Anthropic just dropped a 154-page report that should make anyone in security sit up straight. Between December 2025 and August 2026, cybercriminals and state-sponsored hackers used Claude for cyberattacks, weapons design, propaganda, and mass surveillance.
The Hacker News covered the report in detail. Anthropic calls these actors Generative Threat Groups (GTGs), and they span state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals.
"The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators."
That's the headline. AI has changed who can do what.
Quick Summary
|
What |
Details |
|
Report |
Anthropic 154-page threat report |
|
Period |
December 2025 – August 2026 |
|
Actors |
State-sponsored, criminals, spyware vendors, propaganda |
|
Misuse |
Cyberattacks, weapons, surveillance, influence ops |
|
Key Finding |
AI collapsed the labor gap between states and individuals |
The Spectrum of AI Misuse
Anthropic laid out a spectrum of how threat actors used Claude. It's not just one thing.
- At one end: Conversational use. Claude acted as an engineering assistant for malware, phishing kits, and surveillance tooling.
- In the middle: Human-directed operations. Threat actors told Claude to run commands against victim networks, harvest credentials, and exfiltrate data. A human made every targeting decision.
- At the far end: Autonomous operations. Multi-agent frameworks ran reconnaissance, exploitation, and theft against multiple victims in parallel, for hours or days, with minimal human input.
That last category is the one that keeps security researchers up at night.
Notable Cyber Cases
Here are the cyber campaigns Anthropic highlighted:
|
Group |
Who They Are |
What They Did |
|
GTG-20006 |
Russian state-sponsored (Midnight Blizzard overlap) |
AI-assisted workflow for human-directed intrusion |
|
GTG-50014 (MeowSHA) |
French-speaking, ShinyHunters affiliate |
Scanned 1.8M Android APKs for secrets using TruffleHog |
|
GTG-10007 |
Chinese-speaking, Hunan province, undergrads |
Hit ~50 orgs, autonomous vuln research program |
|
GTG-50020 |
Russian, financially motivated |
Targeted ~30 AI vendors in 4 days, stole API keys |
|
GTG-50029 |
French-speaking, single actor |
Targeted European political parties and media |
|
GTG-50021 |
Russian/Ukrainian |
Fake AI reseller that stole Anthropic credentials |
GTG-50014 (MeowSHA) is worth a closer look. This group ran a distributed credential-harvesting pipeline across 10 AWS EC2 workers. They mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, scanned them for hard-coded secrets using TruffleHog, and sent verified findings to a Telegram group.
That's a lot of scanning. AI made it possible.
GTG-10007 is also notable. A Chinese-speaking group likely based in Hunan province. Some of them were identified as undergraduate students at a Chinese university. They targeted about 50 organizations across education, retail, energy, technology, healthcare, finance, manufacturing, and government sectors globally. They also ran an autonomous vulnerability research program to produce working exploits for previously unknown vulnerabilities in network and security appliances.
Undergraduate students. Running an autonomous vuln research program. That's the new reality.
GTG-50029 is the one with the doxxing platform. A single French-speaking actor targeted European political parties, media, and think-tanks. They exploited a previously undocumented WordPress re-installation race condition to create a rogue admin account. They also abused an exposed search endpoint to breach a political campaign management platform. Central to their operation was a purpose-built doxxing platform called "fafsearch" that cross-referenced individual breach dumps against exfiltrated data.
Surveillance and Repression
Anthropic flagged a long list of surveillance operations. These are cases where Claude was used to build mass surveillance platforms or support transnational repression.
|
Group |
Target |
What They Built |
|
GTG-50027 |
Mali |
Lakana 360 - monitors ~25 million SIM cards |
|
GTG-14010 |
Uyghurs in Syria |
Profiling from 100+ WhatsApp groups |
|
GTG-14020 |
Chinese diaspora |
Dossiers on religious leaders |
|
GTG-14021 |
Transnational repression |
Intelligence analyst role-play |
|
GTG-14022 |
Dissident surveillance |
Government briefings listing threats |
|
GTG-34007 |
Iran |
Firefox extension to harvest identities |
|
GTG-84002 |
Muslim Brotherhood, Sudan, UN |
Sustained influence operation |
|
GTG-84005 |
Malaysia |
Election manipulation platform |
|
GTG-54009 |
Iran and Persian Gulf |
Social media profiling for S2T |
|
GTG-30004 |
Israeli and Jewish diaspora |
Identity-profiling service |
|
GTG-30005 |
U.S. naval forces |
Targeting recommendations |
|
GTG-30006 |
Domestic Iranians |
SECOMS64 Windows implant |
GTG-50027 stands out. A single account used Claude to design a national mass interception and surveillance platform for Mali's state intelligence service. The platform, called Lakana 360, monitors about 25 million SIM cards across three national mobile operators. It generates intelligence dossiers for any phone number. It collects call records, text messages, and voice calls.
That's a national surveillance system. Built with AI assistance.
GTG-14010 is another one. A China state-aligned operation used Claude to track, profile, and recruit Uyghurs and Uyghur armed formations in Syria. They converted conversations extracted from over 100 monitored WhatsApp groups and dozens of Telegram channels into structured Chinese-language data. They created profiles of individuals vulnerable to targeting due to financial stress, family separation, and ideological disillusionment.
That's not just surveillance. That's targeting for recruitment.
