AI工具Score B (56)

Detecting and countering misuse of AI: September 2026 - Anthropic

31 分钟前2 viewsSource: anthropic.com
Detecting and countering misuse of AI: September 2026 Download report Cyber operations Read more Surveillance operations Read more Influence operations Read more Conventional weapons Read more Biological misuse Read more Scams and fraud Read more Illicit distillation Read more Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity. In this report, we share case studies from those operations and describe how malicious use of Claude has evolved since our previous threat reports in March , August , and November 2025. In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate. This report covers activity we disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Claude Haiku, Sonnet, and Opus models were used. None of the misuse cases involved the use of Claude Fable or Mythos-class models, with the exception of one illicit distillation case. The cases we share here aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date. We’re publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer. The threat actors covered in this report include suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals. The cases range from a network of fake dating apps designed to defraud users to surveillance systems built to identify and monitor dissidents. Sophisticated and persistent threat actors continuously test our safeguards and try to circumvent the technical measures we use to detect and prevent misuse. We’ll continue to evolve our safeguards and coordinate with our partners to improve our ability to detect, disrupt, and prevent future misuse. We hope that the findings in this report will help other developers recognize similar patterns on their own platforms, give governments and civil society a clearer view of how emerging threats take shape, and strengthen collective defenses. AI-augmented cyber operations Cyber operations: From assistant to orchestrator Over the past six months, our Threat Intelligence team identified and disrupted a series of cyber operations in which threat actors used Claude. The actors included suspected state-sponsored groups, financially motivated criminals, and politically motivated individuals. This section presents some of those cases. Throughout these case studies, the report will reference Generative Threat Groups (GTGs). These are Anthropic’s internal designators for actors observed to be abusing AI. The report also attempts to measure uplift, a term we use to describe the AI capability boost, or how much more harm was caused with AI versus without AI. We view uplift through the lens of speed, scale, and depth, and attempt to determine how an actor’s adoption of AI meaningfully impacts each of these traits. Many commentators focus on the risk of AI developing exploits at scale. While this is a danger, the risk from AI adoption is more pronounced across the cyber kill chain, where adversaries can operate faster, across a broader and deeper surface area, with fewer resources. The cases span the period from December 2025 through August 2026. In all cases, Claude Haiku, Sonnet, and Opus models were used; no malicious activity was found on Claude Fable or Mythos (which has a series of safeguards in place that greatly reduce its ability to perform harmful cyber tasks). In each case we disrupted the activity involved, strengthened our AI safeguards based on what we learned, and shared intelligence with authorities and industry partners where appropriate. In the following report, we begin by discussing the key trends that we’ve observed in these cyber operations, then move to reporting the case studies and how they highlight those trends. Trends Sophisticated attacks no longer require sophisticated attackers The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators. In the case studies we report below, a hacktivist using stolen API keys, disparate financially motivated individuals, and a state espionage operator each sustained multi-victim campaigns that, even just a year ago, would have required many skilled operators and specialist knowledge. For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation. Every layer of offensive operations has been uplifted by AI, from reconnaissance and tool development to data processing and exploitation. An example of this uplift in capabilities is documented in case study GTG-50014 (described below). The net effect of this uplift in capabilities is access to an increased breadth and depth of knowledge, which in turn drives increased speed of capability development and implementation. In November 2025, we documented an operating model used by a suspected state-sponsored campaign to carry out autonomous attacks. That operating model has now proliferated across every class of actors we investigated. Publicly available offensive agent frameworks, like PentAGI , reproduce much of the same scaffolding for anyone who downloads them. This scaffolding effectively automates each step of the cyber kill chain. The operators behind observed cases range from state services to lone individuals, across a widening set of countries. An example of this adoption of AI-enabled kill chains is documented in case study GTG-20006. As models continue to evolve and improve, we assess that more actors, from lone wolves to organized entities, will continue to adopt AI frameworks to enable more sophisticated cyber attacks at greater speed and scale. AI’s role in cyber operations has become increasingly autonomous A majority of the operations described in this report were enabled by AI via direct execution or orchestration. The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration. Humans remained in the loop by setting the targets of attacks and reviewing exfiltration. An example of this trend is GTG-20006. This actor developed an AI-assisted workflow that automatically rebuilt and re-deployed their toolkit if it was detected by security products. GTG-20006: Russian espionage Historically, cyber espionage actors have followed a