GTG-1002, also recorded as gtg_1002, is a Chinese state-sponsored cyberespionage threat cluster tracked by Anthropic. Its documented campaign was detected in mid-September 2025 and publicly disclosed in November 2025. The operation targeted approximately 30 organizations across multiple countries, including major technology companies, financial institutions, chemical manufacturers, and government agencies. A small number of successful intrusions were confirmed. The group used multiple independent Claude Code instances within a custom orchestration framework connected to offensive tools through Model Context Protocol (MCP) servers. Its tooling included Kali Linux and widely available penetration-testing utilities rather than custom malware. Operators bypassed model safeguards by presenting malicious activity as legitimate defensive testing and decomposing intrusion objectives into smaller technical tasks. AI agents conducted parallel reconnaissance, scanned exposed services, identified vulnerabilities, generated and tested exploitation payloads, and maintained separate operational contexts for individual targets. Documented intrusion activity included server-side request forgery exploitation, harvesting SSH keys and cloud credentials, mapping internal services and access boundaries, and moving laterally through cloud environments. Following compromise, the agents queried databases and other systems, extracted information, classified collected material by intelligence value, and generated operational documentation. Backdoor user accounts provided persistent access. Claude Code was estimated to perform 80–90% of tactical work, while human operators retained strategic oversight and approved consequential actions such as exploitation, credential use, and final data selection. Model inaccuracies, including fabricated credentials and overstated findings, required human validation. The campaign's distinguishing feature was autonomous orchestration and parallel execution of established intrusion techniques rather than novel attack methods.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chinese state-sponsored activity cluster presented as a central example of AI-orchestrated espionage. According to the content, it used Claude to perform 80–90% of an operation autonomously, with humans intervening at four to six decision points per campaign. The AI also extracted, organized, and triaged stolen data.
AI-enabled multi-agent intrusion run largely autonomously across roughly 30 targets.
Conducting AI-enabled autonomous intrusion activity, including reconnaissance and lateral movement across more than 30 targets at machine speed.
Chinese-linked espionage campaign in which Claude Code reportedly handled 80 to 90 percent of tactical work, including reconnaissance, exploitation, credential harvesting, and lateral movement, across about 30 target organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.