Showing posts with label espionage. Show all posts
Showing posts with label espionage. Show all posts

Friday, September 11, 2026

Anthropic details distillation attack campaigns from China (Alibaba, Moonshot AI, and DeepSeek)

Bad news! Serious stuff! The Communist Party of China is well known for its intellectual property theft and espionnage of the West. Competing by illegal means! Very troubling!

What seems to be particularly troubling is that these Chinese companies are apparently sharing the illegal means facilitating these distillation and other attacks.

"A new report released Thursday by Anthropic alleged persistent distillation attacks by China-based AI companies, which have escalated in recent months as competition in the space has intensified.

“Over the last several months, unauthorized labs have developed increasingly sophisticated methods to circumvent our defenses and harvest the capabilities of US frontier models,” the report reads. “The campaigns we identified targeted some of Claude’s most valuable capabilities, including agentic capabilities and tool use, coding and data analysis, and logical reasoning.”

Anthropic previously spoke out about distillation attacks in February, even calling out specific labs.
OpenAI has reported similar activity, which it attributed to DeepSeek specifically. But the campaigns detailed in Anthropic’s new report are both larger and more aggressive. All told, the company observed nearly 200 million exchanges linked to distillation attacks, attributed to five separate campaigns. ..."

"... We define illicit distillation as an industrial-scale, covert campaign to extract a model’s capabilities and replicate them in another model without authorization. Illicit distillation is typically enabled by fraud: sophisticated networks of fake accounts created with stolen credit cards, login credentials, and API keys. ...

Beyond distillation, Alibaba also used Claude to advance its AI R&D efforts. Alibaba used Claude to help develop its internal infrastructure for model development. Claude was used to help develop Alibaba’s reinforcement learning (RL) environments and advance model architecture research.

Alibaba accessed Claude through two main pools of fraudulent accounts. The first consisted of nearly 5,000 fraudulent accounts leveraging residential proxies, disposable emails, and virtual-card payments to obfuscate their access.
When we banned this pool of accounts, Alibaba quickly shifted its traffic through the second pool.
Some of these accounts were found to have been funneling requests from DeepSeek and Xiaomi, demonstrating that the same proxy service networks are often used by a variety of organizations. ..."

Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek | TechCrunch



The graphic below illustrates the life cycle of an illicit distillation campaign.


Friday, September 04, 2026

US military disabled ad tracking on troops' devices following reports of targeted attacks by enemies

Serious stuff! Essentially any and each personal wearable computer device worn by a soldier anywhere in the world could be exploited/spied on by adversaries.

Notice this article is only about government issued devices.

Notice the two articles do not report which country is behind this neither does the letter by the US Senator (e.g. China, Russia, North Korea). Why this secrecy?

"The U.S. Department of Defense has disabled advertising tracking on troops’ phones and computers as part of an effort to protect them from threats that target their locations, according to a letter shared with Sen. Ron Wyden.

Per a letter shared with the senior Democrat on the Senate Intelligence Committee, Wyden said that the U.S. Army, Air Force, Navy, and Marine Corps, and Special Operations Command have all disabled advertising tracking across their government-issued devices. ..."

US military disabled ad tracking on troops' devices following reports of targeted attacks | TechCrunch

Thursday, August 27, 2026

The FBI disrupted a massive China-linked hacking network that broke into government systems.

Good news! What took so long!

"The operation targeted networks at the Federal Reserve, the Energy Department, NASA and the Senate, the FBI said in a court filing. Dubbed QTFY by U.S. officials, the campaign has been run since 2018 by a private company based in China that sells access to hacked networks and stolen information to China’s foreign and military intelligence services, the FBI said."

"U.S. officials say they have disrupted a China-linked hacking operation that broke into U.S. government networks and critical infrastructure, while hiding its tracks on a global network of hacked devices, cloud-computing infrastructure and even clandestine networks.

The goal was to blend in with legitimate networking traffic, making the hacking activity hard to trace. The operation targeted networks at the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy and the Senate, the Federal Bureau of Investigation said in a court filing. ..."

The Wall Street Journal What's news

FBI Shuts Down Sprawling China-Linked Hacking Network (behind paywall) "Spy operation targeted NASA, the Federal Reserve and other areas, hiding within normal internet traffic to avoid detection"

Friday, August 07, 2026

China-linked LightSpy spyware caught targeting victims in 13 countries, including across Europe and the US

Bad news!

So in China state-based spyware platform can turn into a commercial spyware platform? Is the Communist Party of China running a rogue state?

"Researchers linked the latest malicious activity to a Chinese company, after one of the spyware's operators placed an order with KFC using their real name and office address." (Source)

"Security researchers say they have evidence that a Chinese-linked spyware has expanded from mainland China to now target victims in over a dozen countries, including across Europe and the United States. The previously identified spyware also has new functionality capable of stealing troves of data and remotely bricking devices.