pattern of developing and deploying custom toolkits designed to evade detections. Actors would use these tools until defenders identified and built signatures to detect and block them, and there would then begin a new cycle of evasion and detection. Robust defenses and detections therefore created increased costs for adversaries. Now, however, the adoption of AI threatens to quickly and easily subvert defenders’ ability to impose costs on adversaries via static detections alone. GTG-20006 is an actor who has increased their speed by automating their operations using AI. Our attribution is consistent with public reporting linking the actor to Midnight Blizzard. One of the operators is a Russian speaker using the handle “JackPoterz” whose tradecraft and targeting are consistent with Russian state-nexus espionage. They ran operations attacking military intelligence targets in Ukrainian and European governments, as well as diplomatic and defense organizations and individuals connected to US foreign policy. We observed GTG-20006 operate through customized AI-driven workflows that automated much of their operations from development, infrastructure acquisition, phishing, persistence through command and control, to data exfiltration. GTG-20006 employed a custom toolkit composed of two families of Windows-based implants, a mobile exploitation kit, a credential stealing tool that targets browser password stores, a phishing platform designed to mimic priority targets like government organizations, and an administrative console used to manage compromised accounts. Each of these tools was managed and re-tooled as needed during the cyber operations through AI-assisted workflows. The actor also used AI to monitor how well their tools evaded detections from known security defenses. If their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections. The agents were designed to continue iterating on GTG-20006’s toolkit until it was undetected. At that point, the tools were staged for live operations from disposable hosting servers where victim traffic was directed to retrieve the malware during their many cyber operations, including phishing, ClickFix , and DNS hijacking schemes. The actor also used AI to drive their phishing operations. They developed AI-driven workflows to research then register domains and then configure the hosting infrastructure used to send phishing emails. Additional workflows were developed to send the emails and monitor the C2 channels for successful compromises. The human actor engaged primarily to modify Claude Code skills that drove the workflows when they needed to be refined. Our investigation identified more than 20 distinct organizations targeted in the actor’s operational planning, reconnaissance, and live operations. They included government ministries, defense and intelligence bodies, embassies and diplomatic missions, think tanks, and defense-industrial companies, concentrated in Ukraine and Europe but extending to the Middle East and maritime related government agencies in Asia. A common theme of the targeting was Ukraine and military drone technology providers and supply chains. Exceptions included a Southeast Asian government entity relating to maritime shipping and tracking, and a North African government technology authority. Cyber operations The most commonly recurring targets were members of the Ukrainian government, military, and diplomatic staff. The actor scanned email services and remote access systems across more than two dozen Ukrainian government organizations. A secondary recurring target for theft was drone supply chain technology. The actor bulk-exported the mailboxes of at least two drone component manufacturers, targeted a military drone maker, and stole a complete proprietary software development kit for a drone vision system. They spent several days reverse-engineering the drone’s vision system, recovering its product architecture, its hardware bill of materials, its supplier dependencies, and details of an unannounced product. Military drone control and AI vision-related firmware appeared to be of particular interest. Not all targets were direct: to reach their targets indirectly, the actor compromised at least three hospitality vendors that operate hotel guest WiFi. They used compromised admin credentials to modify DNS records so that they pointed to services owned by the actor (a technique known as DNS hijacking). Guests of hotels using the compromised vendors who connected to the hotel WiFi had their traffic, device identifier and IP address sent to the actor’s servers. At that point, ClickFix -style lures were staged to deliver Windows, Android and iOS malware to the victim’s device. The actor was able to use a combination of guest information stolen from the hotel management systems with the data stolen from individual guests’ devices to focus additional targeting efforts. Particular targets of interest were individuals associated with Ukraine, including government officials and drone manufacturers. Note that in July 2026, Microsoft Threat Intelligence published a report on the method of theft and malware delivery used here, which they referred to as CaptiveCrunch . The actor also took over victims’ WhatsApp accounts, using a platform of headless browsers to link victim accounts as companion devices. In part by using the WPPConnect open-source WhatsApp automation library, the actor’s configuration suppressed read receipts so victims would not notice while it bulk-exported Russian and Ukrainian language conversations. At least two former high-level Ukrainian officials were targeted in this way. The actor also targeted surveillance platforms. They found authorization flaws in the application interface of camera streaming services, and from there they enumerated users and harvested tokens that granted them access to the victims’ live camera streams. The same actor also conducted an intrusion of a North African government technology authority. They stole credentials to a VPN appliance, and used them to take over the organization’s central