial sector targeted in Europe, Australia, and Asia

A parallel campaign, documented by the same report, hit financial services companies in Europe, Australia, and Asia. This broad geographic footprint sets this operation apart from the more regionally confined cyberespionage campaigns that traditionally make headlines about Chinese actors.

The choice of the financial sector as a target is not incidental. It matches a documented interest in high-value datatransaction information, internal compliance structures, credentials for sensitive systems — rather than a simple theft of industrial intellectual property.

What this geographic spread means for defenses

A campaign hitting three separate continents simultaneously considerably complicates defensive coordination between national security teams, each operating under different legal frameworks and alert thresholds. No source consulted mentions any formal international coordination mechanism set up specifically in response to this campaign.

This absence of documented coordination leaves each affected jurisdiction managing its own response, with the risk that early warning signals detected in one country do not reach security teams in another country hit by the same infrastructure in time.

No information-sharing structure is mentioned as having been activated specifically for this campaign, which contrasts with mechanisms already in place in other critical sectors like aviation or energy. An attack that crosses three continents at once asks no border for permission; defenses, meanwhile, still stop at the border.

Hunt.io's responsible disclosure window

Seven days between notification and publication

Hunt.io notified the affected organizations and the relevant national CERTs on July 6, 2026, then deliberately withheld publication of its report for a seven-day disclosure window. This practice, standard in the cybersecurity industry, aims to give victims time to fix their vulnerabilities before technical details become public and exploitable by other malicious actors.

The report was ultimately published, via Security Affairs, only on July 16, 2026, ten days after the initial notification — slightly longer than the announced seven-day window, with no precise explanation given for this gap in the available sources.

What this procedure does not guarantee

A responsible disclosure window protects notified organizations, but it guarantees nothing about the fate of unidentified victims or those not notified in time, who remain exposed for the entire duration of that window without knowing it. The report does not specify how many organizations, in total, received a direct notification.

This documentary blind spot is not a criticism of Hunt.io's method, widely recognized as responsible within the industry, but a reminder that coordinated disclosure remains an imperfect compromise between the immediate protection of known victims and complete public information. Protecting ten notified organizations says nothing about the fate of the eleventh, still unaware it is a target.

The question of state attribution

Technical clues, not formal proof

The attribution of this campaign to a Chinese state actor, rather than to a criminal group simply operating from Chinese territory, rests on technical clues: the language of the operator logs, the nature of the infrastructure used, the continuity with the mode of operation described by Anthropic in November 2025. None of these sources alone constitutes formal proof of direct government involvement.

This distinction is not a minor legal detail. It fundamentally changes the nature of the appropriate response: a diplomatic response to a sovereign state differs radically from a purely law-enforcement response to an unaffiliated criminal group, even when both operate from the same territory.

Beijing's silence as data in itself

The Chinese government has not commented on this specific report, according to the sources available for this investigation. This silence is neither an admission nor a denial: it fits a recurring pattern in which Beijing publicly responds to only a fraction of the Western cyberespionage accusations directed at it.

The absence of an official reaction leaves the case in a documentary gray zone where technical evidence accumulates without either party, neither the researchers nor the accused government, being able to definitively settle the question of direct state responsibility. A silence that lasts never proves innocence; it does not prove guilt either. It proves only the absence of a response.

What this case reveals about the race for offensive AI

Consumer tools diverted for offensive purposes

Claude Code and DeepSeek were not, originally, tools designed for espionage. They are coding assistants meant for legitimate commercial and software-development uses. Their documented misuse for cyberespionage illustrates a structural problem: the dual nature of any tool powerful enough to accelerate legitimate work accelerates, in the same proportion, malicious work.

This finding is not unique to China or to these two specific tools. It applies, in principle, to the entire large language model ecosystem capable of generating functional code, regardless of geographic origin or provider.

The responsibility of AI tool providers

Anthropic's disclosure in November 2025 had already set a precedent: that of an AI provider documenting the malicious use of its own product itself, rather than leaving that discovery to third parties. This voluntary transparency remains, to date, the exception rather than the norm in an industry where most providers say little about the documented misuse of their tools.

The persistence of similar campaigns nine months after that disclosure raises a question no source consulted closes: that of the real effectiveness of the corrective measures taken by AI providers after identifying documented malicious use. Documenting an abuse does not automatically stop it; the closed door still has to stay closed.

