Chinese hacking firms are increasingly utilizing artificial intelligence to enhance their cyber-espionage capabilities, according to reports from Google's Threat Intelligence Group and AI company Anthropic. These groups are moving beyond basic AI prompting to employ AI agents that can automate significant portions of their intrusion campaigns, drastically reducing the time spent actively hacking and sometimes completing an entire operation in less than six hours.

One specific Chinese group, tracked by Google since 2023, has focused relentlessly on academic, medical, and military research organizations in North America, particularly targeting proprietary AI research. This group is compromising unrelated victims' cloud networks to install open-source AI models. This method allows hackers to query models without leaving a trace via commercial AI products and to bypass monitoring and guardrails that commercial chatbots might impose, as explained by John Hultquist, chief analyst at Google's Threat Intelligence Group.

Anthropic also reported disrupting a cyber operation linked to the Chinese government that used an AI system to direct hacking campaigns. This operation targeted approximately thirty global entities, including tech companies, financial institutions, chemical companies, and government agencies, succeeding in a small number of cases. Researchers noted that the concerning aspect was the degree of automation achieved by AI in these operations. Separately, an autonomous AI system was reported to have conducted cyberattacks on Taiwan's government agencies, mapping 21 systems, cracking 85 user accounts, and extracting 2,500 personnel records over four days in July.

Furthermore, threat intelligence firm Hunt.io documented a second China-linked campaign that integrated commercial AI models directly into cyber-espionage. This campaign targeted Taiwan's Kuomintang Party archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Vietnam. The AI models assisted in automating tasks such as scanning for vulnerabilities, testing stolen credentials, deploying webshells, collecting data, and generating reports, rather than autonomously breaching systems. One significant breach involved a Fengtai District government Office Automation environment in China, where operators achieved command execution, collected sensitive data including chronic-disease reports with patient health information, and created new privileged accounts. These operations utilized AI models like Claude, Qwen, and DeepSeek for reconnaissance, exploitation, and reporting, with some backend systems exposing AI agent configurations and chatbot conversations containing real student data.

In a related development, Chinese AI companies have been accused by Anthropic of attempting to clone American AI models by funneling millions of real Chinese user queries to them through intermediate platforms. This suggests a broader strategy by Chinese entities to leverage AI, both defensively for intelligence gathering and offensively for cyber operations, while also trying to replicate advanced AI capabilities.