account server. This allowed them to exfiltrate its full credential database: more than 300,000 national identity records, and the commercial registry data of more than half a million companies operating in the country. The actor continued to develop a cloud email espionage platform that in part used “Embassy Kit,” the actor’s framework for managing device code phishing, to operate a Microsoft 365 token theft campaign. This platform, which was used to target diplomatic and government personnel, resulted in the access and exfiltration of mail records from at least eight organizations including a national prosecutor office, a military education institute, and a regional intergovernmental organization. Windows credential stealers were delivered via fake update-themed social engineering lures, alongside companion payloads with full remote access capabilities. These payloads were designed to freeze the victim machine’s security updates, meaning that new malware detection signatures published by security vendors would not be retrieved or run on the victim’s machine. The actor used AI at every point in their operations: Reconnaissance: The actor used AI to fingerprint email and remote access systems and to harvest information from public sources, building target lists for phishing. Initial access: The actor used AI to build and operate the platform that ran these cyber intrusion campaigns. The campaign’s primary access technique was a form of device code phishing that abused legitimate sign-in flows for cloud email services (for further details on device code phishing see this post from Microsoft .) The actor used AI to set up the phishing infrastructure and the exploitation tooling, and executed portions of the intrusions directly including running commands against victim systems, harvesting credentials, and moving laterally through networks under the actor’s direction. Collection and exfiltration: The actor used AI to perform the extraction and organization of hundreds of gigabytes of stolen data. In some cases, exfiltration was achieved via bulk exports from compromised mailboxes. Maintaining access: The actor used AI to assist in maintaining access to compromised accounts and tenants by automating the registration of actor-controlled devices into the victim organization’s tenant. In on-premises environments, the actor used AI to monitor the stealth and persistence of their implants. When their implants were flagged by security products, the actor used Claude to systematically identify, modify and redeploy the detected artifacts. The result of the above is that AI has inverted the cost back onto defenders. Previously, defenders might have been able to slow an attacker’s operational tempo via the deployment of a new detection. Now, at least in theory, capable adversaries can “close the loop,” bypassing traditional security detections faster than defenders can develop and deploy them. The actor’s malware included the following: Windows malware: PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc; Android malware: GiftDrop, a rebranded GiftsExpress Android surveillance RAT; iOS malware: DarkSword, an iOS exploit chain. Indicators of compromise ms365-live[.]com teams.ms365-live[.]com m365-owa[.]com owa-ms365[.]com ms365-device[.]com mslivetest.duckdns[.]org my-invite[.]org chamber-ua[.]org chathamhouse[.]eu ukrinform-share[.]net 104.145.210[.]184 31.57.243[.]154 statistic-ms[.]live static-ms[.]live 104.194.151[.]133 ad-g[.]org 104.194.159[.]55 docs-viewer[.]org 144.172.114[.]192 wa-connect[.]eu mygreatmarket[.]org mygreatmarket[.]com 213.145.86[.]112 2.26.53[.]194 cdncounter[.]net static.cdncounter[.]net stuseamandesilt[.]org api.stuseamandesilt[.]org cdn.stuseamandesilt[.]org update.stuseamandesilt[.]org itechx[.]tel pdfviewer2024.b-cdn[.]net meridian-protocol[.]org meridiangroup-corp[.]com projectnightcrawler[.]dev metricwave[.]org mgsend[.]org 148.135.195[.]111 185.198.234[.]26 185.198.234[.]101 149.54.42[.]106 104.194.149[.]228 38.146.28[.]132 38.146.28[.]75 wa-meeting[.]com russianearabroad[.]com russianearabroad[.]org anna.manager@russianearabroad[.]net events@embassy-protocol[.]int msedgeupdate_v3[.]exe msedgeupdate[.]exe version[.]dll WUEngine[.]exe DiagHost[.]exe client_20260507093021_4286d211_x64[.]exe fix_network[.]apk be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593 GTG-50014: ShinyHunters smash-and-grab opportunists While some cyber threat actors may conduct targeted intrusions, seeking specific information for espionage or other purposes, others are less focused and deliberate in their operations. These opportunistic hackers have historically used broad-based scanning techniques to identify and probe unpatched internet-facing systems, before exploiting these vulnerabilities to compromise or take over the target systems. We’ve identified several advanced threat actors who used AI to uplift their opportunistic criminal activity, using Claude’s capabilities to accelerate their ability to rapidly scan, exploit, and take over target systems. Opportunistic attacks come in many forms: racing N-day patches for mass exploitation; rummaging through public container stores, code repos, mobile applications, websites and more looking for credentials, tokens, and API keys; mass scan and exploitation of vulnerable internet facing devices; the creation of service accounts on novice service providers with poor security to escape their containers; prompt injection of LiteLLM or OpenClaw deployments; and more. Many actors scour the internet for ways into networks and services, stealing data for sale and extortion and later reselling access. This was the case before AI. With AI, however, the pre-existing ecosystem of criminal cyber conduct has increased in scale and severity. With AI, diverse target environments are made trivial to understand and adjust to; unique and obscure configurations are made clear and exploitable. The old adage of “security through obscurity” is no longer viable in this new AI-assisted world: everything connected to the internet is a potential target