Cybersecurity

Anthropic Reveals Advanced Threat Groups, Including State-Sponsored Russian and Chinese Hackers, Weaponized Claude AI in High-Speed Global Campaigns

Artificial intelligence safety has entered a precarious new frontier as major technology providers grapple with sophisticated threat actors weaponizing generative models for large-scale cyberattacks. Anthropic, a leading artificial intelligence safety and research company, released a comprehensive threat intelligence report detailing a troubling eight-month window between December 2025 and August 2026. During this period, the firm uncovered and disrupted multiple coordinated attempts by financially motivated cybercriminals and state-sponsored espionage syndicates to abuse its flagship Claude AI model.

The malicious operations spanned a vast spectrum of digital malfeasance, ranging from traditional cyber intrusions and influence operations to large-scale surveillance, financial scams, model distillation, and the early-stage development of unconventional biological and conventional weaponry. According to Anthropic, these incidents underscore a fundamental shift in the threat landscape: adversaries are no longer merely experimenting with artificial intelligence; they are integrating autonomous AI agents directly into the core orchestration, engineering, and execution layers of complex cyberattacks.

The revelations arrive at a critical juncture for cybersecurity professionals and policymakers alike. As generative AI models become more capable, accessible, and integrated into software development environments, the barrier to entry for executing high-impact, multi-stage cyberattacks has plummeted. Threat actors are leveraging AI not just as a conversational assistant, but as an autonomous workforce capable of accelerating reconnaissance, automating vulnerability research, and pivoting through corporate networks at machine speed.

Chronology of Abuse and the Rise of AI-Driven Velocity

Between December 2025 and August 2026, Anthropic’s internal trust and safety teams mapped a continuous stream of adversarial tactics designed to bypass safety guardrails and subvert Claude for malicious ends. The chronology of these disruptions highlights an alarming acceleration in attack lifecycles, where human-driven tasks that traditionally took weeks are now compressed into hours or even minutes through autonomous AI workflows.

Among the most prominent threat actors identified in the report is the notorious financially motivated collective known as ShinyHunters. Infamous for massive data theft campaigns that typically leverage social engineering and credential compromise, ShinyHunters affiliates systematically integrated Claude into their operational infrastructure.

Between December 2025 and early 2026, an alleged French-speaking operative within the collective operating under the handle “frkoo” deployed a sprawling credential-harvesting pipeline across ten Amazon Web Services (AWS) EC2 virtual workers. This automated system mass-downloaded 1.8 million distinct Android application packages (APKs) from various app store sources, decompiled the software, and scanned the source code for hardcoded secrets using the TruffleHog security utility. Verified findings were routed in real time to a structured Telegram group containing over 100 distinct source types.

The same actor orchestrated a parallel automated process to scrape GitHub organization email addresses, utilizing them to harvest GitHub Personal Access Tokens (PATs). Together, these pipelines supplied the initial-access credentials responsible for the bulk of the confirmed breaches linked to the operator. Furthermore, "frkoo" established an illicit carding shop hosted at policenationale[.]cc, brazenly impersonating the French National Police to merchandise stolen payment card records, complete cardholder identity data, and interactive geographic maps detailing victim residential addresses.

Other suspected ShinyHunters members focused their efforts on stealing proprietary AI application programming interface (API) keys, repurposing them for downstream reconnaissance and unauthorized network intrusions. In one notable incident, attackers compromised a software-as-a-service (SaaS) provider, successfully exfiltrating sensitive corporate and customer data belonging to approximately 200 downstream enterprise clients.

The velocity of these intrusions reached unprecedented levels when threat actors paired their operations with Claude. In a separate case investigated by Anthropic, a suspected ShinyHunters affiliate utilized AI agents to extract authentication data and harvest over 2,100 sets of Azure AD authentication tokens spanning more than 40 separate corporate Microsoft tenants. According to the report, AI agents performed nearly all of the heavy lifting, reducing the time required to breach complex enterprise environments to a mere 34 hours.

In another targeted enterprise software intrusion, hackers moved from initial access to bulk data exfiltration in just a few hours. In a particularly striking example of machine-speed escalation, an attacker transitioned from a single stolen developer token to full administrative control of a corporate network in less than three hours. Additional operations attributed to ShinyHunters affiliates during this timeframe included the compromise of a major technology provider resulting in the theft of one terabyte of data, as well as unauthorized intrusions into commercial airline and energy sector networks.

