AI-Driven Espionage and Android Malware Campaigns Reported
Reports say China-linked GTG-1002 used AI agents for most espionage work, alongside PromptSpy Android malware and other AI fraud tools.
One report says Anthropic disclosed that PRC-linked GTG-1002 used Claude Code as an autonomous operator, pairing the model with open-source penetration tools through Model Context Protocol servers. A second report describes the same China-linked campaign as using AI agents for 80-90% of operational tasks but does not name Claude Code or Anthropic. Both identify PromptSpy as Android malware using generative AI; the first calls it the first such malware and says it uses Google Gemini for device-specific reconnaissance and execution, while the second says it reads screen content and requests interaction instructions. Only the first cites Trellix on agents automating credential harvesting through lateral movement. Only the second names LunaLock, which uses AI to locate sensitive data for extortion, and describes deepfake calls and trusted payment approvals used for fraud and theft. The outlets agree AI is shifting toward autonomous intrusion and trust abuse, but they disagree on tooling, task share, and which malware to emphasize.
- One report says Anthropic disclosed PRC-linked GTG-1002 using Claude Code as an autonomous espionage operator with open-source penetration tools via Model Context Protocol servers.
- A second report calls GTG-1002 China-linked and says AI agents handled 80-90% of operational tasks, without naming Claude Code or Anthropic.
- Both reports identify PromptSpy as Android malware that uses generative AI; only the first calls it the first such malware and names Google Gemini.
- Sources differ on PromptSpy: device-specific reconnaissance and execution versus reading screen content and requesting interaction instructions.
- One report cites Trellix saying AI agents automate the kill chain from credential harvesting to lateral movement.
- The second report adds LunaLock, which uses AI to find sensitive data for extortion, plus deepfake calls and abused payment approvals tied to fraud and data theft.
Coverage timelineoldest first · each row is one article
- · 4d agoAI-Powered Threats Exploit Digital Trust Through Autonomous Breach Techniques
GBHackers· 70
A PRC-linked group used Claude Code as an autonomous operator for espionage, while researchers identified the first Android malware leveraging generative AI.
- · 3d agoAI-Driven Cyberattacks Enter New Phase With Autonomous Fraud and Digital Trust Abuse
Cyber Security News· 55
AI-driven cyberattacks are automating fraud and intrusions, with the GTG-1002 campaign using AI agents for most operational tasks.