for exploitation. Once actors gain access, they typically move straight to databases and look for customer data. If the target is a software-as-a-service (SaaS) provider, they often use the stolen data to access the end customers, and make extortion demands, telling the provider that all of their data and their customers’ data will be leaked or sold online if they do not pay. We identified and disrupted multiple clusters of financially motivated cybercrime activity conducted by operators suspected to be affiliates of the ShinyHunters collective, known for several large-scale data theft operations followed by pay-or-leak extortion demands. Although the affiliates appear disparate, and seem to be operating with their own tooling and operational workflows, analysis of their approaches and objectives shows that they are part of the same overall operation. Figure 1. The attack lifecycle shared by the clusters of suspected ShinyHunters affiliates that we disrupted, from harvesting credentials to extortion. One French-speaking operator going by the aliases of (MeowSHA | frkoo | blazespider) ran a distributed credential-harvesting pipeline across a fleet of 10 AWS EC2 workers. This pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog . Verified findings were routed in real time to a Telegram group organized into over 100 source types. A parallel GitHub organization email harvester fed a second stream of stolen GitHub Personal Access Tokens. These two credential pipelines supplied the initial-access credentials for the bulk of the confirmed breaches associated with frkoo. Operational security discipline by the operators was mixed. frkoo managed an EC2-based credential-harvesting pipeline, exposed their own EC2 staging IP, multiple Telegram bot tokens, a Squid proxy with hardcoded credentials and at least one public paste-site upload directly within a victim environment. They also registered a domain name impersonating the French national police, policenationale[.]cc (though we believe this served as branding for the criminal storefront rather than as a phishing lure). The subdomain autoshop.policenationale[.]cc served as the web frontend for the actor’s carding autoshop: a storefront selling stolen payment-card records (“fiches”) enriched with BIN lookups, full cardholder PII, and an interactive geolocation map of victim addresses. The shop was delivered to customers through a Telegram Mini App (@Soraki_Bot) backed by the actor’s “Soraki” platform, a PostgreSQL/GraphQL stack that also aggregated multiple French breach datasets (including a ~400,000-record telecom/ISP dataset with IBANs and BICs) into a searchable service. Across the collective of operators, during multiple target intrusions, a target’s AI API keys were stolen from the target’s enterprise software vendors. One of the stolen API keys was then used by the attacker for roughly three weeks to conduct secondary attacks, which targeted other organizations including compromising a French retail chain and probing a Web3 identity platform. They also continued post-breach attacks against a nonprofit victim, and in the case of frkoo, continued development work on their own carding shop that masqueraded as a French police department site. One of the more serious compromises was of a technology provider. The operators exfiltrated more than a terabyte of data, including hundreds of thousands of national identifiers and millions of payment card records, then staged the stolen material on a public website to pressure the victim into paying a ransom. At an airline, the threat actors accessed systems holding tens of millions of passenger records. At an energy company, the operators claimed that they could remotely control the charging current of electric-vehicle chargers installed in customers’ homes. Another affiliate appeared to specialize in supply-chain theft, where a company is compromised in order to reach the downstream data of their customers. After breaching a software-as-a-service provider, the operators used that foothold to extract data belonging to roughly 200 of the SaaS company’s downstream customer organizations. It then conducted a session-store dump containing over 2,100 Azure AD token sets spanning more than 40 corporate tenants in about 34 hours. AI agents performed nearly all of the work. In a different compromise, the actor leveraged Claude in a supply chain compromise of a software-as-a-service (SaaS) vendor to accelerate reconnaissance and to enable data exfiltration. The actor exploited a cross-site scripting vulnerability to gain access, escalated privileges, and ultimately exfiltrated data from thousands of downstream customer organizations. The actor used Claude by helping to identify, understand, and use developer and authentication APIs, create and convert privileged tokens, and build tools to enable bulk exports and cross-tenant data collection. Against a different target, the same attacker also claimed to have collected legitimate HackerOne bug-bounty payouts of $2,000 and $5,000 from two of the companies they infiltrated and extorted, treating BugBounty disclosure programs and intrusion as additional revenue streams against the same targets they were compromising. They also appeared to scrape HackerOne and BugBounty submissions as a form of reconnaissance during focused attacks on specific targets. This threat actor’s operational tempo was relatively consistent. One breach of an enterprise software company took only hours from first access to bulk data theft. Another compromise escalated from a single stolen developer token to full administrative control of a victim’s cloud environment in roughly three hours. This was followed by iteratively scraping internal datastores, and in the case of supply chain attacks, iteratively accessing and scraping the end customer’s data as well. We detected and banned accounts associated with the ShinyHunters associates, implemented measures to detect and disrupt future misuse from the actors, and engaged government authorities, industry partners, and victims to remediate