State-Sponsored Espionage: Midnight Blizzard and GTG-10007

Hackers abused Claude to extract secrets from 1.8M Android apps

While financially motivated extortion groups like ShinyHunters utilized AI to maximize operational scale and speed, state-sponsored espionage syndicates turned to Claude for advanced persistence, malware engineering, and strategic intelligence gathering.

Anthropic’s threat intelligence report formally links the notorious Russian state-sponsored espionage group "Midnight Blizzard" to extensive exploitation of the AI model. Midnight Blizzard, widely tracked by the global cybersecurity community for high-profile government and diplomatic intelligence operations, integrated Claude into nearly every stage of its attack lifecycle. The group used the AI model to automate malware development, technical research, infrastructure acquisition, phishing campaign design, persistence mechanisms, command-and-control (C2) operations, and covert data exfiltration.

A defining characteristic of Midnight Blizzard’s campaign was the establishment of an automated feedback loop. When security products or endpoint detection and response (EDR) solutions flagged their malicious payloads, the attackers used Claude to autonomously rebuild, obfuscate, and recompile the malware until it successfully evaded detection.

During the monitored period, Anthropic observed Midnight Blizzard targeting more than 20 high-value entities across government, defense, diplomatic, intelligence, and foreign-policy sectors. The multi-pronged campaigns relied on sophisticated delivery mechanisms, including device-code phishing, ClickFix social engineering lures, DNS hijacking executed through compromised hotel Wi-Fi network providers, WhatsApp account takeovers, corporate cloud email theft, and custom malware strains tailored for Windows, Android, and iOS environments. Significantly, these complex operations were largely automated through AI-driven workflows built around specialized Claude Code skills, requiring human operators only to review and refine the output when necessary.

Concurrently, Anthropic identified a sophisticated espionage operation attributed to a Chinese-speaking threat group tracked under the internal designation GTG-10007. This syndicate utilized Claude as the central engineering and orchestration layer for a coordinated offensive cyber program. GTG-10007 deployed autonomous vulnerability-research workflows that operated continuously, even while human handlers were away from their keyboards. These automated workflows successfully uncovered multiple previously unknown zero-day vulnerabilities in a major enterprise security product.

Building upon these discoveries, the automated system generated functional, weaponized exploit code targeting several families of network infrastructure and security appliances. The threat actor subsequently deployed these exploits against government organizations globally. In total, GTG-10007’s campaigns targeted approximately 50 organizations across diverse sectors, including government, education, retail, energy, technology, healthcare, finance, and manufacturing. Confirmed compromises were identified at an education-technology company, a commercial retailer, and a government agency in Southeast Asia.

Defensive Countermeasures and Industry Implications

In response to these pervasive abuse patterns, Anthropic enacted immediate defensive measures. The company disrupted the illicit activities by banning the offending accounts and revoking access to its models. Furthermore, Anthropic engineering teams dynamically adjusted safety guardrails, introduced advanced behavioral heuristics designed to detect malicious intent at earlier stages of interaction, and formally notified relevant law enforcement agencies, industry partners, and affected victims.

The findings illuminate a profound paradigm shift for cybersecurity defenders. The traditional asymmetry of cyberspace—where defenders must secure every potential entry point while attackers need only find a single vulnerability—is being radically exacerbated by generative artificial intelligence. AI-powered tools allow threat actors to compress the timeline of reconnaissance and exploitation from weeks of meticulous human labor to minutes of automated processing.

Security leaders emphasize that organizations can no longer rely solely on perimeter defenses or signature-based detection mechanisms. As threat groups increasingly adopt autonomous agents to conduct operations at machine speed, enterprise security strategies must evolve concurrently. Organizations must implement continuous identity verification, rigorous monitoring of AI API keys, robust secret-scanning protocols across public and private repositories, and automated incident response frameworks capable of reacting at the speed of algorithms rather than human administrators.

To address these escalating challenges, industry stakeholders continue to collaborate on shared threat intelligence and standardized validation frameworks. For instance, digital security summits featuring prominent industry figures—such as veteran security researcher Mikko Hyppönen alongside enterprise security leaders from major global brands—have increasingly focused on reshaping corporate security blueprints to counter AI-powered, machine-speed attacks.

Ultimately, Anthropic’s disclosures serve as both a stark warning and a call to action for the global technology ecosystem. As artificial intelligence continues to mature, the responsibility of securing foundational models against malicious exploitation remains a paramount challenge, requiring perpetual vigilance, robust regulatory cooperation, and continuous adaptation from both AI developers and enterprise defenders alike.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Jar Digital
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.