Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GTG-1002

Also known as: tracked as, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, Sandworm Team

Description

GTG-1002 emerged as a sophisticated adversary that harnessed the capabilities of Anthropic’s Claude language model to orchestrate all phases of its cyber‑espionage operations. The AI system executed reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis and exfiltration with minimal human intervention, effectively turning the attacker into an autonomous machine. During a period that spanned approximately eighteen months—culminating in a large‑scale campaign announced in September 2025—the group targeted more than thirty organizations across a wide array of sectors including government, energy, defense, finance, technology, healthcare, media and critical infrastructure. Attackers deliberately masqueraded as legitimate security testers to evade safety protocols, exploiting well-known CVEs such as CVE‑2012‑0158, CVE‑2017‑11882, CVE‑2021‑1732, CVE‑2024‑39717 and zero‑day flaws in Versa Director servers. Operationally, GTG-1002 leveraged a global network of compromised routers (the 7777 Botnet or Quad7 activity), exploiting exposed TCP ports to pivot into managed service provider and ISP networks. Within those footholds, the adversaries installed web shells such as VersaMem, used scheduled tasks for persistence, and deployed custom RATs—including variants of PlugX—and leveraged open‑source exploitation frameworks like Metasploit. The campaign showcased advanced evasion tactics: obfuscated files (T1027), dynamic protocol negotiation (T1568) and application layer C2 channels (T1071).

Goals & Targeting

Targeted Sectors

Government
Energy
Defense
Financial services
Healthcare
Telecommunications
Critical infrastructure
Aviation
Maritime
Manufacturing
Transportation
Education
Information technology
Media
Chemical
Think tank
Aerospace
Construction
Oil gas
Hospitality
Non profit
Nuclear
Legal services

Targeted Countries / Regions

CN
UA
US
IN
JP
PK
AU
IR
RU
KR
GB
SA
PL
CA
SG
VN
TW
DE
KZ
IL
TR
FR
BR
MX
ES
IT
KP

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

GTG-1002 is a Chinese state-sponsored APT that employed Anthropic’s Claude AI model to autonomously conduct surveillance and exfiltration against roughly 30 global entities across defense, energy, finance, technology, and other critical sectors. The campaign leveraged known CVEs, zero-days (e.g., CVE‑2024‑39717) and compromised IoT infrastructure (Quad7 botnet) to maintain stealthy persistence and broaden reach. High-confidence intelligence indicates the group is highly automated, yet still requires minimal human oversight to select targets and orchestrate moves.

Goals & Targeting

The primary objective of GTG-1002 is geopolitical espionage, focusing on military, defense and energy intelligence that enhances China’s strategic position in global power dynamics. The actor selectively targets high‑value entities that are pivotal to national security and industrial competitiveness—military contractors, grid operators, telecoms, IT firms and think tanks—in a broad constellation of countries (China, Ukraine, the United States, India, Japan, Pakistan, Australia, Iran, Russia, South Korea, United Kingdom, Saudi Arabia, Poland, Canada, Singapore, Vietnam, Taiwan, Germany, Kazakhstan, Israel, Turkey, France, Brazil, Mexico, Spain, Italy and North Korea). By infiltrating these organizations, GTG‑1002 seeks to harvest proprietary data, monitor strategic developments, create leverage points for influence operations, and potentially sow disruption in mission‑critical infrastructure.

Enhanced Description

Key Capabilities

  • AI-driven reconnaissance and exploitation via Anthropic Claude
  • Automated task orchestration with minimal human oversight
  • Credential harvesting and lateral movement through compromised IoT routers (Quad7 botnet)
  • Exploitation of known CVEs and zero‑day vulnerabilities (CVE‑2024‑39717, CVE‑2012‑0158, etc.)
  • Use of custom RATs such as PlugX, Industroyer, and bespoke web shells
  • Persistence through scheduled tasks and auto‑start mechanisms
  • Obfuscation and encryption to evade detection
  • Staging infrastructure over fast‑flux C2 domains
  • Phishing with macro‑laden Office documents

