LLMs in Cyberespionage and Bank Phishing
Hunt.io found LLM-assisted espionage against governments and finance. In Mexico, a phishing network hit banks with more than 100 domains.
A Hunt.io report describes a language model-assisted cyberespionage operation targeting governments and financial entities, while another technical analysis details a modular phishing campaign against at least 12 Mexican financial institutions.
A Hunt.io report describes a language model-assisted cyberespionage operation targeting governments and financial entities. The campaign was framed as an advanced persistent cyberattack, with generative AI embedded across the offensive decision-making cycle.
Tactics Using Claude Code and DeepSeek
According to the analysis, Claude Code was used to automate offensive tasks, while DeepSeek-v4-pro handled tactical reasoning. The pairing of both models, according to the source cited by Moncloa.com, was part of the attacker's decision-making process.
The technical attribution of the operation points to a Chinese actor, although Hunt.io describes it with moderate confidence rather than as an absolute certainty. That distinction matters for reading the case without drawing conclusions the material does not support.
Modular Phishing Against Mexican Banks
In parallel, a technical analysis published by Ministang.com identified a sophisticated modular phishing infrastructure that has targeted at least 12 Mexican financial institutions over three years. The operation uses more than 100 associated domains and multiple phishing pages per domain.
The campaign relies on GitHub Pages to host fake sites and the SheetBest API to exfiltrate credentials, removing the need for dedicated backend infrastructure, according to the analysis. Operators also use obfuscated JavaScript, random paths, and dynamic brand-selection panels to impersonate legitimate banking portals and make detection harder.
Data collection happens through multi-step forms that mimic real banking authentication flows. Credentials are exfiltrated in real time to Google spreadsheets controlled by the attackers.
Targets and Hardening
The focus on governments and finance fits the typical target set described for APT29, a group that prioritizes ministries, diplomatic organizations, technology companies, research institutions, public policy organizations, cloud environments, identity infrastructure, and software supply chains, with an emphasis on sustained access rather than immediate disruption.
Against this kind of threat, Shieldworkz recommends reviewing and revoking inactive remote credentials, verifying IT/OT segmentation, suspending nonessential remote access, and rotating credentials as part of immediate hardening during geopolitical escalations. The same guidance suggests coordinating with sector ISACs such as E-ISAC for energy and WaterISAC, consuming emergency directives from CISA, and reviewing compliance with regulatory frameworks such as NERC CIP to reduce risk from APT groups targeting critical infrastructure.
Sources
- Security articles – infraestructura de phishing modular contra instituciones financieras mexicanasministang.com· Ministang.com
- Securing critical infrastructure from APT Groups during geopolitical eventsshieldworkz.com· Shieldworkz
- Análisis general de APT29 y sus objetivos típicoskrypt3ia.wordpress.com· Krypt3ia (blog)
- Claude Code Used in AI-Run Espionage on 30 Targets (2025)vibeoops.com· VibeOops
- Ciberespionaje chino LLM: Claude Code y DeepSeek atacan gobiernos y finanzasmoncloa.com· Moncloa.com
- LLM-Powered APT Campaigns: How China-Linked Operators Weaponized Claude Code and DeepSeek in a Government-Targeted Intrusionundercodetesting.com· UndercodeTesting



