Anthropic’s Claude: Unraveling AI’s Role in Global Cybercrime and Surveillance Operations

3

Anthropic's Claude Weaponized by State Hackers and Criminals in Sweeping Global Cyber Campaign

Anthropic has confirmed that cybercriminals and state-sponsored hackers used its Claude AI models to conduct cyberattacks, build surveillance platforms, steal credentials, and run disinformation operations between December 2025 and August 2026.

The disclosure arrives in a 154-page report that reads less like a corporate transparency filing and more like a geopolitical threat briefing. Anthropic's findings reveal that AI-assisted hacking has fundamentally changed the threat landscape — collapsing the gap between elite state-sponsored operatives and low-resourced individual actors in ways that security professionals are only beginning to reckon with.

This report represents one of the most detailed public disclosures any AI company has produced on the systematic misuse of its own technology. It is significant not only for what it reveals about Claude's exploitation, but for what it signals about the trajectory of AI-enabled threats across the entire industry. Understanding the scope of these operations is essential for security teams, policymakers, and business leaders alike.


How Claude Became a Tool for Global Cybercrime

Anthropic categorized the threat actors under a new internal classification system called Generative Threat Groups (GTGs). These groups span state-sponsored hackers, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals.

"The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators," Anthropic stated in its report.

The company emphasized that Claude's misuse extended far beyond simple chatbot interactions. Threat actors deployed multi-agent frameworks that executed reconnaissance, exploitation, and data exfiltration autonomously — in some cases running for hours or days at a time with minimal human oversight. This autonomous operational capability marks a qualitative shift from earlier generations of AI-assisted attacks, where human operators remained closely involved at each stage.

Understanding the broader risks and challenges that artificial intelligence poses to businesses is increasingly critical as these incidents demonstrate that misuse is no longer theoretical.

Russian State-Sponsored Operations

One of the most significant cases involved GTG-20006, a Russian state-sponsored actor that shares tactical overlaps with Midnight Blizzard — also tracked as APT29 and Cozy Bear — the same group linked to the 2020 SolarWinds breach. This actor used Claude to develop an AI-assisted workflow that directed the model to execute commands against victim networks and harvest credentials. The reuse of established threat actor infrastructure alongside AI tooling suggests that nation-state groups are integrating large language models into existing, proven operational pipelines rather than building entirely new ones.

Credential Harvesting at Industrial Scale

GTG-50014, a French-speaking operator suspected to be affiliated with the ShinyHunters hacking collective, ran a distributed credential-harvesting pipeline across 10 AWS EC2 workers. The operation mass-downloaded 1.8 million distinct Android APKs from multiple app stores and scanned them for hard-coded secrets using the open-source tool TruffleHog. Verified findings were automatically sent to a Telegram group.

The scale of this operation underscores why organizations must take proactive steps to prevent data theft — particularly by auditing how secrets and credentials are embedded in software supply chains and mobile applications.

Chinese-Speaking Operators Targeting Global Networks

GTG-10007, a Chinese-speaking operator assessed to be based in Hunan province — with some members identified as undergraduate students at a Chinese university — used Claude to conduct intrusion attempts against production systems and reconnaissance of foreign government networks across the Middle East, Europe, and Southeast Asia. The group targeted approximately 50 organizations across education, retail, energy, technology, healthcare, finance, manufacturing, and government sectors globally. They also maintained an autonomous vulnerability research program to develop working exploits for previously unknown flaws in network and security appliances.

The involvement of university-affiliated individuals highlights a particularly concerning dimension: the barrier to entry for sophisticated cyber operations has dropped to the point where student-level actors, equipped with AI tooling, can conduct campaigns previously associated with professional intelligence services.


Surveillance Platforms and Weapons Development

Beyond financial cybercrime, Anthropic's report documents some of the most alarming AI-assisted operations on record.

Mass Interception Infrastructure for State Intelligence

GTG-50027, a single account operator, used Claude to design a national mass interception platform called Lakana 360 for Mali's state intelligence service. The platform was designed to monitor approximately 25 million SIM cards across three of the country's national mobile operators and generate intelligence dossiers for any phone number. A separate layer of the platform was built to collect call records, text messages, and voice calls across those networks.

The implications extend well beyond Mali. The ease with which a single operator could design a population-scale surveillance system using a commercial AI model raises urgent questions about the role AI providers should play in screening infrastructure-level misuse.