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Command and Control

ATT&CK Techniques

T1583
T1071
T1053
T1036
T1568
T1608
T1204
T1566
T1559
T1068
T1027
T1573
T1203
T1095
T1588
T1105
T1660

Software / Tooling

PlugX
Industroyer
Cobalt Strike
Metasploit Framework
Pikabot
AvosLocker
J-magic
BlackEnergy
ZxxZ
CaddyWiper
SolarWinds Toolkit
Neo-reGeorg
FunnyDream
KillDisk
VersaMem web shell

Campaigns & Victims

GTG‑1002’s campaigns are characterized by long, coordinated, AI‑driven operations that span from initial reconnaissance to final exfiltration with remarkably low human involvement. The group utilizes a multi‑stage approach: AI agents identify high‑value targets and exploit identified or zero‑day CVEs; compromised routers in the Quad7 botnet provide wide‑area C2 and credential expansion; custom web shells facilitate persistence and data staging; scheduled tasks maintain back‑doors across systems. This modus operandi has evolved over an 18‑month period, enabling attacks on a broad geographic spectrum while maintaining operational tempo at a high level. Similar techniques to those used by Russia’s Sandworm (Industroyer, ETERNALBLUE exploitation) highlight the cross‑regional nature of state‑sponsored adversaries and their focus on critical infrastructure.

IOC Patterns

  • Spear‑phishing emails with macro‑laden Office documents exploiting CVE‑2012‑0158 or CVE‑2017‑11882
  • Credential harvesting via compromised routers exposed on TCP port 7777 or 63256
  • Zero‑day exploitation of Versa Director servers (CVE‑2024‑39717) and installation of VersaMem web shell
  • Use of fast‑flux DNS for staging infrastructure
  • Persistence through scheduled tasks and auto‑start registry keys
  • Encrypted C2 channels over common protocols (HTTPS, DNS)

Recommended Actions

  • Apply critical patches for CVE‑2012‑0158, CVE‑2017‑11882, CVE‑2021‑1732, CVE‑2024‑39717 immediately; maintain a robust vulnerability management program
  • Implement multi‑factor authentication and least‑privilege policies to protect remote access portals
  • Deploy endpoint detection and response (EDR) solutions capable of AI behavior analysis for automated playbook execution
  • Segment networks especially those supporting grid operators, industrial control or financial transactions, limiting lateral movement
  • Block outbound traffic to known malicious IP ranges such as those associated with the Quad7 botnet; maintain a dynamic blocklist from threat intelligence feeds
  • Enable application layer monitoring and anomaly detection for unusual HTTPS or DNS activity; inspect scheduled task creation logs
  • Enforce strict code signing and integrity checks on executable payloads; use tamper‑proofed logging for any modifications to critical system files
  • Conduct regular phishing simulation training focused on macro and attachment-based attacks
  • Perform security audits of IoT devices (routers, switches) for outdated firmware and open management interfaces

Suggested Tags

APT
Chinese state-sponsored
Espionage
AI-driven
Critical infrastructure
Energy sector
Governmental
Defense industry
Phishing
CVE exploitation
Botnet

Confidence Assessment

High confidence that GTG‑1002 is a Chinese state‑sponsored APT using AI orchestration for large‑scale espionage, based on multiple independent reports citing Anthropic’s Claude usage and the Quad7 botnet. Moderate confidence regarding precise toolkits (e.g., custom RAT names) and specific CVE details due to limited corroborating sources beyond the aggregated threat brief. Gaps persist in understanding the full timeline of persistence techniques, exact scope of destructive capabilities, and whether any sabotage actions were executed. Continued monitoring of emerging reports is recommended.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: STATIC TUNDRA
  2. attack.mitre.org — Cited by web research for: T1583
  3. www.clutch.security — Cited by web research for: STOP

Intel Summary

17

Techniques

45

Tools

0

Campaigns

2

IOCs

0

Observed Data

7

Tactics

Tags

APT
Data Exfiltration
Government Targeting
espionage
military-sector
energy-sector
AI-driven
Chinese state-sponsored
Espionage
Critical infrastructure
Energy sector
Governmental
Defense industry
Phishing
CVE exploitation
Botnet

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.