Influence Operations
Anthropic also took down a number of influence operations. In these, Claude played the role of sub-editor or content creator.
|
Group |
Location |
What They Did |
|
GTG-04001 |
Central African Republic |
Pro-Russia, anti-France talking points |
|
GTG-54002 |
France (LKM Company) |
70 fabricated news websites |
|
GTG-84005 |
Malaysia |
Election manipulation |
|
GTG-24015 |
Russia |
State media content (Sputnik, RT) |
|
GTG-34001 |
Iran |
Government intelligence bulletins |
|
GTG-54006 |
Bangladesh |
Pro-Awami League fabricated news |
|
GTG-84006 |
Iran |
Impersonating activists (PMOI/MEK) |
|
GTG-54004 |
Kenya |
Pro-administration astroturfing |
|
GTG-84002 |
Sudan |
Anti-Muslim Brotherhood content |
|
GTG-54009 |
Iran/Gulf |
Surveillance profiling |
|
GTG-14020 |
China |
Dossiers on religious leaders |
|
GTG-14021 |
China |
Transnational repression |
|
GTG-14022 |
China |
Dissident surveillance |
|
GTG-34007 |
Iran |
Surveillance case management |
|
GTG-50027 |
Mali |
National mass interception |
|
GTG-30004 |
Iran |
Israeli/Jewish profiling |
|
GTG-30005 |
Iran |
U.S. naval targeting |
|
GTG-30006 |
Iran |
Malware and phishing |
Anthropic emphasized that none of these efforts amassed authentic engagement. They were disrupted before they could build an audience.
GTG-54002 is interesting. A commercial "influence-as-a-service" operation that used Claude to mass-produce and rewrite political content across about 70 fabricated news websites. It was traced back to LKM Company, a France-based digital advertising agency.
GTG-54006 is another one. A sustained, automated disinformation network that used Claude to generate fabricated Bengali-language news in Bangladesh and promote the Awami League party. It was linked to a single actor in Gaibandha District using 29 Claude accounts rotated to bypass platform limits.
Weapons Design
This is the part that's genuinely alarming. Anthropic said it neutralized Claude misuse efforts by threat actors to develop weapons.
What They Found:
- Northern Yemen: Guided weapons development
- China (two operations): Chinese-language specification for an anti-torpedo fire control system, targeting software for electronic warfare
- Russia: Full-stack autonomous first-person-view (FPV) kamikaze drone swarm
AI-assisted weapons design. Drone swarms. Fire control systems.
What Anthropic Did
Anthropic said it identified and took down these operations. It also disrupted influence campaigns before they could build an audience.
The company's takeaway: "As AI models become more widely used, providers will continue to acquire threat-relevant visibility into real-world use that even governments and intergovernmental organizations lack."
That's a bold claim. But it's probably true. AI providers see how their models are used in ways that governments don't.
"We hope that sharing these early insights with the public helps inform governments, the industry, and the general public on the nature of these risks, and the safeguards that are necessary for ensuring the safe deployment of AI models."
This Means to You
The Threat Is Now Different:
- AI has bridged the labor gap between states and individuals
- Multi-agent models operate independently
- The cost of launching complex attacks is decreasing
Things to Look Out For:
- AI-assisted reconnaissance and exploitation
- Multi-agent systems operating in parallel
- Credential harvesting at scale
- Vulnerability analysis and exploitation done autonomously
Actions to Take:
- Look for patterns of attacks by AI
- Look out for rapid retry waves and systematic enumeration
- Consider the impact of AI attacks on your infrastructure
- Get ready for a world where anyone can conduct sophisticated operations
The Bottom Line
Anthropic's report shows that Claude was used for cyberattacks, weapons design, propaganda, and mass surveillance. The threat actors span states, criminals, spyware vendors, and propaganda institutions. AI has collapsed the labor gap that used to separate well-resourced operations from individual operators.
What You Need to Know:
|
Key Point |
Detail |
|
Report |
Anthropic 154-page threat report |
|
Period |
December 2025 – August 2026 |
|
Actors |
State-sponsored, criminals, spyware vendors, propaganda |
|
Misuse |
Cyberattacks, weapons, surveillance, influence ops |
|
Key Finding |
AI collapsed the labor gap between states and individuals |
What You Need to Do:
- Monitor for AI-assisted attack patterns
- Watch for multi-agent frameworks
- Review your exposure
- Prepare for AI-powered attacks
FAQ Section
What is the Claude Anthropic misuse report?
An 154-page report about how cybercriminals and state hackers abused Claude to carry out cyber operations, weapons development, propaganda, and surveillance from December 2025 to August 2026.
What is Generative Threat Group (GTG)?
A term by Anthropic which refers to the threats posed by threat actors who misuse the capabilities of generative AI for their malicious activities. GTG refers to many different threat actors, ranging from state-sponsored hackers to financially motivated hackers, spyware providers, propaganda firms, and politically motivated threat actors.
What would be the most shocking revelation?
AI-powered weapons, ranging from weapon guidance in Yemen, an anti-torpedo fire control system in China, to kamikaze FPV drone swarms in Russia.
How did AI change the threat landscape?
AI collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators.
What should organizations do?
Identify signs of AI-assisted attacks, look out for multi-agent systems, assess their vulnerability, and prepare for AI attacks.