[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDpUoJ20SdUXi9AuNLnmeUoISgfFRMjrsz5usQ-T1WP0":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"5da86ca9-8f9f-4b43-b23c-7cb5d88d3dd1","Claude Used to Automate Exploitation and Data Theft Across Multiple Victims","claude-used-to-automate-exploitation-and-data-theft-across-multiple-victims-0f8acc","Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial","Anthropic has issued a warning that its Claude AI models are being exploited by various threat actors, including state-sponsored groups and cybercriminals, for malicious purposes such as cyber attacks, weapons design, and mass surveillance. These \"Generative Threat Groups\" (GTGs) leverage AI to bypass skill and tooling gaps, enabling sophisticated operations like reconnaissance, exploitation, and data exfiltration. The report details specific campaigns involving Russian, Chinese, and French-speaking actors, highlighting AI-assisted exploitation, credential harvesting, and even fraudulent AI reseller schemes.","Anthropic warns of state-sponsored and criminal groups using Claude AI for cyber attacks.","Claude Used to Automate Exploitation and Data Theft Across Multiple Victims Ravie LakshmananSep 11, 2026Artificial Intelligence \u002F Cyber Operations Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals. \"The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators,\" Anthropic said. \"The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration.\" Among the notable cases highlighted by Anthropic is the development of an AI-assisted workflow by a Russian state-sponsored threat actor it calls GTG-20006, which shares tactical and tradecraft overlaps with a Russian advanced persistent threat (APT) group tracked as Midnight Blizzard (aka APT29 and Cozy Bear). Some of the other AI-enabled cyber campaigns highlighted by Anthropic in its 154-page report include - GTG-50014 (aka MeowSHA, frkoo, and blazespider), a French-speaking operator and a suspected affiliate of the ShinyHunters collective that ran a distributed credential-harvesting pipeline across a fleet of 10 AWS EC2 workers that mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, scanned them for hard-coded secrets using TruffleHog, and sent verified findings to a Telegram group. Another ShinyHunters affiliate that specialized in supply chain theft by compromising software-as-a-service (SaaS) vendors to steal data belonging to downstream customers, accelerate reconnaissance, and enable data exfiltration. GTG-10007, a Chinese-speaking operator likely based out of Hunan province, some of whom have been identified as undergraduate students at a Chinese university and have used Claude to conduct intrusion attempts against production systems, reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia, a vulnerability-research and exploit development effort against major endpoint-security products, and develop an intelligence-collection platform for bulk-harvesting of open-source material aligned with Beijing's priorities. The threat actor targeted about 50 organizations across education, retail, energy, technology, healthcare, finance, manufacturing, and government sectors globally. The group also maintained an autonomous vulnerability research program to produce working exploits for previously unknown vulnerabilities in network and security appliances. GTG-50021, a Russian and Ukrainian-speaking group that ran a fraudulent AI reseller operation offering cheap Claude access, only for customers' traffic to be silently proxied to a different AI model, while the illicit scheme installed a credential harvester to siphon their Anthropic account credentials and sell them to other proxy resellers for malicious use. GTG-50020, a Russian-speaking, financially-motivated actor that has historically targeted hotel booking and financial technology platforms but has since focused on the AI supply chain by stealing model provider API keys and unsuccessfully attempting to gain access to pre-release AI models. The threat actor is estimated to have targeted about 30 AI vendors in a four-day window using similar techniques. GTG-50029, a single French-speaking actor that used Claude to target European political parties, media, think-tanks, and the SaaS providers used by these organizations, including by exploiting a previously undocumented WordPress re-installation race condition that made it possible to create a rogue administrator account without valid credentials, as well as by abusing an exposed search endpoint to breach a political campaign management platform and siphon sensitive data. The threat actor has also been observed deploying web shells and a browser exploitation C2 framework against other targets. Central to the attacker's operation was a purpose-built doxxing platform named \"fafsearch\" that offered the ability to cross-reference individual breach dumps against exfiltrated data. \"At one end, actors used Claude conversationally: it acted as an engineering assistant in the creation of malware, phishing kits, and surveillance tooling,\" Anthropic said. \"Further along the spectrum, threat actors directed Claude to execute operations (such as running commands against victim networks, harvesting credentials, and exfiltrating data) with a human making each individual targeting decision (GTG-20006).