
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026.
The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals.
"The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators," Anthropic said. "The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration."
Among the notable cases highlighted by Anthropic is the development of an AI-assisted workflow by a Russian state-sponsored threat actor it calls GTG-20006, which shares tactical and tradecraft overlaps with a Russian advanced persistent threat (APT) group tracked as Midnight Blizzard (aka APT29 and Cozy Bear). Some of the other AI-enabled cyber campaigns highlighted by Anthropic in its 154-page report include -
- GTG-50014 (aka MeowSHA, frkoo, and blazespider), a French-speaking operator and a suspected affiliate of the ShinyHunters collective that ran a distributed credential-harvesting pipeline across a fleet of 10 AWS EC2 workers that mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, scanned them for hard-coded secrets using TruffleHog, and sent verified findings to a Telegram group.
- Another ShinyHunters affiliate that specialized in supply chain theft by compromising software-as-a-service (SaaS) vendors to steal data belonging to downstream customers, accelerate reconnaissance, and enable data exfiltration.
- GTG-10007, a Chinese-speaking operator likely based out of Hunan province, some of whom have been identified as undergraduate students at a Chinese university and have used Claude to conduct intrusion attempts against production systems, reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia, a vulnerability-research and exploit development effort against major endpoint-security products, and develop an intelligence-collection platform for bulk-harvesting of open-source material aligned with Beijing's priorities. The threat actor targeted about 50 organizations across education, retail, energy, technology, healthcare, finance, manufacturing, and government sectors globally. The group also maintained an autonomous vulnerability research program to produce working exploits for previously unknown vulnerabilities in network and security appliances.
- GTG-50021, a Russian and Ukrainian-speaking group that ran a fraudulent AI reseller operation offering cheap Claude access, only for customers' traffic to be silently proxied to a different AI model, while the illicit scheme installed a credential harvester to siphon their Anthropic account credentials and sell them to other proxy resellers for malicious use.
- GTG-50020, a Russian-speaking, financially-motivated actor that has historically targeted hotel booking and financial technology platforms but has since focused on the AI supply chain by stealing model provider API keys and unsuccessfully attempting to gain access to pre-release AI models. The threat actor is estimated to have targeted about 30 AI vendors in a four-day window using similar techniques.
- GTG-50029, a single French-speaking actor that used Claude to target European political parties, media, think-tanks, and the SaaS providers used by these organizations, including by exploiting a previously undocumented WordPress re-installation race condition that made it possible to create a rogue administrator account without valid credentials, as well as by abusing an exposed search endpoint to breach a political campaign management platform and siphon sensitive data. The threat actor has also been observed deploying web shells and a browser exploitation C2 framework against other targets. Central to the attacker's operation was a purpose-built doxxing platform named "fafsearch" that offered the ability to cross-reference individual breach dumps against exfiltrated data.
"At one end, actors used Claude conversationally: it acted as an engineering assistant in the creation of malware, phishing kits, and surveillance tooling," Anthropic said. "Further along the spectrum, threat actors directed Claude to execute operations (such as running commands against victim networks, harvesting credentials, and exfiltrating data) with a human making each individual targeting decision (GTG-20006)."
"At the far end, operations ran autonomously, with minimal human input or supervision: these included multi-agent frameworks conducting reconnaissance, exploitation, and theft against multiple victims, in parallel, for hours or days at a time (GTG-50014, GTG-50020, GTG-50029)."
The AI company said it also identified and took down a number of influence operations in which Claude played the role of a "sub-editor or content creator" to churn out content and run them at a scale beyond what low-resourced actors could have accomplished on their own. However, Anthropic emphasized that none of these efforts amassed authentic engagement and that they were disrupted before they could even build an audience.
Some of the influence and surveillance campaign clusters flagged by Anthropic at a high level are below -
- GTG-04001, a Russian-speaking actor in Bangui that engaged in a foreign information manipulation and interference operation in the Central African Republic to amplify pro-Russia, anti-France talking points.
- GTG-54002, a commercial "influence-as-a-service" operation that used Claude to mass-produce and rewrite political content across about 70 fabricated news websites. The operation has been traced back to LKM Company, a France-based digital advertising agency.
- GTG-84005, a single account that used Claude to run a commercial election manipulation platform primarily targeting users in Malaysia based on political and social factors, such as their race and religion, by posing as a defensive cyber intelligence and counter-disinformation tooling outlet. The activity has been found to share links with BBS Bilisim Teknolojileri, an Istanbul-based technology company.
- GTG-24015, a set of four accounts that used Claude as an "editorial and news production desk" to distribute them via state media outlets like Sputnik Moldova, RIA Novosti, Sputnik en Español, Sputnik Africa, and RT's English-language newsroom.