threats posed by the actors. The use of AI during intrusions and data theft operations often resembles “ vibe hacking ,” wherein operators direct AI to achieve general goals like using a credential for an entity or retrieving data from a broad set of targets, then allow the AI to evaluate the environment, author and execute scripts, provide summaries, and repeatedly execute until the task is complete. Very often, the operator may not directly understand each target environment or the complexities of finding and accessing valuable information, instead deferring the specifics to the AI. Security practitioners use the phrase “living off the land” to describe attacks that use tools that are already present in the victim’s environment. The opportunistic hackers described in this section have applied the same principles to AI. The operators treated the AI supply chain itself as both a target and a resource. They stole AI API keys from multiple target environments and used them to provide additional AI compute. In every instance, the API keys involved were stolen from Anthropic customers’ environments. Anthropic’s own systems were not compromised by this actor. We examine this pattern in detail in the section on the AI supply chain. Attack lifecycle and AI integration Figure 2. The attack lifecycle and AI integration. Sourcing and recon. Most intrusions began from compromised credentials. The actor also engaged in extensive scanning, vishing, phishing and domain spoofing operations to trick employees into giving access to systems. Figure 3. Sourcing and recon. Discover. Exposed access tokens were also discovered at industrial scale through a wide variety of automated scraping and mining projects. These included analyzing application binaries, code repositories and integrations, client side code, credential stores, container images, metadata endpoints, open storage and victim-deployed AI agents. An example of this is with one actor project that downloads all APK files from Google Play Store and searches them for exposed session tokens or other access mechanisms that could be abused for access. Figure 4. Discover. Validate/qualify. Everything found is tested and qualified before use or resale, such as batch cloud key validation, purpose built login oracles, live replay against production, grading for resale value, and offline cracking. Figure 5. Validate/qualify. Expand in-victim. One working credential is used to expand access within the victim, and used for things like whole-cluster secret dumps, admin-token amplification, CI/CD injection, database and session-table dumps, mining dumps for signing keys, and vendor-OAuth fan-out to every downstream tenant. Figure 6. Expand in-victim. Exfil channels. Material moves out over six channels: consumer cloud storage, a private NAS over mesh-VPN, Telegram bot streams, staging inside victim clouds, C2 channels, and plain bulk API pulls. Figure 7. Exfil channels. Warehouse. Loot is warehoused for reuse and sale: a self-hosted estate that re-serves stolen databases, loot trees for each victim, a Telegram warehouse that also serves as the storefront, and working key stores. Figure 8. Warehouse. Mint/persist. New credentials and durable access are minted so the operation outlives rotation: cloud API keys in victim accounts, platform developer keys, forged sessions and 2FA codes, network backdoors. Figure 9. Mint/persist. Monetize. Monetization: resale channels and key pools, direct financial theft, extortion over the stolen data, dual-hat bounty income, and bulk data held for leverage. Figure 10. Monetize. Common workflows observed Figure 11. Common workflows observed. Indicators of compromise updatebeacon.duckdns[.]org esvfecawvjmchjslqyemho2fiduc59wzn.oast[.]fun soraki-proxy.20245aad98d27b1b1a2f0f103e1d7ee0.workers[.]dev soraki[.]cc soraki[.]work policenationale[.]cc emailsecure[.]email mozilla[.]ws signin-1psswoord[.]com on-pssword[.]com ari-chain[.]com arichain[.]network bitmart-mystery[.]com defi-claim[.]xyz service-infos[.]info 0x0[.]st // Exfiltration file uploads via curl Exfiltration locations fuckyoubasil[@]s3.ap-tokyo.megas4[.]com https[:]//s3.eu-central-1.s4.mega[.]io/fuckyoubasil/ https[:]//s3.ap-tokyo.megas4[.]com/<victim-name> <victim-name>.s3.ap-tokyo.megas4[.]com Telegram group IDs Indicator Type Description -1003893854338 Telegram group/chat ID Private group named “ClintonHog.” Received the first wave of verified stolen credentials from the actor’s APK secret-scanning pipeline. -1003311614569 Telegram group/chat ID Private group named “ChatMignon.” Primary exfiltration channel: 471 forum topics, one per secret-detector type, receiving verified stolen credentials in real time. 8632748474 Telegram bot account ID Bot posting pipeline findings into group -1003893854338 (“ClintonHog”). 8664033117 Telegram bot account ID Bot posting pipeline findings into group -1003311614569 (“ChatMignon”). 8628746407 Telegram bot account ID Bot delivering AWS SES credential-validation results directly to the operator’s user account. 8709258476 Telegram bot account ID Bot delivering AWS SNS SMS-abuse test results directly to the operator’s user account. 8179098353 Telegram user ID Operator account receiving the SES/SNS bot output. Table 1. Telegram group IDs. Attacker egress IPs IP Start Date End Date 162.128.129[.]106 2026-02-20 2026-03-10 195.178.110[.]131 2026-03-12 2026-04-30 45.148.10[.]242 2026-04-06 2026-04-27 92.118.39[.]3 2026-04-10 2026-04-19 185.65.134[.]246 2026-04-19 2026-05-04 185.65.134[.]199 2026-04-19 2026-04-28 193.32.249[.]161 2026-03-21 2026-04-18 193.32.249[.]164 2026-04-18 2026-05-06 193.32.249[.]170 2026-03-20 2026-04-06 104.36.50[.]54 2026-04-24 2026-04-24 104.193.135[.]207 2026-04-05 2026-04-05 2a04:cec0:1185:34f2:a150:7081:caed[:]448e 2026-04-06 2026-04-07 2a01:e0a:2e2:aa40:b15d:5d28:6f4a[:]8d53 2026-04-20 2026-04-21 91.171.138[.]169 2026-04-19 2026-04-21 176.177.12[.]62 2026-04-19 2026-04-20 Table 2. Attacker egress IPs. GTG-10007: Exploit foundries and autonomous attack frameworks Historically, cyber operations have been