Hacking

Anthropic: Claude Used for Cyberattacks and Surveillance

Published  ·  8 min read

Anthropic just dropped a 154-page report that should make anyone in security sit up straight. Between December 2025 and August 2026, cybercriminals and state-sponsored hackers used Claude for cyberattacks, weapons design, propaganda, and mass surveillance.

The Hacker News covered the report in detail. Anthropic calls these actors Generative Threat Groups (GTGs), and they span state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals.

"The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators."

That's the headline. AI has changed who can do what.

Quick Summary

What

Details

Report

Anthropic 154-page threat report

Period

December 2025 – August 2026

Actors

State-sponsored, criminals, spyware vendors, propaganda

Misuse

Cyberattacks, weapons, surveillance, influence ops

Key Finding

AI collapsed the labor gap between states and individuals

The Spectrum of AI Misuse

Anthropic laid out a spectrum of how threat actors used Claude. It's not just one thing.

  • At one end: Conversational use. Claude acted as an engineering assistant for malware, phishing kits, and surveillance tooling.
  • In the middle: Human-directed operations. Threat actors told Claude to run commands against victim networks, harvest credentials, and exfiltrate data. A human made every targeting decision.
  • At the far end: Autonomous operations. Multi-agent frameworks ran reconnaissance, exploitation, and theft against multiple victims in parallel, for hours or days, with minimal human input.

That last category is the one that keeps security researchers up at night.

Notable Cyber Cases

Here are the cyber campaigns Anthropic highlighted:

Group

Who They Are

What They Did

GTG-20006

Russian state-sponsored (Midnight Blizzard overlap)

AI-assisted workflow for human-directed intrusion

GTG-50014 (MeowSHA)

French-speaking, ShinyHunters affiliate

Scanned 1.8M Android APKs for secrets using TruffleHog

GTG-10007

Chinese-speaking, Hunan province, undergrads

Hit ~50 orgs, autonomous vuln research program

GTG-50020

Russian, financially motivated

Targeted ~30 AI vendors in 4 days, stole API keys

GTG-50029

French-speaking, single actor

Targeted European political parties and media

GTG-50021

Russian/Ukrainian

Fake AI reseller that stole Anthropic credentials

GTG-50014 (MeowSHA) is worth a closer look. This group ran a distributed credential-harvesting pipeline across 10 AWS EC2 workers. They mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, scanned them for hard-coded secrets using TruffleHog, and sent verified findings to a Telegram group.

That's a lot of scanning. AI made it possible.

GTG-10007 is also notable. A Chinese-speaking group likely based in Hunan province. Some of them were identified as undergraduate students at a Chinese university. They targeted about 50 organizations across education, retail, energy, technology, healthcare, finance, manufacturing, and government sectors globally. They also ran an autonomous vulnerability research program to produce working exploits for previously unknown vulnerabilities in network and security appliances.

Undergraduate students. Running an autonomous vuln research program. That's the new reality.

GTG-50029 is the one with the doxxing platform. A single French-speaking actor targeted European political parties, media, and think-tanks. They exploited a previously undocumented WordPress re-installation race condition to create a rogue admin account. They also abused an exposed search endpoint to breach a political campaign management platform. Central to their operation was a purpose-built doxxing platform called "fafsearch" that cross-referenced individual breach dumps against exfiltrated data.

Surveillance and Repression

Anthropic flagged a long list of surveillance operations. These are cases where Claude was used to build mass surveillance platforms or support transnational repression.

Group

Target

What They Built

GTG-50027

Mali

Lakana 360 - monitors ~25 million SIM cards

GTG-14010

Uyghurs in Syria

Profiling from 100+ WhatsApp groups

GTG-14020

Chinese diaspora

Dossiers on religious leaders

GTG-14021

Transnational repression

Intelligence analyst role-play

GTG-14022

Dissident surveillance

Government briefings listing threats

GTG-34007

Iran

Firefox extension to harvest identities

GTG-84002

Muslim Brotherhood, Sudan, UN

Sustained influence operation

GTG-84005

Malaysia

Election manipulation platform

GTG-54009

Iran and Persian Gulf

Social media profiling for S2T

GTG-30004

Israeli and Jewish diaspora

Identity-profiling service

GTG-30005

U.S. naval forces

Targeting recommendations

GTG-30006

Domestic Iranians

SECOMS64 Windows implant

GTG-50027 stands out. A single account used Claude to design a national mass interception and surveillance platform for Mali's state intelligence service. The platform, called Lakana 360, monitors about 25 million SIM cards across three national mobile operators. It generates intelligence dossiers for any phone number. It collects call records, text messages, and voice calls.

That's a national surveillance system. Built with AI assistance.

GTG-14010 is another one. A China state-aligned operation used Claude to track, profile, and recruit Uyghurs and Uyghur armed formations in Syria. They converted conversations extracted from over 100 monitored WhatsApp groups and dozens of Telegram channels into structured Chinese-language data. They created profiles of individuals vulnerable to targeting due to financial stress, family separation, and ideological disillusionment.

