Listen to the article
A blacklisted Chinese technology company has claimed it has developed a “cyber nuclear weapon” capable of finding and exploiting software vulnerabilities.
The disclosure has raised fresh concerns over China’s expanding offensive cyber capabilities.
Qihoo 360 says it has built an artificial intelligence system approaching the capabilities of Anthropic’s Claude Mythos, the powerful US model that has alarmed Western governments because of its ability to uncover previously unknown flaws in computer systems.
The claims come amid warnings from Britain and its allies that China is already using state-linked hackers and commercial technology companies to penetrate foreign governments, telecommunications networks and critical infrastructure.
In April, GCHQ’s National Cyber Security Centre warned that China-linked groups were increasingly using “covert networks” of compromised routers and smart devices to disguise attacks. The NCSC said the Chinese state-sponsored group Volt Typhoon had used such networks to pre-position offensive cyber capabilities inside critical infrastructure, while Flax Typhoon had used them for espionage.
The NCSC says China-linked campaigns have targeted governments, telecoms, transport and military infrastructure around the world, including in the UK.
Qihoo has been on a US Commerce Department blacklist since 2020. In June, the Pentagon designated 360 Security Technology, its listed parent company, as a “Chinese military company”, saying it was affiliated with China’s Ministry of Industry and Information Technology and Ministry of State Security and was a “military civil fusion contributor” to Beijing’s defence industrial base.
Qihoo has previously rejected US allegations against the company.
Zhou Hongyi, Qihoo’s founder and chairman, told a cybersecurity conference in Beijing that his company had developed a system called Tulongfeng, which he described as China’s answer to Mythos.
Mr Zhou called Mythos the “equivalent to a cyber nuclear weapon in the AI era” and a “strategic asset” for the United States. He said Tulongfeng possessed similar vulnerability-discovery capabilities and could, when combined with other Qihoo technology, provide China with a comparable cyber weapon.
His claims have not been independently verified.
Mythos, unveiled by Anthropic in April, caused alarm because it demonstrated an ability to discover previously unknown software weaknesses and develop methods to exploit them. Access was initially restricted to selected companies and government agencies because of fears the technology could be misused.
Washington later imposed temporary export restrictions on Anthropic’s most advanced models, including Mythos, preventing foreign nationals from using them. Anthropic briefly disabled access before the restrictions were eased after safeguards were agreed.
Mr Zhou compared the development of AI cyber systems to the nuclear arms race and argued that China needed its own deterrent.
“Previously, nuclear weapons constituted strategic deterrence. In the future, vulnerability discovery capabilities may become the new strategic deterrent,” he said.
“China’s cybersecurity industry must possess its own Mythos. This game-changing weapon of mass destruction cannot remain solely in the hands of others.”
He claimed Tulongfeng had discovered more than 3,000 software vulnerabilities, including several classed as high risk by Chinese authorities.
The warning is significant because China has already been accused by Western governments of conducting cyber operations on an industrial scale.
The UK and its allies have linked Chinese groups to the Salt Typhoon campaign, which targeted telecommunications providers, governments and critical networks. British authorities have also accused China-linked hackers of targeting the Electoral Commission and carrying out reconnaissance against MPs.
The threat is expected to grow as AI makes sophisticated hacking faster and cheaper.
In June, the cyber chiefs of the Five Eyes intelligence alliance — Britain, the US, Canada, Australia and New Zealand — warned that frontier AI models were on the verge of transforming both attack and defence.
“The timeline is not years, it is months,” they said, warning that AI would increase the “speed, scale and sophistication” of cyber threats.
Alan Woodward, a cybersecurity expert at the University of Surrey, said China would inevitably develop comparable systems.
“It might not be as good as Mythos, but what it does show is these things are going to come out anyway,” he said.
