Anthropic Details Russian, Chinese AI-Uplifted Ops on Claude
TL;DR
- In Russian GTG-20006 operations, AI agents ran the full attack cycle; humans supervised rather than operated reconnaissance, exploitation, and exfiltration.
- Alibaba-linked operators harvested 151 million Claude exchanges in the largest documented illicit distillation attack, targeting direct capability gains for Qwen models.
- GTG-20006's malware auto-rebuild loop ran 130 days, iteratively evading detection signatures and inverting the cost burden onto defenders.
Anthropic's September threat intelligence report covers activity the company disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Running through it is a leveling finding: "AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators."
A Russian espionage cluster the report tracks as GTG-20006 ran AI-assisted operations against Ukrainian, European and diplomatic targets. Anthropic writes that its investigation "identified more than 20 distinct organizations targeted in the actor's operational planning, reconnaissance, and live operations." A separate Chinese-speaking group, GTG-10007, likely residing in Changsha in China's Hunan province, was aimed at roughly fifty organizations spanning education, retail, energy, finance and manufacturing.
Influence operations dominate the report's scale numbers. Anthropic details "nine of those cases. They originated in Russia, Iran, Turkey, and across the Gulf, South Asia, Africa and Europe, and targeted audiences on six continents." One French-registered outfit ran approximately 70 fabricated news websites that published at least 8,913 articles in about 20 languages. An Istanbul-based operation ran roughly a thousand fake X/Twitter accounts targeting all 222 Malaysian parliamentary constituencies.
The AI supply chain surfaces as its own target category. A financially motivated Russian-speaking actor, GTG-50020, compromised an AI vendor's evaluation sandbox and hit around thirty AI companies in four days, seeking access to a pre-release Claude model — though, the company adds, "the actor never compromised Anthropic's own systems." Actors linked to ShinyHunters, meanwhile, harvested API keys from application repositories and cloud metadata endpoints and resold them.
For investigators, Anthropic states the takeaway plainly: "sophistication has stopped being a reliable signal of who is behind an operation." The report lands during a run of misuse disclosures from the company; our tracker logged Anthropic detailing four Claude cyber incidents and inviting METR to audit its detection work earlier the same week, one of 334 Anthropic stories we've logged in the last 90 days.
What others are reporting
-
Al Jazeera Read →
International news framing leads with the Yemen GTG-87001 missile case, positioning Claude as a weapons-engineering substitute for state actors in active conflict zones.
The operators used Claude 'in place of human software engineers' to write missile-guidance and flight-control software.
-
TechNode Global Read →
China-focused outlet surfaces a previously unreported Southeast Asian maritime infrastructure target within the Midnight Blizzard campaign, extending its known victim geography.
AI moved beyond assisting human hackers to orchestrating reconnaissance, exploitation and data theft
-
Cyber Kendra Read →
Security-specialist framing leads with the GTG-20006 auto-rebuild loop, arguing static signature defenses are structurally obsolete against AI-enabled adversaries.
Capable adversaries can now close the loop, bypassing traditional security detections faster than defenders can develop
-
FoneArena Read →
Most granular operational coverage, listing GTG codes across all seven harm domains and naming the 151 million exchange harvest tied to Alibaba Qwen improvement.
Large language models are increasingly being embedded into autonomous, multi-agent frameworks that can execute complex tasks at machine speed.
Shared on Bluesky by 18 AI experts (top 5 by trust)
-
>the houthis were trying to use claude to build their rocket guidance system just get me off the fucking ride www.anthropic.com/threat-intel...
View on Bluesky →
Originally reported by anthropic.com
Read the original article →Original headline: Anthropic Threat Report Disrupts Bio-Weapons Plots, Chinese Distillation and Russian Cyber Ops on Claude