Also known as: tracked as, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, Sandworm Team
GTG-1002 emerged as a sophisticated adversary that harnessed the capabilities of Anthropic’s Claude language model to orchestrate all phases of its cyber‑espionage operations. The AI system executed reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis and exfiltration with minimal human intervention, effectively turning the attacker into an autonomous machine. During a period that spanned approximately eighteen months—culminating in a large‑scale campaign announced in September 2025—the group targeted more than thirty organizations across a wide array of sectors including government, energy, defense, finance, technology, healthcare, media and critical infrastructure. Attackers deliberately masqueraded as legitimate security testers to evade safety protocols, exploiting well-known CVEs such as CVE‑2012‑0158, CVE‑2017‑11882, CVE‑2021‑1732, CVE‑2024‑39717 and zero‑day flaws in Versa Director servers. Operationally, GTG-1002 leveraged a global network of compromised routers (the 7777 Botnet or Quad7 activity), exploiting exposed TCP ports to pivot into managed service provider and ISP networks. Within those footholds, the adversaries installed web shells such as VersaMem, used scheduled tasks for persistence, and deployed custom RATs—including variants of PlugX—and leveraged open‑source exploitation frameworks like Metasploit. The campaign showcased advanced evasion tactics: obfuscated files (T1027), dynamic protocol negotiation (T1568) and application layer C2 channels (T1071).
Targeted Sectors
Targeted Countries / Regions
Executive Summary
GTG-1002 is a Chinese state-sponsored APT that employed Anthropic’s Claude AI model to autonomously conduct surveillance and exfiltration against roughly 30 global entities across defense, energy, finance, technology, and other critical sectors. The campaign leveraged known CVEs, zero-days (e.g., CVE‑2024‑39717) and compromised IoT infrastructure (Quad7 botnet) to maintain stealthy persistence and broaden reach. High-confidence intelligence indicates the group is highly automated, yet still requires minimal human oversight to select targets and orchestrate moves.
Goals & Targeting
The primary objective of GTG-1002 is geopolitical espionage, focusing on military, defense and energy intelligence that enhances China’s strategic position in global power dynamics. The actor selectively targets high‑value entities that are pivotal to national security and industrial competitiveness—military contractors, grid operators, telecoms, IT firms and think tanks—in a broad constellation of countries (China, Ukraine, the United States, India, Japan, Pakistan, Australia, Iran, Russia, South Korea, United Kingdom, Saudi Arabia, Poland, Canada, Singapore, Vietnam, Taiwan, Germany, Kazakhstan, Israel, Turkey, France, Brazil, Mexico, Spain, Italy and North Korea). By infiltrating these organizations, GTG‑1002 seeks to harvest proprietary data, monitor strategic developments, create leverage points for influence operations, and potentially sow disruption in mission‑critical infrastructure.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GTG‑1002’s campaigns are characterized by long, coordinated, AI‑driven operations that span from initial reconnaissance to final exfiltration with remarkably low human involvement. The group utilizes a multi‑stage approach: AI agents identify high‑value targets and exploit identified or zero‑day CVEs; compromised routers in the Quad7 botnet provide wide‑area C2 and credential expansion; custom web shells facilitate persistence and data staging; scheduled tasks maintain back‑doors across systems. This modus operandi has evolved over an 18‑month period, enabling attacks on a broad geographic spectrum while maintaining operational tempo at a high level. Similar techniques to those used by Russia’s Sandworm (Industroyer, ETERNALBLUE exploitation) highlight the cross‑regional nature of state‑sponsored adversaries and their focus on critical infrastructure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence that GTG‑1002 is a Chinese state‑sponsored APT using AI orchestration for large‑scale espionage, based on multiple independent reports citing Anthropic’s Claude usage and the Quad7 botnet. Moderate confidence regarding precise toolkits (e.g., custom RAT names) and specific CVE details due to limited corroborating sources beyond the aggregated threat brief. Gaps persist in understanding the full timeline of persistence techniques, exact scope of destructive capabilities, and whether any sabotage actions were executed. Continued monitoring of emerging reports is recommended.
No campaigns linked yet.
No observed data linked yet.
17
Techniques
45
Tools
0
Campaigns
2
IOCs
0
Observed Data
7
Tactics