The documentary limits of this investigation

What the report does not quantify

None of the sources consulted provide a precise figure for the total number of victims hit by this campaign, nor for the financial scale of the damage caused to the financial services companies targeted in Europe, Australia, and Asia. Hunt.io's report focuses on the technical description of the infrastructure and methods, not on a numbered tally of consequences.

This absence of figures should not be read as a sign of small scale. It reflects instead the inherent limits of an investigation conducted from outside the attacking infrastructure, without direct access to the victims' own systems to precisely assess data or financial losses.

What methodological caution requires us not to claim

This investigation cannot, with the sources available, confirm that the Chinese government directly commissioned this campaign, nor establish a formal chain of responsibility beyond the technical clues already mentioned. Any claim in that direction would exceed what the sources allow us to establish.

Rigor, here again, is not an obstacle to the story but the condition of its credibility. Accusing more forcefully than the facts prove never strengthens a case; it simply hands the accused a weakness to point to.

The broader context of Sino-Western technological tensions

A case that adds to other documented frictions

This cyberespionage case fits within a broader climate of technological tensions between China and Western powers, a climate also fed by documented frictions over export controls on semiconductors and critical minerals that arose in the same period, in July 2026. Each new case, whether commercial or security-related, feeds an already-established mutual mistrust.

This accumulation of frictions across different registers — trade, cybersecurity, military technology — draws a landscape where each side builds, case after case, a case for mistrust of the other, with no international body appearing able to arbitrate the whole.

The absence of a multilateral framework for AI-driven offensive cybersecurity

No source consulted mentions the existence of a multilateral framework specifically designed to govern the use of artificial intelligence tools in state or quasi-state cyberespionage campaigns. Existing AI governance bodies focus, for the most part, on questions of model safety and commercial ethics, not on their misuse in intelligence operations.

This gap in international governance leaves every AI provider and every government managing, separately and by its own rules, a phenomenon that, by its nature, ignores national borders. Treaties get negotiated for the weapons we can see; no one has yet negotiated one for the weapons that write their own code.

What this campaign means for targeted companies

A vulnerability that no longer depends only on human defense

For the financial services companies targeted by this campaign, the finding documented by Hunt.io changes the nature of the risk to anticipate. A defense designed to spot an attacker's classic human errors — slow reaction times, poorly adapted exploits, generic phishing pages — becomes less effective against AI tools capable of quickly correcting their own mistakes after a failure.

This shift imposes, following the very logic of the report, a revision of traditional defense assumptions, which often supposed a limited human adaptation speed on the attacker's side. That limit no longer holds the same way when the attacker relies on AI tools to rework its exploits.

What companies still cannot measure

No source consulted establishes how many, among the companies targeted in Europe, Australia, and Asia, actually suffered a confirmed data exfiltration, as opposed to a mere detected attempt blocked in time. This distinction, essential for assessing the real scale of the damage, remains absent from the available report.

This documentary uncertainty does not erase the seriousness of the signal sent by this discovery: a sophisticated, AI-assisted attack infrastructure operated across multiple continents before being spotted by outside researchers rather than by the victims' own internal defenses. It was not the target's defense that detected the attack; it was a researcher's curiosity, chasing something else. That sentence alone sums up the scale of the problem.

The precedent of documented state cyberespionage campaigns

A gradual escalation rather than a sudden break

Cyberespionage campaigns attributed, with varying degrees of certainty, to actors linked to China are not a new phenomenon in 2026. What changes, documented specifically by this case and by Anthropic's November 2025 disclosure, is the gradual integration of generative AI tools into attack chains that previously relied on entirely human work.

This technical evolution fits within a gradual escalation rather than a sudden, visible rupture. Each documented campaign adds a piece to a larger puzzle, that of artificial intelligence's growing place in offensive intelligence operations, regardless of national origin.

What the repetition of this method implies for the future

The probability that this method will repeat, a third time, in some still-different form, cannot be ruled out based on the two documented occurrences alone. What the sources allow us to state is that the mode of operation was not neutralized by its first public exposure, which is itself a strong indicator of its likelihood to recur.

This documented recurrence places an obligation of vigilance, for AI providers and defense teams alike, that can no longer be limited to a one-off response after each discovery. A method that returns twice is no longer an incident; it is already, nearly, a doctrine.

The precedent of campaigns attributed to Western actors

An asymmetry of scrutiny worth naming

The media and political treatment of cyberespionage campaigns is not always symmetric depending on the geographic origin of the suspected actor. Campaigns attributed to Western services have, in the past, received different coverage than campaigns attributed to Chinese, Russian, or North Korean actors, without that difference in treatment always resting on an objective difference in the severity of the facts.