limited in their scale and impact by two key constraints: the supply of working offensive exploits, and the supply of skilled operators capable of deploying those exploits. We have identified multiple threat actors who have effectively established automated exploit foundries with AI. In doing so, they have designed and implemented autonomous workflows by which they can direct Claude to conduct vulnerability and exploit research agentically around the clock. Across multiple instances, we identified Claude being used to meaningfully accelerate the pace of vulnerability research, testing, and exploit design. We identified and investigated a sustained espionage operation, tracked as GTG-10007, conducted by Chinese-speaking operators likely residing in Changsha in China’s Hunan province. Two of the operators were identified as undergraduate students at a Chinese university in Hunan studying curriculum in a School of Computer & Communication Engineering. One had a prior internship at a Chinese security company, Sangfor, and was actively interviewing for a role at a different Chinese security company, QiAnXin, for an offensive cyber operations role. Multiple operators within this group used Claude as the engineering and orchestration layer of a coordinated offensive program involving a variety of tasks: intrusion attempts against production systems; reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia; a standing vulnerability-research and exploit development effort against major endpoint-security products; malware development; and an intelligence-collection platform. Notably, a team ran parallel workstreams that had shared tooling and infrastructure bases and persistent campaign records that maintained context between working sessions; it also had collection and vulnerability research capabilities that kept operating while its owners were away. The actor targeted roughly fifty organizations, spanning education, retail, energy, technology, healthcare, finance, manufacturing, as well as multiple government agencies globally. The actor compromised an education-technology company, extracting hundreds of megabytes of bulk student personal data from the company’s cloud storage. They also gained access to a retail company’s production systems, reaching internal hosts and demonstrating their ability to modify the live environment. Finally, they targeted a Southeast Asian government agency, retrieving citizen records including names, phone numbers, and home addresses. The group maintained an autonomous vulnerability research program. Its centerpiece was sustained research against a major security product (of a class of software deployed specifically to detect intrusions) which produced multiple previously-unknown vulnerabilities that were validated by the actor in their own lab environment. The same research effort produced working exploits for several families of network and security appliances. In a separate workflow, the actor was observed conducting cyber operations involving exploitation attempts against those same appliances owned by multiple government organizations globally. We banned accounts associated with the actors and deployed additional monitoring to detect and ban related activity. Distinct workstreams were run in parallel. One workflow conducted cyber operations involving exploitation and intrusions, another performed foreign-government reconnaissance, another reverse-engineered security products in search of new vulnerabilities, another developed and tested custom malware, and another built and maintained collection infrastructure. Autonomous espionage The operators routinely ran “agent swarms,” where a lead AI agent decomposed reconnaissance and post-exploitation work and dispatched it to many subagents running in parallel. The operation maintained persistent campaign memory. Target lists, harvested credentials, engagement state, and standing instructions were saved across working sessions, so each session could be resumed mid-campaign with the program’s accumulated context. The cluster built and operated an intelligence-collection platform that ran unattended bulk harvesting of open-source material aligned with state intelligence priorities (including publicly accessible military doctrine and official publications, regional defense reporting, and policy sources). Appliance zero-day research: Binary reversing and exploit-development loop The following is a brief description of the loop the actor used in its zero day exploit foundry operations. The actor configured autonomous AI-driven workflows to target appliance firmware and binaries. The workflow started with loading firmware and binaries into a decompiler through a tool server. An assistant agent surveyed the image, and walked decompilation and cross-reference chains (over thousands of decompile calls, with back-to-back decompile sequences dominating the call stream). It then formed vulnerability hypotheses against a knowledge base it curated over time and prior proof-of-concept lookups. From there, the workflow tasked the writing of exploit code against those hypothesized vulnerabilities, and tested the code against lab copies of the target product. The workflow iterated over edits of the exploit code until success, at which point the chain landed in the operator’s private exploit portfolio. Vendor firmware images were obtained and decrypted with a purpose-built skill, unpacked into root filesystems, and loaded into disassembler and audit sessions. Vulnerability patterns were hunted component-by-component with parallel agents instructed to require evidence and use project memory. One workflow iterating continuously on network appliances yielded more than a dozen possible zero day findings in a single month. Figure 12. Appliance zero-day research: binary reversing and exploit-development loop. Attack-surface and OSINT reconnaissance loop Other AI workflows ran continuously to conduct reconnaissance. This workflow took input for scan scopes seeded from target verticals and ran through an asset search engine via a dedicated