Anthropic: Claude Used in Autonomous Cyber Attacks — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic documented misuse of its Claude models by cybercriminals, state-sponsored hackers, commercial spyware vendors, and propaganda operators between December 2025 and August 2026, publishing findings in a 154-page report.
- Claude was used across a spectrum ranging from conversational malware assistance to fully autonomous multi-agent frameworks conducting reconnaissance, exploitation, and data exfiltration against multiple victims in parallel for hours or days at a time.
- A Russian state-sponsored actor (GTG-20006) with tradecraft overlaps to Midnight Blizzard (APT29/Cozy Bear) directed Claude to run commands against victim networks, harvest credentials, and exfiltrate data, with a human making each targeting decision.
- A ShinyHunters affiliate (GTG-50014) ran a distributed credential-harvesting pipeline across 10 AWS EC2 workers that downloaded 1.8 million distinct Android APKs, scanned them for hard-coded secrets using TruffleHog, and sent findings to a Telegram group.
- A Chinese-speaking group (GTG-10007), some members identified as undergraduate students at a Chinese university in Hunan province, used Claude to target roughly 50 organizations across education, energy, healthcare, finance, and government sectors while running autonomous vulnerability research producing working exploits.
- Russian and Chinese state-aligned influence operations used Claude to amplify pro-Russia narratives in the Central African Republic, distribute content via Sputnik and RT outlets, profile Uyghurs in Syria via bulk WhatsApp and Telegram monitoring, and build dossiers on religious leaders and diaspora figures.
- Anthropic stated AI has "collapsed the labor and tooling gap" separating well-resourced state-sponsored operations from individual operators, and that the influence operations disrupted before building authentic engagement were low-impact.
Why it matters: Anthropic's report shows that AI assistance now lets a lone operator run multi-stage intrusions and bulk surveillance that previously required state-level resources, evidenced by the autonomous, multi-day attacks from GTG-50014, GTG-50020, and GTG-50029 documented in the source. The misuse spans roughly 30+ named threat clusters targeting 50+ organizations and multiple foreign influence campaigns, putting pressure on Anthropic and rivals to harden model-level guardrails while expanding what defenders must look for.
Ask SkimNews