\" \"At the far end, operations ran autonomously, with minimal human input or supervision: these included multi-agent frameworks conducting reconnaissance, exploitation, and theft against multiple victims, in parallel, for hours or days at a time (GTG-50014, GTG-50020, GTG-50029).\" The AI company said it also identified and took down a number of influence operations in which Claude played the role of a \"sub-editor or content creator\" to churn out content and run them at a scale beyond what low-resourced actors could have accomplished on their own. However, Anthropic emphasized that none of these efforts amassed authentic engagement and that they were disrupted before they could even build an audience. Some of the influence and surveillance campaign clusters flagged by Anthropic at a high level are below - GTG-04001, a Russian-speaking actor in Bangui that engaged in a foreign information manipulation and interference operation in the Central African Republic to amplify pro-Russia, anti-France talking points. GTG-54002, a commercial \"influence-as-a-service\" operation that used Claude to mass-produce and rewrite political content across about 70 fabricated news websites. The operation has been traced back to LKM Company, a France-based digital advertising agency. GTG-84005, a single account that used Claude to run a commercial election manipulation platform primarily targeting users in Malaysia based on political and social factors, such as their race and religion, by posing as a defensive cyber intelligence and counter-disinformation tooling outlet. The activity has been found to share links with BBS Bilisim Teknolojileri, an Istanbul-based technology company. GTG-24015, a set of four accounts that used Claude as an \"editorial and news production desk\" to distribute them via state media outlets like Sputnik Moldova, RIA Novosti, Sputnik en Español, Sputnik Africa, and RT's English-language newsroom. GTG-34001, a set of three Iranian state-aligned accounts that used Claude to shape public opinion, turn official government intelligence bulletins into tailored content, and disseminate the content across social media platforms. GTG-54006, a sustained, automated disinformation network that used Claude to generate fabricated Bengali-language news in Bangladesh and promote the country's Awami League party. The activity has been linked to a single actor based in Gaibandha District in Bangladesh via a set of 29 Claude accounts that were rotated to bypass platform limits and detection. GTG-84006, a distributed influence operation that targeted Iranian audiences across the world with an aim to impersonate real activists and engage in live political conversations. The activity has been linked to People's Mojahedin Organization of Iran (PMOI\u002FMEK) and the National Council of Resistance of Iran (NCRI). GTG-54004, an account used by a single actor to mass-produce Kenyan political content as part of what's suspected to be a domestic astroturfing campaign with a pro-administration bent. GTG-84002, an account used","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fclaude-used-to-automate-exploitation.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEiG0iCBQ4Eqxn0QOtvYZSysksPzr5fT0m8aLqNTa0a7Gcz3A5ikRt1oAenJwzo8rxcLERq54SNLtRvkYXKMTo0nMOmV8pWh4It3T0vP7q4J5Z23tdDkbBf3j7v317S7sQbBBbN6j6MuHusofo3qcbm2Y3DWT76gHp4Z1_En2QnJMCyEpvCo1sCcXoRZVw5-\u002Fs1600\u002Fclaudeai.jpg","2026-09-11T14:29:47+00:00","2026-09-11T16:00:29.069833+00:00",8,[18,21,24,27,29,31],{"name":19,"type":20},"Claude","product",{"name":22,"type":23},"Anthropic","vendor",{"name":25,"type":26},"Midnight Blizzard","threat_actor",{"name":28,"type":26},"APT29",{"name":30,"type":26},"Cozy Bear",{"name":32,"type":26},"ShinyHunters","839da5c1-3c34-47e2-9499-f7201640e3ac",{"id":33,"icon":35,"name":36,"slug":37},null,"AI Security","ai-security",[39,44,49,51],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":50},{"id":33,"icon":35,"name":36,"slug":37},{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]