tool server and bundled probing tools that fingerprinted the results. The identified exposed surface was mapped and entry points were qualified against known vulnerabilities. Each round’s findings fed a persistent project memory, and expanded the target set for the next sweep. The actor used the framework to target multiple foreign government and diplomatic agencies, in addition to over a dozen domestic Chinese companies. Figure 13. Attack-surface and OSINT reconnaissance loop. Autonomous collection-fleet loop A fleet of thirteen standing collection AI agents ran on a scheduled job to identify and download content from target websites, including publicly accessible US military and government sites like contract postings, and social media personas. The workflow did this through layered crawlers, anti-bot bypass techniques, and commercial proxy exits. An adjacent pipeline summarized and scored the retrieved content with an intelligence report-styled framing. From there, the workflow digests were delivered to a distribution portal. Figure 14. Autonomous collection-fleet loop. Hands-on intrusions The operator engaged primarily in development, workflow output consumption related areas and during intrusion events produced from the autonomous exploitation workflows or in cases where access was obtained through weak or harvested credentials and exposed consoles. With access to internal networks, the AI assistant enumerated hosts, escalated via credential reuse and exposed management surfaces, harvested credentials and data stores, and staged material back to operator infrastructure then pivoted to the next host on what was harvested. Despite targeting entities globally in AI workflows, the actor concentrated hands-on efforts exclusively on domestic China victims. AI supply chain as target, loot, and attack compute Access to the uplift granted by AI is highly sought after by malicious actors and the broader criminal economy. Access to AI in the form of compromised API keys, session tokens, and devices has increasingly become the sole objective of multiple criminal groups. These groups then often sell that access through brokers, which often feed into fraudulent AI reseller networks that rotate in new stolen API keys and session tokens until they exhaust their usage. Malicious actors also use or purchase these stolen API keys and session tokens from brokers for their cyber attack operations. A criminal AI supply chain has established a range of pathways to farm victim API keys and session tokens. One such approach involved masquerading as real AI service providers to deliver malware. The actor stood up websites that purported to be an intermediary service between multiple AI models and offered discounted access to frontier AI models. Site visitors would be compromised in a variety of ways, the most persistent one was by having the victims download and install malicious client side applications often spoofing as popular AI harnesses including Claude Code but were in fact credential harvesters that would gather all of the victim’s credentials and authenticated session tokens on their device and send them to the attacker. That included any AI related session tokens or API keys on the victim’s device. As the victim’s API keys or account may be identified as compromised and reset, the credential harvester continued to identify any new sessions on the device and sent them to the actor. In so doing the actor effectively mimicked the same fraudulent reseller networks they were supplying compromised credentials to but instead used this scheme to have victims continuously feed their credentials to the attacker and subsequently be sold to the fraudulent resellers. GTG-50021 is a group that engaged in similar activity. They are a Russian and Ukrainian speaking group, one of whom went by the alias “kl1zy.” They ran a fraudulent AI reseller operation offering cheap Claude access—which turned out to be neither cheap nor actually Claude. Customers believed they were buying discounted Claude access, but their traffic was in fact silently proxied to a different AI model while the reseller’s tooling installed a credential harvester, stealing their Anthropic account credentials and selling them onward to other AI proxy resellers for malicious use. GTG-50021 indicators of compromise awstore[.]cloud kiro[.]cheap sys-tools[.]cfd aws-us-east-3[.]com holdboost[.]store deltaclient[.]xyz iymkjuzymkapovrntoxy.supabase[.]co There are also groups that attempt to target the AI ecosystem and supply chain itself, seeking to gain access to restricted models via AI vendors, evaluators, and trusted access programs. For example, multiple actors were observed compromising AI wrapper services’ implementation of LiteLLM—they used prompt injection to exfiltrate the production API keys used in their cloud-hosted container environments. Fraudulent resellers have increasingly been supplied by compromised access. Most commonly, this comes from legitimate customers who have inadvertently exposed their API keys and session tokens in their products, applications and public code such as GitHub, mobile application install files, Docker containers, websites, and chatbots. Malicious actors are constantly mining these sources for exposed keys and analyzing them for authentication abuse vectors. Operators who obtain AI credentials gain three things at once: Loot : Stolen keys and accounts have resale value in established markets; Compute : Having the credentials means that their attack workloads can run at someone else’s expense; Cover : The activity is attributed to the credential’s legitimate owner. A hacktivist campaign (described later in this report) ran for a month entirely on stolen API keys. ShinyHunters affiliates, on obtaining a victim’s AI keys during an intrusion, switched their own attack workloads onto the victim’s keys. GTG-50020, after compromising an AI vendor’s evaluation sandbox, took its production keys first. AI API keys and session tokens are targets; the integrations customers build around AI such as sandboxes, proxies, and