VMTech
Discuss a project

Anthropic Details Claude Misuse in Automated Cyber Operations

Anthropic Details Claude Misuse in Automated Cyber Operations

Anthropic has reported that cybercriminals, state-sponsored groups, spyware vendors and influence operators misused its Claude models between December 2025 and August 2026. The company’s 154-page report describes activity ranging from malware and phishing development to multi-agent workflows that performed reconnaissance, exploitation and data exfiltration against multiple victims.

Anthropic groups the actors under the label Generative Threat Groups, or GTGs. It said the cases show AI being used not only conversationally as an engineering assistant, but also within operational frameworks that could run for hours or days with limited human supervision.

From assisted tasks to automated operations

One of the cases concerns GTG-50014, also known as MeowSHA, frkoo and blazespider, a French-speaking operator assessed as a suspected ShinyHunters affiliate. Anthropic said the actor operated a distributed credential-harvesting pipeline across 10 AWS EC2 workers, downloading 1.8 million distinct Android APKs from several app-store sources.

The pipeline scanned the applications for hard-coded secrets using TruffleHog and sent verified findings to a Telegram group. Anthropic also described a separate ShinyHunters affiliate that compromised SaaS vendors to steal downstream customer data, accelerate reconnaissance and support data exfiltration.

GTG-20006, a Russian state-sponsored actor that aligns with reporting on Midnight Blizzard, APT29 and Cozy Bear, used Claude in a workflow where a human made individual targeting decisions while the model was directed to execute activities such as commands against victim networks, credential harvesting and data exfiltration.

AI supply-chain and infrastructure targets

Anthropic identified GTG-50020 as a Russian-speaking, financially motivated actor that shifted attention to the AI supply chain. The group stole model-provider API keys and unsuccessfully sought access to pre-release AI models, targeting about 30 AI vendors in a four-day period using similar techniques.

The report also described GTG-50021, which operated a fraudulent AI reseller service. Customers were offered low-cost Claude access, but their traffic was silently proxied to another AI model while a credential harvester collected Anthropic account credentials for resale to proxy resellers.

The significance of API-key theft is reinforced by Claude model distillation attempts on attempts to distil Claude models, because both forms of abuse place model access and provider controls at the centre of the threat landscape.

Influence and surveillance misuse

Anthropic said it disrupted influence operations in which Claude acted as a sub-editor or content creator. The company said those campaigns were stopped before building an audience and did not achieve authentic engagement. One operation, GTG-54002, used Claude to produce and rewrite political material across about 70 fabricated news sites and was traced to France-based digital advertising agency LKM Company.

The report also documented surveillance-related activity. GTG-34007 used 16 accounts to support a surveillance case-management frontend, analyse 155,216 X posts and develop a malicious Mozilla Firefox extension called al-Najm al-thāqib. GTG-50027 used Claude to design Lakana 360, described as a national interception and surveillance platform for Mali’s state intelligence service that could monitor about 25 million SIM cards across three mobile operators.

Business implication

Organisations should treat AI accounts, API keys, agent permissions and automated data workflows as high-value security assets, and ensure that credential harvesting, unusual model access and abnormal data collection are incorporated into security monitoring and response processes.

#cybersecurity#artificialintelligence#threatintel#apikeysecurity
Open analytics
On the site 0 views
min read 4 11.09.2026
Instagram

Anthropic Details Claude Misuse in Automated Cyber Operations

Open the post on Instagram ↗