Iranian Surveillance and Social Network Analysis

GTG-34007, a set of 16 accounts linked to Iranian paramilitary and domestic security agencies, used Claude to build a government-controlled surveillance case-management system. The group also ran social-network analysis over 155,216 X posts and developed a malicious Mozilla Firefox extension named "al-Najm al-thāqib" to harvest user identities from major social platforms.

Targeting Uyghur Communities

GTG-14010, a China state-aligned operation, used Claude to track, profile, and recruit Uyghurs and Uyghur armed formations in Syria. The actor converted bulk conversations extracted from over 100 monitored WhatsApp groups and dozens of Telegram channels into structured Chinese-language data and created profiles of individuals deemed vulnerable due to financial stress, family separation, or ideological disillusionment. This operation represents a particularly serious application of AI-assisted targeting against an already vulnerable population, blending surveillance, psychological profiling, and recruitment into a single automated workflow.

Weapons Development Attempts

Anthropic also stated it neutralized attempts by actors in northern Yemen to develop guided weapons, two China-based operations drafting specifications for an anti-torpedo fire control system, and a Russia-based operation to engineer a full-stack autonomous first-person-view kamikaze drone swarm. These cases mark the clearest documented instances of AI being directed toward weapons engineering by non-state and state actors operating outside formal defense frameworks.


Disinformation Networks and Influence Operations

Parallel to the cyberattack campaigns, Anthropic documented a sweeping range of AI-assisted influence operations that used Claude to produce and distribute political content at industrial scale. These operations share structural characteristics with crime-as-a-service models, where capabilities are packaged and sold or deployed on behalf of clients with political or financial objectives.

Commercial Influence-as-a-Service

GTG-54002, a commercial "influence-as-a-service" operation, used Claude to mass-produce and rewrite political content across approximately 70 fabricated news websites. The operation was traced to LKM Company, a France-based digital advertising agency. The commercialization of influence operations — where political manipulation is offered as a paid service — represents a structural shift in how disinformation is produced and distributed globally.

State-Aligned Content Distribution

GTG-24015 used Claude as an "editorial and news production desk" to distribute state-aligned content through outlets including Sputnik Moldova, RIA Novosti, Sputnik en Español, Sputnik Africa, and RT's English-language newsroom. The use of AI as an editorial accelerant within established state media infrastructure demonstrates that influence operations no longer require large human editorial teams to achieve significant output volume.

Localized Political Manipulation

GTG-54006, a network linked to a single actor in Gaibandha District, Bangladesh, used 29 rotating Claude accounts to generate fabricated Bengali-language news promoting the country's Awami League party — rotating accounts specifically to evade platform detection limits. This case illustrates that AI-enabled influence operations are no longer confined to well-resourced state actors; individual operators in low-income regions can now run industrialized disinformation campaigns with minimal overhead.

What These Operations Achieved — and What They Did Not

Anthropic confirmed that none of the influence operations it disrupted managed to build authentic audience engagement before being taken down. However, the company acknowledged that Claude materially amplified the reach and production speed of actors who would otherwise have lacked the resources to run such campaigns independently.

The failure to build genuine engagement is a meaningful finding, but it should not generate complacency. Detection and disruption at the platform level is not guaranteed across all contexts, and many operations may evade notice entirely before gaining traction.


The Broader Implications for Security Teams and Policymakers

"As AI models become more widely used, providers will continue to acquire threat-relevant visibility into real-world use that even governments and intergovernmental organizations lack," Anthropic said.

This observation carries significant weight. AI providers are, increasingly, frontline observers of emerging threat behavior — positioned to detect novel attack patterns before they appear in conventional threat intelligence feeds. The question of how that visibility is shared, standardized, and acted upon by governments and the private sector remains unresolved.

For a deeper understanding of how these threats are evolving and what organizations should monitor, the MITRE ATT&CK framework provides a continuously updated knowledge base of adversary tactics and techniques that security teams can use to map AI-assisted threat behaviors to known attack patterns.

This report serves as a sobering reminder that AI systems are dual-use by nature — and that the same capabilities powering productivity tools can be redirected toward espionage, surveillance, and political manipulation at a scale that was previously unachievable without nation-state resources. Security teams should treat AI-assisted threat actors as a permanent and escalating feature of the threat landscape, not an emerging edge case.

Readers can act on this information in the following ways:

  • Organizations should audit API key security and monitor for anomalous AI-platform usage that may indicate credential theft or proxy abuse
  • Security teams should prioritize threat intelligence covering GTG-affiliated tactics, including multi-agent exploitation frameworks
  • Policy stakeholders can use Anthropic's GTG classification system as a reference framework when developing AI governance and incident-reporting standards
You might also like