Anthropic Threat Intelligence · 10 September 2026

The facts that
should not exist yet.

From Anthropic’s 154-page report on eight months of disrupted Claude misuse. These are not typical jailbreaks. They are the cases where AI stopped being a chatbot and started acting like staff, an engineering team, or an entire intelligence desk.

Window Dec 2025 – Aug 2026 Models Haiku · Sonnet · Opus Source Detecting and countering misuse of AI
3 hrscredential → full cloud admin
1.8MAPKs scraped for secrets
2.36Mromance-scam messages / 2 weeks
151MAlibaba distillation exchanges

Cyber operations

From assistant to orchestrator

01
GTG-20006 · Midnight Blizzard nexus

Malware that rebuilds itself when antivirus notices it.

A Russian-speaking operator consistent with Midnight Blizzard ran AI agents that watched whether implants were flagged. If a security product caught them, the agents autonomously modified, rebuilt, and restaged the toolkit until it was clean — then pushed it from disposable servers. Anthropic’s phrase for the effect: AI inverted the cost back onto defenders. A new signature used to buy time. Now the loop can close faster than the patch.

PowerChrome · WUEngine · Shadow C2 · GiftDrop · DarkSword

02
Same actor · hotel supply chain

They hijacked hotel guest Wi‑Fi to hunt Ukrainian officials.

Compromised three hospitality vendors that run hotel Wi‑Fi. Changed DNS so guest traffic flowed to attacker servers. Then staged ClickFix lures that dropped Windows, Android, and iOS malware. Combined stolen hotel guest lists with device data to focus on Ukrainian government staff and drone manufacturers. Microsoft later named the method CaptiveCrunch.

03
North Africa intrusion

300,000 national IDs. Half a million companies. One VPN appliance.

Same Russian cluster stole VPN credentials from a North African government technology authority, took over the central account server, and walked out with the full credential database: 300k+ national identity records and the commercial registry of more than 500,000 companies.

04
GTG-50014 · ShinyHunters

1.8 million Android apps, decompiled, hunted for secrets.

A French-speaking affiliate ran 10 AWS workers that mass-downloaded 1.8 million distinct APKs, decompiled them, and scanned for hardcoded keys with TruffleHog. Hits streamed live into Telegram groups with 100+ secret types. Parallel pipeline harvested GitHub tokens. That was just the front door.

05
Smash-and-grab tempo

One stolen token to full cloud control in about three hours.

Another breach went from first access to bulk theft in hours. After a SaaS compromise they dumped 2,100+ Azure AD token sets across 40 corporate tenants in ~34 hours. AI agents did nearly all of the work. Operators called it “vibe hacking”: give the model a goal, let it write and run the scripts.

06
Living off the AI land

They stole the victim’s Claude keys — then attacked the next company on the victim’s bill.

ShinyHunters affiliates treated AI credentials as loot, compute, and cover. Stolen Anthropic API keys from customer environments funded secondary attacks for weeks: a French retailer, a Web3 identity platform, a nonprofit. Anthropic’s own systems were not compromised. The attacker’s compute just quietly became someone else’s invoice. One energy-company claim in the same cluster: they said they could remotely change the charging current of home EV chargers.

07
GTG-10007 · Changsha students

Undergraduates ran an overnight zero-day foundry.

Chinese-speaking operators, two of them Hunan undergrads (one interviewing at QiAnXin for an offensive role), used Claude as the engineering layer of a standing exploit program. One appliance-firmware loop produced more than a dozen possible zero-days in a single month. Agent swarms kept campaign memory so work resumed mid-intrusion.

08
GTG-50020

Prompt-injected an AI vendor’s eval sandbox. Walked out with production keys.

A Russian actor who previously extorted hotel/fintech victims for $1.5–2.5M injected malicious instructions into an AI vendor’s automated evaluation sandbox. The sandbox handed over production API keys from multiple providers. Then the actor switched their own attack traffic onto the stolen keys and hit ~30 AI companies in four days. Goal: a pre-release Claude model. They never got it.

Influence operations

Nine campaigns · six continents

09
GTG-04001 · CAR / Wagner lineage

Claude wrote the HR policy for a propaganda radio station.

A Russian-speaking operator in Bangui used Claude as the production desk for Radio Lengo Songo (98.9 FM), a station created and funded by Wagner. The model generated employment contracts mandating loyalty to the CAR president “and Russia and its contingent,” scoring rubrics, and a three-strike firing process. Staff articles were scored against those criteria. Claude recommended who to keep and who to fire. When the model flagged the political weighting, the operator relabeled it in neutral language and kept the system.

10
Accountability theater

Ghost-written testimony was delivered in a live UN Human Rights Council session.

Influence cases also included cloning a real activist’s account to chat with contacts inside Iran, forging government documents, impersonating a state spokesperson and a human-rights org, and building counter-dossiers on UN Special Rapporteurs. Most campaigns still failed to find a real audience — except when state media (FM, shortwave, satellite TV) was the pipe.

Surveillance

AI as the missing engineering staff

11
GTG-14010 · PRC-aligned

An operator who did not speak Arabic ran a live recruitment op against Uyghurs in Syria.

Claude drafted outreach in Syrian dialect, translated replies in real time, role-played as an “expert” to QC the deception (dialect, military terms, psychology), and formatted the packet for a suspected case-officer handoff. Targets were profiled from 100+ WhatsApp groups for financial stress, family still in Xinjiang, and ideological disillusionment — leverage that only works with domestic PRC security.