- GTG-34001, a set of three Iranian state-aligned accounts that used Claude to shape public opinion, turn official government intelligence bulletins into tailored content, and disseminate the content across social media platforms.
- GTG-54006, a sustained, automated disinformation network that used Claude to generate fabricated Bengali-language news in Bangladesh and promote the country's Awami League party. The activity has been linked to a single actor based in Gaibandha District in Bangladesh via a set of 29 Claude accounts that were rotated to bypass platform limits and detection.
- GTG-84006, a distributed influence operation that targeted Iranian audiences across the world with an aim to impersonate real activists and engage in live political conversations. The activity has been linked to People's Mojahedin Organization of Iran (PMOI/MEK) and the National Council of Resistance of Iran (NCRI).
- GTG-54004, an account used by a single actor to mass-produce Kenyan political content as part of what's suspected to be a domestic astroturfing campaign with a pro-administration bent.
- GTG-84002, an account used by a single actor to run a sustained influence operation against the Muslim Brotherhood, the Sudan conflict, and the United Nations accountability mechanisms.
- GTG-54009, a commercial surveillance platform that used Claude to analyze, classify, and profile the social media activity of users in Iran and the Persian Gulf region. The activity is assessed to have been carried out by, or on behalf of, an Israeli-Singaporean commercial intelligence vendor named S2T Unlocking Cyberspace.
- GTG-14010, a China state-aligned operation that used Claude to track, profile, and recruit Uyghurs and Uyghur armed formations in Syria. The actor has been found to use the AI model to convert conversations extracted in bulk from over 100 monitored WhatsApp groups and dozens of Telegram channels into structured Chinese-language data and "creating profiles of individuals who might be vulnerable to targeting due to financial stress, family separation, and ideological disillusionment."
- GTG-14020, a set of accounts likely linked to a Chinese government-aligned intelligence operation that used Claude to build Chinese-language dossiers targeting religious leaders and Chinese diaspora figures across Asia, as well as map religious venues and instruct the model to adopt "China's standpoint."
- GTG-14021, a set of accounts from China-based actors that used Claude to support surveillance and transnational repression, including prompting the model to assume the role of an intelligence analyst serving China's national security apparatus.
- GTG-14022, a China-based "public opinion monitoring" and dissident surveillance operation that used Claude to produce government briefings that listed dissidents, activists, ethnic minority and Chinese diaspora communities, and foreign media as threats to political stability while asking it to play the role of a "senior emergency public opinion analyst serving the government of the People's Republic of China."
- GTG-34007, a set of 16 accounts operated by two Iranian-nexus actors associated with paramilitary and domestic security agencies that used Claude to build a frontend for what appears to be a government-controlled surveillance case-management system, run social-network analysis over 155,216 X posts, and build domestic surveillance capabilities via a malicious Mozilla Firefox extension named "al-Najm al-thāqib" to harvest user identities from major social network platforms.
- GTG-50027, a single account that used Claude to design a national mass interception and surveillance platform called Lakana 360 for Mali's state intelligence service to monitor about 25 million SIM cards spanning three of the country's national mobile operators, and generate intelligence dossiers for any phone number. The platform has a separate layer that collects call records, text messages, and voice calls across the mobile networks.
- GTG-30004, an Iran-nexus threat actor that used Claude to develop an automated, open-source intelligence identity-profiling service targeting Israeli and Jewish diaspora organizations.
- GTG-30005, an Iran-nexus threat actor that used Claude to gather and analyze publicly accessible data to develop targeting recommendations against U.S. naval forces in the region and build software components of a domestic mass-surveillance platform that combined automatic license-plate recognition with mobile-device identifier interception.
- GTG-30006, an Iranian threat actor that leveraged free Claude.ai accounts to develop malware, a delivery pipeline, and a phishing portal targeting domestic Iranians. This included a bogus ESET NOD32 antivirus login page that transmits captured credentials to Telegram, a ClickFix-style Windows Run dialog lure, and geofenced delivery pages. The threat actor has also used Claude to build SECOMS64, a modular Windows implant with keylogging, screenshot capture, and Chrome credential extraction capabilities.
Elsewhere, Anthropic said it neutralized Claude misuse efforts by threat actors based in northern Yemen to develop guided weapons, two China-based operations to draft a Chinese-language specification for an anti-torpedo fire control system and build targeting software for electronic warfare, and a Russia-based operation to engineer a full-stack autonomous first-person-view (FPV) kamikaze drone swarm.
"As AI models become more widely used, providers will continue to acquire threat-relevant visibility into real-world use that even governments and intergovernmental organizations lack," the company said. "We hope that sharing these early insights with the public helps inform governments, the industry, and the general public on the nature of these risks, and the safeguards that are necessary for ensuring the safe deployment of AI models."