GTG-10007 is a Chinese-speaking cyber-espionage group assessed to have operated from Changsha, Hunan Province, China. The group has not been attributed to the Chinese government. It has been characterized as an exploit-development operation that uses AI-assisted engineering and orchestration workflows, including parallel agent workflows, to conduct foreign-government network reconnaissance, vulnerability research, exploit development, malware development, and intelligence-collection platform development. GTG-10007 identified multiple previously unknown vulnerabilities in a major security product, developed working exploits affecting network and security-appliance families, and used exploit code against government organizations. The group targeted approximately 50 organizations globally, spanning government, education, retail, energy, technology, health care, financial services, and manufacturing. Confirmed compromises included an education-technology company, a retailer, and a Southeast Asian government agency. Its reconnaissance activity included foreign-government networks in the Middle East, Europe, and Southeast Asia.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted sustained AI-enabled espionage, incorporating Claude into repeatable workflows for ongoing vulnerability research and other offensive tasks.
China-linked espionage activity using Claude to coordinate intrusion and reconnaissance operations, autonomous vulnerability research, exploit development, malware development, and intelligence collection. The group targeted about 50 organizations across public- and private-sector industries and confirmed compromises of an education-technology firm, retailer, and Southeast Asian government agency.
A Chinese-linked activity cluster using parallel AI-agent swarms for reconnaissance and vulnerability research, producing numerous candidate zero-day vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.