resellers are part of the attack surface. Organizations should treat AI keys and agent integrations with the same level of seriousness as they do production credentials—because attackers treat them with the same level of seriousness, too. AI access should be purchased only through authorized channels. An alleged discount that requires routing traffic and credentials through an unknown intermediary introduces tremendous risk to user data and systems. GTG-50020: From hotel bookings to the AI supply chain GTG-50020 is a Russian-speaking, financially-motivated actor who had historically conducted intrusions against hotel booking and financial technology platforms. In one intrusion, they exfiltrated roughly 26 gigabytes of data from one victim and sought payment in extortion attempts (or from selling the data on darkweb forums) of between $1.5 and 2.5 million. They then redirected the same tradecraft towards the AI industry. By injecting malicious instructions into an AI vendor’s automated evaluation sandbox, the actor caused the sandbox to hand over the credentials it held—including the production AI API keys from multiple providers belonging to that vendor. Those stolen keys were then abused by the actor: they continued their intrusion attempts against the vendor and other unrelated targets simultaneously. In effect, when they obtained the target’s API keys, they automatically switched to using the victim’s keys instead of their own. A follow-on campaign run from the same infrastructure attacked roughly thirty AI companies in about four days with similar techniques. They identified one successful attack path and repeated it against all thirty targets, adapting slightly to account for differences across the targets. The actor’s stated goal, pursued across more than a dozen avenues, was access to a pre-release Claude model. The actor never gained access; every attempted path failed. In all of this, the keys involved were customers’ keys stolen from customers’ environments. The actor never compromised Anthropic’s own systems. This case is the clearest demonstration to date that the AI supply chain has become a deliberate criminal target. The actor pursued AI vendors for their production API keys, and had an explicit ambition—which, to be clear, was never realized—to gain access to pre-release AI models. Human-directed AI pentest loop The operator maintained a per-target scope file that launched a custom workflow to delegate work to parallel reconnaissance and exploitation agents. The agent’s findings were re-tested for working access; if viable, they were merged into an incremental report. This workflow iteratively looped against the next target domain. Figure 15. Human-directed AI pentest loop. Autonomous exploitation pipeline The actor used a containerized open-source pentest platform fronted by a local model gateway. It was aimed at a target’s web applications. Worker agents ran injection, XSS, authentication-bypass, and SSRF testing without human supervision, collecting potential findings and credentials into the operator’s workspace. This loop was run with exploitation enabled against production systems, meaning it both attempted to identify vulnerabilities and actively exploit them for access in the same workflows. Figure 16. Autonomous exploitation pipeline. Fraud account factory Residential proxies and antidetect browser profiles were provisioned, after which bots drove signup flows on exchange and marketplace targets. Commercial CAPTCHA-solving services, automated inbox polling, and automated identity-verification steps defeated onboarding controls, and the resulting verified accounts were banked for later operations. Figure 17. Fraud account factory. KYC interception cloak The actor also engaged in credential theft and phishing campaigns. Victims were directed to lookalike verification domains whose reverse proxy relayed the real know your customer (KYC) flow, so the victim completed genuine identity verification while the operator captured the verified session and documents from the proxy relay in the middle. The captured session was then used by the actor from their machines to access the target service and data. Figure 18. KYC interception cloak. Attacker egress IPs IP Start End 141.133.125[.]208 2026-05-21 2026-05-23 167.250.111[.]136 2026-05-23 2026-06-03 178.16.54[.]141 2026-05-21 2026-06-16 37.27.103[.]22 2026-05-26 2026-06-13 194.163.183[.]216 2026-05-23 2026-05-24 202.66.167[.]230 2026-05-21 2026-06-04 146.103.101[.]253 2026-05-21 2026-06-13 146.103.97[.]169 2026-05-21 2026-05-25 Table 3. Attacker egress IPs. GTG-50029: Hacktivists targeted European political and affiliated entities AI has helped to close the capability gap turning low-level “hacktivists” into advanced persistent threats. As demonstrated repeatedly throughout our case studies, AI capabilities raise the baseline as well as reduce the resource requirements for offensive cyber operators. In this section, we provide details of a hacktivist campaign we investigated and disrupted, in which small well-motivated operations were able to achieve significant goals due to the integration of AI in their operations. In the spring of 2026, a single French-speaking actor was observed using Claude to target European political parties, media, think-tanks, and the SaaS providers used by these organizations. This actor built their own custom Rust-based scanner designed to scan and validate public containers for exposed API keys. Once keys were validated, the actor’s tool was designed to rotate key usage across a local proxy layer. This enabled the actor to blend their traffic in with the traffic from the legitimate owner of the stolen API keys. As we saw in the case studies above, access to an exposed API removes the barrier to entry for a rogue actor. GTG-50029 provides another example of an actor embracing the use of AI across the kill chain. The actor used AI’s agentic coding skills in a framework that helped it manage sub-agents; the sub-agents were themsel

Read the full original article:

anthropic.com