This asymmetry does not excuse this investigation from its methodological rigor toward the Chinese case documented here. It simply invites placing this Hunt.io report within a broader landscape of multipolar cyberespionage, where several powers, not just one, are developing AI-assisted offensive capabilities.

What this perspective does not change

Recognizing the existence of similar offensive capabilities elsewhere in no way reduces the documented seriousness of the campaign described in Hunt.io's report. The reported facts — identified infrastructure, documented methods, victims spread across three continents — remain intact, regardless of the geography of other comparable campaigns run by other powers.

This perspective serves the rigor of the case, not its dilution.

No source consulted allows a figure-for-figure comparison of the scale of this Chinese campaign against comparable operations run by other powers, for lack of equivalent reports made public with the same level of technical detail. Naming an asymmetry of treatment does not dilute a proven accusation; it simply places it in a more honest landscape.

What the comparison with Western defenses reveals

Rising cybersecurity budgets, but detection still external

The financial services companies targeted by this campaign operate, for the most part, in jurisdictions where cybersecurity budgets have risen steadily in recent years. That increase was nonetheless not enough to allow internal detection of the campaign documented by Hunt.io, which was spotted from outside rather than from within the victims' own defense systems.

This finding does not mean those budgets are poorly spent. It signals instead that the adaptation speed of an AI-assisted attack can, in certain documented cases, outpace the detection capacity of otherwise well-funded defenses.

What this limit implies for future campaigns

If properly funded defenses were not enough to detect this campaign before an outside researcher spotted it by technical chance, the question of the sufficiency of current defense models against AI-assisted attacks remains open for the entire global financial sector, not just the documented victims of this particular campaign.

This question goes beyond the scope of this single investigation, but it flows directly from it. A defense budget that grows every year guarantees nothing if the threat it must counter changes faster than it does.

What this investigation establishes, with the caution required by sources that do not allow confirming direct government involvement, is that a sophisticated cyberespionage infrastructure, assisted by diverted AI tools, operated across three continents before being spotted by outside researchers. The fact that this discovery fits the continuity of an earlier Anthropic disclosure strengthens the hypothesis of a persistent mode of operation rather than an isolated incident.

What remains to be established, in the months ahead, is the real scale of the damage suffered by the targeted companies and the ability of AI providers to durably prevent the misuse of their tools for offensive ends. What the next disclosure, if it comes, will confirm or disprove is the trajectory of this silent escalation. An open directory left by mistake was enough to reveal this case; next time, the mistake might not happen.

This case remains, despite everything, a file of converging technical clues rather than closed legal proof, and it is precisely this limit that must frame any future reading of this affair.

Signed Maxime Marquette, columnist

Columnist's Transparency box

Editorial positioning

This investigation is written from an acknowledged angle, pro-Western, which guides the priority given to the consequences for Western companies and institutions targeted by this campaign. This positioning is a declared editorial choice, not a claim to absolute neutrality, but it implies no fixed categorization of any government as guilty beyond what the sources establish: attribution to a Chinese state actor is presented as a documented hypothesis, not as a legally established fact.

Methodology and sources

This investigation relies exclusively on the report from Hunt.io, relayed by Security Affairs on July 16, 2026, as the single primary source for all the technical facts reported. A secondary source from CNBC was consulted for the broader context of AI-linked cyberattacks involving Chinese actors. Every figure or technical detail has been explicitly attributed to its source; where data was missing, notably on the total number of victims, that limitation is flagged in the text rather than hidden.

Nature of the analysis

This text distinguishes three categories of information: corroborated facts from Hunt.io's technical report; attributed quotes from the researchers, presented with explicit attribution and no additional implicit validation; and the columnist's personal analysis, clearly identified by tone and phrasing, which reflects only his own judgment on the significance of the reported facts, never on any government guilt presented as proven.

Sources

Primary sources

Secondary sources

Get the geopolitics analyses

Conflicts, powers, alliances: the MadMax thread without the noise.

Cite this article

Maxime Marquette (2026). INVESTIGATION: A leaky Hong Kong server exposes an AI-powered Chinese spy ring. MadMax. https://mad-max.co/en/article/investigation-a-leaky-hong-kong-server-exposes-an-ai-powered-chinese-spy-ring

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Investigation33 reads3625 words20 min read