That's not just surveillance. That's targeting for recruitment.

Influence Operations

Anthropic also took down a number of influence operations. In these, Claude played the role of sub-editor or content creator.

Group

Location

What They Did

GTG-04001

Central African Republic

Pro-Russia, anti-France talking points

GTG-54002

France (LKM Company)

70 fabricated news websites

GTG-84005

Malaysia

Election manipulation

GTG-24015

Russia

State media content (Sputnik, RT)

GTG-34001

Iran

Government intelligence bulletins

GTG-54006

Bangladesh

Pro-Awami League fabricated news

GTG-84006

Iran

Impersonating activists (PMOI/MEK)

GTG-54004

Kenya

Pro-administration astroturfing

GTG-84002

Sudan

Anti-Muslim Brotherhood content

GTG-54009

Iran/Gulf

Surveillance profiling

GTG-14020

China

Dossiers on religious leaders

GTG-14021

China

Transnational repression

GTG-14022

China

Dissident surveillance

GTG-34007

Iran

Surveillance case management

GTG-50027

Mali

National mass interception

GTG-30004

Iran

Israeli/Jewish profiling

GTG-30005

Iran

U.S. naval targeting

GTG-30006

Iran

Malware and phishing

Anthropic emphasized that none of these efforts amassed authentic engagement. They were disrupted before they could build an audience.

GTG-54002 is interesting. A commercial "influence-as-a-service" operation that used Claude to mass-produce and rewrite political content across about 70 fabricated news websites. It was traced back to LKM Company, a France-based digital advertising agency.

GTG-54006 is another one. A sustained, automated disinformation network that used Claude to generate fabricated Bengali-language news in Bangladesh and promote the Awami League party. It was linked to a single actor in Gaibandha District using 29 Claude accounts rotated to bypass platform limits.

Weapons Design

This is the part that's genuinely alarming. Anthropic said it neutralized Claude misuse efforts by threat actors to develop weapons.

What They Found:

  • Northern Yemen: Guided weapons development
  • China (two operations): Chinese-language specification for an anti-torpedo fire control system, targeting software for electronic warfare
  • Russia: Full-stack autonomous first-person-view (FPV) kamikaze drone swarm

AI-assisted weapons design. Drone swarms. Fire control systems.

What Anthropic Did

Anthropic said it identified and took down these operations. It also disrupted influence campaigns before they could build an audience.

The company's takeaway: "As AI models become more widely used, providers will continue to acquire threat-relevant visibility into real-world use that even governments and intergovernmental organizations lack."

That's a bold claim. But it's probably true. AI providers see how their models are used in ways that governments don't.

"We hope that sharing these early insights with the public helps inform governments, the industry, and the general public on the nature of these risks, and the safeguards that are necessary for ensuring the safe deployment of AI models."

This Means to You

The Threat Is Now Different:

  • AI has bridged the labor gap between states and individuals
  • Multi-agent models operate independently
  • The cost of launching complex attacks is decreasing

Things to Look Out For:

  • AI-assisted reconnaissance and exploitation
  • Multi-agent systems operating in parallel
  • Credential harvesting at scale
  • Vulnerability analysis and exploitation done autonomously

Actions to Take:

  • Look for patterns of attacks by AI
  • Look out for rapid retry waves and systematic enumeration
  • Consider the impact of AI attacks on your infrastructure
  • Get ready for a world where anyone can conduct sophisticated operations

The Bottom Line

Anthropic's report shows that Claude was used for cyberattacks, weapons design, propaganda, and mass surveillance. The threat actors span states, criminals, spyware vendors, and propaganda institutions. AI has collapsed the labor gap that used to separate well-resourced operations from individual operators.

What You Need to Know:

Key Point

Detail

Report

Anthropic 154-page threat report

Period

December 2025 – August 2026

Actors

State-sponsored, criminals, spyware vendors, propaganda

Misuse

Cyberattacks, weapons, surveillance, influence ops

Key Finding

AI collapsed the labor gap between states and individuals

What You Need to Do:

  • Monitor for AI-assisted attack patterns
  • Watch for multi-agent frameworks
  • Review your exposure
  • Prepare for AI-powered attacks

FAQ Section

What is the Claude Anthropic misuse report?

An 154-page report about how cybercriminals and state hackers abused Claude to carry out cyber operations, weapons development, propaganda, and surveillance from December 2025 to August 2026.

What is Generative Threat Group (GTG)?

A term by Anthropic which refers to the threats posed by threat actors who misuse the capabilities of generative AI for their malicious activities. GTG refers to many different threat actors, ranging from state-sponsored hackers to financially motivated hackers, spyware providers, propaganda firms, and politically motivated threat actors.

What would be the most shocking revelation?

AI-powered weapons, ranging from weapon guidance in Yemen, an anti-torpedo fire control system in China, to kamikaze FPV drone swarms in Russia.

How did AI change the threat landscape?

AI collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators.

What should organizations do?

Identify signs of AI-assisted attacks, look out for multi-agent systems, assess their vulnerability, and prepare for AI attacks.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067