The researchers at cybersecurity firm Arctic Wolf said that the LightSpy spyware, first discovered in 2018 and previously linked to Chinese state-backed hackers, has since evolved into a commercial spyware platform operated by a single threat actor who caters to governments, enterprises, and militaries. ...

According to the company, LightSpy operates a network of at least 117 servers in several countries around the world. ..."

China-linked LightSpy spyware caught targeting victims in 13 countries, including the US | TechCrunch


What is an arctic wolf doing? (Source)




Tuesday, July 21, 2026

Taiwan alleges ex-TSMC staff stole chip secrets to sell to China

Bad news! Sounds familiar!

"Taiwanese prosecutors on Monday indicted a former TSMC deputy manager for allegedly stealing trade secrets involving national core technologies with the intent of using them to advance China's chip ambitions. ..."

Taiwan alleges ex-TSMC staff stole chip secrets to sell to China - Nikkei Asia "Indictment is first under National Security Act involving attempt to advance Chinese chip ambitions"

Monday, July 13, 2026

Former Iranian president Ahmadinejad (age 69) under arrest by IRGC for work with Mossad

Are the mullahs of Iran panicking? Who will be next?

IRGC = Islamic Revolutionary Guard Corps

Former Iranian president Ahmadinejad under arrest by IRGC for work with Mossad | The Jerusalem Post "For years, Israel conducted a covert operation aimed at recruiting former Iranian president Ahmadinejad as an intelligence asset and, at a later stage, even planned to install him as Iran’s leader."


Mahmoud Ahmadinejad (Source)




Saturday, April 18, 2026

FBI says these apps downloaded from smartphone app storefronts let China suck up your personal data

I think this is plausible! These storefronts surely are valuable targets for espionnage.

Unlike the article below, I don't think these apps are limited to typical, popular Chinese apps like Temu, TikTok, Tencent etc. Any popular App could be affected.

"Centralized smartphone app storefronts, like Apple’s App Store for iPhone and the Google Play Store for Android, make apps feel like they all come from the same safe place online, but the developers behind these apps are spread out all over the world. This month, the FBI brought attention to international developers, warning that installing apps built by foreign nations could pose a major threat to user privacy and security. ..."

FBI says these apps let China suck up your personal data (behind paywall)

Wednesday, April 15, 2026

Iran acquired Chinese spy satellite to monitor US military bases

When communists aid fanatic, suicidal islamists and terrorists!

"Iran secretly acquired a Chinese spy satellite, giving the Islamic Republic a new capability to target US military bases across the Middle East during the recent war, the Financial Times reported on Wednesday.

The TEE-01B satellite, built and launched by the Chinese company Earth Eye Co, was acquired by the Islamic Revolutionary Guard Corps’ Aerospace Force in late 2024 after it was launched into space from China, the report said, citing leaked Iranian military documents. ...

Last week, CNN reported that US intelligence suggested China was preparing to deliver new air defense systems to Iran in the coming weeks, citing three sources familiar with recent intelligence assessments. ..."

Iran acquired Chinese spy satellite to monitor US military bases | The Jerusalem Post "A new report reveals Iran secretly acquired a Chinese spy satellite, giving it the ability to monitor US military bases in the Middle East during the recent war, including air and naval facilities."

Wednesday, March 25, 2026

Israeli teen indicted for working with Iranian operatives, charged with espionage & spraying pro Iran propaganda graffiti in public places

Bizarre! Do Iranian mullahs have respect for children? Not when it is about Israel

Child labor is cheap!

"State prosecutors filed an indictment in the Tel Aviv District Juvenile Court on Wednesday against a 14-year-old from central Israel who is accused of carrying out paid assignments for hostile actors while suspecting they were Iranian.

It is another case in a widening pattern of Iranian efforts to recruit Israelis online for intelligence-gathering and sabotage-related missions during the war, according to the authorities. ...

Last April, the teenager contacted a person in a Telegram group after seeing a message about work he was interested in, and the two agreed that he would perform tasks in exchange for payment in cryptocurrency transferred to a digital wallet, the prosecutors said, adding that he opened four digital wallets into which handlers transferred more than $1,170. ...

Among the tasks attributed to him were: spraying the graffiti slogan, “We are committed to the covenant,” in multiple areas of Tel Aviv and on vehicles; filming streets near Ichilov Hospital in Tel Aviv and neighborhoods in Ramat Gan; and recording a video of the Tel Aviv skyline while describing the location of the Kirya military headquarters.

Prosecutors said he was also asked to rent an apartment near the Kirya, after which he sent a picture of an apartment for rent and spoke with several landlords in the area.

According to the prosecutors, the teen was also instructed to spray pro-Iranian graffiti on Foreign Minister Gideon Sa’ar’s home and to prepare video documentation of the minister. The slogan was to read: “We will avenge Ruhollah’s children” – an apparent reference to Ruhollah Khomeini, the founder of Iran’s 1979 Islamic Revolution and the country’s first supreme leader. ..."

