Anthropic says multiple threat groups, including financially motivated criminals and state-sponsored espionage groups linked to Russia and China, attempted to abuse its Claude AI model for cyberattacks and other malicious activities.
In a threat intelligence report covering activity between December 2025 and August 2026, the AI company documented the misuse of Claude in cyberattacks, influence operations, surveillance, fraud, biological and conventional weapons development, and AI model distillation.
Anthropic said it disrupted several operations associated with the ShinyHunters collective, a cybercrime group known for large-scale data theft campaigns that often begin with social engineering and compromised accounts.
ShinyHunters used Claude to automate credential theft
An alleged French-speaking ShinyHunters member using the handle “frkoo” distributed a credential-harvesting pipeline across 10 Amazon Web Services EC2 workers. The infrastructure scanned approximately 1.8 million Android application packages, or APKs, downloaded from multiple app stores.
According to Anthropic, the pipeline downloaded and decompiled the APK files before scanning them for hardcoded secrets with TruffleHog. The results were reportedly routed in real time to Telegram groups organized into more than 100 source categories, Anthropic said.
The same attackers used another automated process to collect GitHub organization email addresses and target GitHub Personal Access Tokens, or PATs.
Anthropic said the two pipelines supplied the initial credentials that “frkoo” used in the majority of confirmed breaches attributed to the activity.
The company also linked “frkoo” to a card shop hosted at National Police Agency[.]cc, a website that impersonated the French National Police. The site allegedly sold stolen payment card records, complete cardholder information, and an interactive map showing victims’ addresses.
Other individuals believed to be associated with ShinyHunters reportedly stole AI API keys and used them to conduct reconnaissance and infiltrate additional organizations.
In one incident, the attackers compromised a software-as-a-service provider and stole data belonging to approximately 200 downstream customers.
AI-assisted attacks accelerated intrusion operations
Anthropic said a suspected ShinyHunters threat actor used Claude to extract authentication data and obtain more than 2,100 Azure Active Directory authentication tokens associated with over 40 corporate Microsoft tenants.
The operation reportedly took approximately 34 hours, with Anthropic stating that AI agents performed nearly all of the work.
Other harmful activity attributed to ShinyHunters affiliates included the compromise of a technology provider and theft of 1 TB of data, an attack against an airline, and unauthorized access to an energy company’s systems.
The threat actors also moved quickly after obtaining initial access. In one case involving an enterprise software company, attackers reportedly stole large quantities of data within a few hours.
In another incident, the attackers allegedly escalated from a single stolen developer token to full administrative control in approximately three hours.
Russian espionage group used Claude across attack stages
Anthropic’s report also details activity attributed to Midnight Blizzard, a Russian state-sponsored espionage group. The company said the group used Claude to automate malware development, phishing operations, infrastructure acquisition, persistence, command-and-control activities, and data exfiltration.
The attackers reportedly created a feedback loop that rebuilt malware whenever security software detected it.
Anthropic observed Midnight Blizzard targeting more than 20 government, defense, diplomatic, intelligence, and foreign policy organizations.
The campaign allegedly involved device-code phishing, ClickFix attacks, DNS hijacking through a compromised hotel Wi-Fi provider, WhatsApp account takeovers, cloud email theft, and malware targeting Windows, Android, and iOS devices.
Claude was reportedly used throughout the attack chain. Midnight Blizzard automated its operations through AI-driven workflows built around Claude Code skills, while human operators modified those skills when improvements were necessary.
Chinese-speaking group conducted automated vulnerability research
Anthropic also described espionage activity by a Chinese-speaking group tracked as GTG-10007. The group allegedly used Claude as an engineering and orchestration layer for a coordinated cyberattack program involving:
- Attempts to compromise production systems
- Reconnaissance of foreign government networks across the Middle East, Europe, and Southeast Asia
- Vulnerability research and exploit development targeting major endpoint security products
- Malware development
- Construction of an information-gathering platform
Anthropic said GTG-10007 operated an autonomous vulnerability research workflow with limited or no human involvement. The workflow reportedly discovered multiple previously unknown vulnerabilities in major security products.
The automated effort also produced valid exploits for several families of network and security appliances. The attackers allegedly used the exploit code against government organizations in multiple countries.
The group targeted approximately 50 organizations across government, education, retail, energy, technology, healthcare, finance, and manufacturing. Anthropic said confirmed breaches involved education technology companies, retailers, and government agencies in Southeast Asia.
Anthropic bans accounts and strengthens Claude safeguards
Anthropic said it blocked the attackers from continuing to use Claude for malicious activity and banned the associated threat actor accounts.
The company also said it strengthened Claude’s safety guardrails based on observed abuse, added detection measures to identify similar activity more quickly, and notified law enforcement, industry partners, and affected organizations.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about AI-driven attacks, machine-speed defense, and how organizations can verify, decide, fix, and revalidate security controls faster.
Source: www.bleepingcomputer.com



