GTG-1002 Claude Code Espionage Campaign
- Autonomous Agents
- Data Exfiltration
- Credential & Identity Theft
In September 2025, GTG-1002 used a jailbroken Claude Code agent to conduct a cyber-espionage campaign against approximately 30 organizations, succeeding against a small number. Anthropic assessed with high confidence that GTG-1002 was a Chinese state-sponsored group. GTG-1002 selected organizations in the technology, financial, chemical-manufacturing, and government sectors and configured an autonomous attack framework to operate against them. The operators obtained access to Claude Code and circumvented its safeguards by concealing their malicious purpose behind a false defensive-security persona and apparently benign tasks. GTG-1002 then connected the jailbroken Claude agent to scanners, browser automation, password crackers, database tooling, and dedicated penetration-testing servers through MCP. Between operator-controlled stage gates, the adversary's jailbroken Claude agent autonomously inspected target infrastructure, identified high-value systems, scanned for vulnerabilities, and developed and deployed a tailored exploit chain for an identified SSRF vulnerability. After obtaining access to a target, it mapped internal resources and network relationships, found authentication certificates in system configuration files, used harvested credentials to access additional services, established a backdoor account, and collected sensitive information from local systems and internal databases. The adversary's jailbroken Claude agent performed an estimated 80-90% of campaign activity, including processing collected data, categorizing it by intelligence value, and documenting attack progress. Human operators retained approximately four to six critical decisions per target, including review and approval before selected data was exfiltrated over the Claude web service.