Teen indicted over alleged Iran-linked spying assignments | The Jerusalem Post "A 14-year-old Israeli has been indicted for working with Iranian operatives, carrying out sabotage and surveillance tasks in exchange for cryptocurrency."

Tuesday, February 24, 2026

Anthropic accused three Chinese AI companies of setting up more than 24,000 fraudulent accounts

This is a serious allegation!

"Anthropic accused three Chinese AI companies of setting up more than 24,000 fraudulent accounts with its Claude AI model to help their own systems catch up.
The U.S. AI startup said that DeepSeek, Moonshot AI and MiniMax prompted Claude more than 16 million times to siphon data and that the activity raised national-security concerns for the U.S. Earlier this month, OpenAI, an Anthropic rival, sent a memo to House lawmakers accusing DeepSeek of using the same tactic to mimic its products. Representatives from the trio of Chinese companies didn’t respond to requests for comment."

"Anthropic is accusing three Chinese AI companies of setting up more than 24,000 fake accounts with its Claude AI model to improve their own models.

The labs — DeepSeek, Moonshot AI, and MiniMax — allegedly generated more than 16 million exchanges with Claude through those accounts using a technique called “distillation.” Anthropic said the labs “targeted Claude’s most differentiated capabilities: agentic reasoning, tool use, and coding.” ..."

The Wall Street Journal What's news

Sunday, January 25, 2026

China’s top general is accused of giving nuclear secrets to the U.S. and accepting bribes for official acts

A spy for the US at this high a level! Or was this general purged?

"China’s senior-most general is accused of leaking information about the country’s nuclear-weapons program to the U.S. and accepting bribes for official acts, including the promotion of an officer to defense minister, said people familiar with a high-level briefing on the allegations. The briefing came just before China’s Ministry of National Defense made the bombshell announcement of an investigation into Gen. Zhang Youxia, once considered Chinese leader Xi Jinping’s most-trusted military ally."

The Wall Street Journal What's news


General Zhang Youxia


Friday, December 05, 2025

A Russian cosmonaut turned out to be a spy and was removed from SpaceX mission

Well Putin the Terrible himself was a KGB agent!

"A Russian cosmonaut was removed from SpaceX’s February mission after allegedly photographing classified SpaceX engines and documentation at company headquarters, violating U.S. national security laws."

Friday, December 5, 2025 - Join The Flyover



Russian cosmonaut Oleg Artemyev


Friday, November 28, 2025

US asks Lebanon to return undetonated GBU-39 bomb, fearing it could reach Russia, China - report

Always trouble with unexploded ordnance! This time of a different kind!

"The United States has asked Lebanon to return a GBU-39 small-diameter bomb launched by the Israel Air Force toward Beirut during the operation that killed Hezbollah military commander Ali Tabatabai earlier this week, after it failed to detonate, according to Lebanese media. ..."

US urges Lebanon to return undetonated GBU-39 | The Jerusalem Post "The GBU-39 is a glide bomb manufactured by Boeing. Once launched, it deploys wings and can glide up to 110 km, despite lacking its own engine."




Saturday, November 15, 2025

Five people plead guilty to helping North Koreans infiltrate US companies as 'remote IT workers'

What is this little fat man, i.e. dictator Kim Jong Un, up to? 😊

Does North Korea do anything positive to improve humanity?

Then there are the several thousand North Korean mercenaries fighting in the Ukraine for Putin the Terrible!

According to Google: "Kim Jong Un is approximately 5 feet 7 inches to 5 feet 8 inches tall. His weight has fluctuated, and reports from various times place him anywhere from 264 pounds (\(120\) kg) to over \(300\) pounds (\(140\) kg)."

According to Google: "While there is no exact number of starving North Koreans, recent reports estimate that over 10 million people are undernourished and face severe food insecurity. This is equivalent to more than 40% of the population."

When will the Korean peninsula be reunited? Germany was reunited in 1990!

"Five people have pleaded guilty to helping North Koreans defraud U.S. companies by posing as remote IT workers, the U.S. Department of Justice (DOJ) announced on Friday.

The five people are accused of working as “facilitators” who helped North Koreans get jobs by providing their own real identities, or false and stolen identities of more than a dozen U.S. nationals. The facilitators also hosted company-provided laptops in their homes across the U.S. to make it look like the North Korean workers lived locally, according to the DOJ press release.

These actions affected 136 U.S. companies and netted Kim Jong Un’s regime $2.2 million in revenue, said the DOJ. ..."

Five people plead guilty to helping North Koreans infiltrate US companies as 'remote IT workers' | TechCrunch

Justice Department Announces Nationwide Actions to Combat Illicit North Korean Government Revenue Generation "Four U.S. Nationals and Ukrainian Identity Broker Plead Guilty / Department Seeks Forfeiture of More Than $15M in Virtual Currency Stolen and Laundered by North Korean Hackers"


Kim Jong Un


Wednesday, October 15, 2025