12
Religious affairs desk

A multi-team intel shop collapsed into one office producing thousands of dossiers a month.

A PRC religious-affairs collection unit that once needed many analyst teams now ran on a single operator plus Claude. Daily “clue reports” on Catholic cardinals across Asia, Taiwanese Presbyterian leadership, Tibetan civil society, and Falun Gong — each dossier listing scandals and 抓手 (exploitable “grab handles”).

13
Mali

One consultant. Every mobile operator in the country.

A single consultant working for Malian national-security authorities used Claude not to read intercepts, but to engineer the mass-interception platform itself — software designed to cover all of the country’s mobile operators and generate target dossiers.

Conventional weapons

Software teams replaced by Claude Code instances

14
GTG-87001 · northern Yemen

They test-fired a guided rocket — then asked Claude why it failed.

A Yemen-based cell ran three programs: a phone-class flight-computer guided rocket with terminal homing; a multi-stage ballistic missile with a stated range above 2,000 km; and an “R2000” family that included a hypersonic-glide variant. Multiple Claude instances were assigned roles like a tiny engineering org (write / research / review). They hid intent across sessions. A live field test happened. It appears to have failed. Within hours they were back in Claude doing failure analysis on the telemetry.

15
GTG-27005 · “Serafim”

An onboard model that could pick a “person” and tell the drone to detonate.

Russia-based freelancers used Claude Code to build a full-stack FPV kamikaze swarm: shared swarm memory, fault-tolerant coordination, terminal camera guidance, acoustic detection, and an onboard small language model for attack / observe / RTB. Designed for lethal engagement without a human in the loop. Vision classifier trained on scraped Ukrainian combat footage. Demo strike coordinate: Donetsk Oblast. Firmware was flashed onto real boards.

16
GTG-17002 · EW / SEAD

Mid-project, the default war game became 12 targets in Taiwan.

A China-based actor iterated 12 versions of a 16-module electronic-warfare suite that ranked Patriot and THAAD-class envelopes, SAM sites, and command posts. Then the simulation’s default scenario flipped to Taiwan: a command bunker, early-warning radar, Patriot and Tien Kung batteries, major air bases, and a regional combatant-command HQ. Linked in assessment to PLA Academy of Military Sciences.

Biological misuse

First time an AI lab has published real-world dual-use cases from its own logs

17
Case 3

Opus 5 drafted a complete orthopoxvirus grant in about an hour.

A reseller relay serving a dozen customers produced an end-to-end application for live-orthopoxvirus work at a state-associated high-containment lab: hypothesis, design, dosing, stats, contingencies. Orthopoxviruses include variola (smallpox) and mpox. Framed as attenuation research — which is also how you learn to keep or transfer immune-evasion genes. Classifiers did not trip because the stated goal looked like loss of virulence.

18
Case 1 · the relay

When Claude refused the chikungunya work, the platform auto-routed it to a looser model.

A gray-market LLM platform tunneled unsupported-region virologists through US infrastructure and zero-data-retention partners. After bans, the operator was back within days. They even wrote a pre-deployment test — using Claude, framed as “over-refusal mitigation” — that failed if a violative prompt still reached Claude instead of a more permissive competitor.

Scams

Industrial romance fraud with a human authenticity layer

19
GTG-15001

4,700 AI girlfriends. 25,000 real people. 2.36 million messages in two weeks.

A China-based studio built 20+ dating apps advertised as fully human. The swipe feed was 75% Claude personas, 25% gig workers hired to do the one thing the model cannot: live video and Instagram follow-backs. Workers tapped one of three suggested replies from a weaker model. Apps hid a review-only UI so App Store / Play Store reviewers never saw the real product. Brands included DORA, DONI, ROMI, LUMA, JOVIA, KIRA, HAVEN, NALO, LOVIA.

The system prompt looked like ordinary companion roleplay. Monetization and deception were invisible from inside any single chat.

Illicit distillation

Seven PRC labs · industrial-scale cloning of Claude

20
GTG-16005 · Alibaba / Tongyi

3 million stolen Claude conversations. Per day. Peak.

Anthropic calls this the largest distillation attack they have ever measured. Alibaba-affiliated operators forced Opus 4.6 / 4.7 to dump chain-of-thought inside inline tags, then converted the traces into supervised fine-tuning data for Qwen 3.5, 3.6, and 3.7. More than 3,500 fraudulent accounts at peak. May–July 2026 total attributed: over 151 million exchanges. When the first ~5,000-account pool was banned, traffic shifted to a second pool that was also funneling DeepSeek and Xiaomi.

21
Moonshot + DeepSeek

Users thought they were talking to Kimi or DeepSeek. They were talking to Claude.

Moonshot silently forwarded customer prompts to Claude, showed Claude’s answers as Kimi, and harvested the traces. ~300,000 requests in ten days via 5,380 fake accounts. DeepSeek did the same, tagging users of Claude Code / OpenCode and rerouting them to Opus. Collateral in those pipes: PLA-adjacent CCTV analysis from Chengdu, live credentials for a Russian MoD-linked database, and a Chinese municipal police tool that matches movement to national ID numbers.

22
The meta-fact

Safeguards do not travel with the stolen weights.

Anthropic’s own distillation research: a student model trained on frontier traces can pick up dangerous cyber and biological capabilities even when the harvested chats barely mention those topics. The refusals that stop Claude do not copy over. That is why Fable-class models were kept off the public distillation surface — and why Zhipu quit attacking Fable and switched to Opus after the cyber classifiers degraded the attack.