← BACK TO FEED
cybersecuritystate-sponsored hackingAI misusedisinformationsurveillance

Anthropic's Claude Has Been Weaponised By State Hackers, Fraudsters, and Surveillance Vendors Alike

Anthropic has published a report revealing that its Claude AI models are being exploited by a wide range of malicious actors — including state-sponsored hackers, cybercriminals, and commercial spyware vendors — for purposes such as cyberattacks, mass surveillance, weapons development, and influence operations. The company introduced the term "Generative Threat Groups" (GTGs) to categorise these actors, highlighting cases involving Russian, Chinese, Iranian, and other operators using Claude in increasingly autonomous, multi-agent frameworks to conduct reconnaissance, credential harvesting, and data exfiltration at scale. Anthropic warned that AI has effectively erased the resource gap that once separated sophisticated state actors from individual operators, while expressing hope that sharing these findings will help governments and the industry develop stronger safeguards.

Anthropic has published what amounts to a 154-page confession that its Claude models have been systematically abused by a fairly alarming cast of characters: Russian and Chinese state-sponsored hackers, commercial spyware operators, influence-for-hire firms, and lone operators running election manipulation schemes from their bedrooms.

The report, covering activity between December 2025 and August 2026, groups the offenders under the banner of Generative Threat Groups, or GTGs. The range of activity spans cyberattacks, weapons development, mass surveillance infrastructure, and coordinated disinformation. It is, to put it mildly, a lot.

One of the more technically sophisticated cases involves GTG-20006, a Russian state-sponsored actor with overlapping tradecraft to Midnight Blizzard (APT29, Cozy Bear, take your pick). This group used Claude not as a chatbot but as a component inside multi-agent pipelines executing reconnaissance, exploitation, and data exfiltration with a human making the targeting calls but Claude doing much of the legwork.

Then there is GTG-50014, a French-speaking operator suspected to be affiliated with the ShinyHunters collective. This group ran a distributed credential-harvesting operation across ten AWS EC2 workers, pulling down 1.8 million Android APKs from various app stores, scanning them for hard-coded secrets with TruffleHog, and routing findings to a Telegram group. A separate ShinyHunters affiliate focused on supply chain theft, working through compromised SaaS vendors to reach downstream customers.

GTG-10007 is a Chinese-speaking group, some members apparently undergraduate students at a Chinese university, who used Claude to probe foreign government networks across the Middle East, Europe, and Southeast Asia, develop exploits for endpoint security products, and build an intelligence-collection platform designed to bulk-harvest open-source material aligned with Beijing's priorities. Around 50 organisations across education, healthcare, finance, energy, and government sectors were targeted globally. The group also ran an autonomous vulnerability research programme hunting for zero-days in network appliances.

On the financial crime side, GTG-50021 ran a fraudulent Claude reseller scheme, taking customers' money for cheap API access, silently proxying their traffic to a different model, and harvesting their Anthropic account credentials to sell to other proxy resellers. GTG-50020, a Russian-speaking financially motivated group, targeted roughly 30 AI vendors in a four-day window trying to steal API keys and gain access to pre-release models.

GTG-50029 is a single French-speaking actor who managed to exploit a previously undocumented WordPress reinstallation race condition to create a rogue administrator account without valid credentials, breach a political campaign management platform through an exposed search endpoint, and build a purpose-made doxxing tool called "fafsearch" for cross-referencing breach data. Web shells and a browser exploitation command-and-control framework also featured in this actor's toolkit.

The influence operation side of the report is similarly grim. GTG-54002 used Claude to churn out political content across roughly 70 fabricated news websites, traced back to LKM Company, a French digital advertising agency. GTG-24015 used Claude as an editorial desk feeding content into Sputnik Moldova, RIA Novosti, RT's English newsroom, and other outlets. GTG-34001 involved Iranian state-aligned accounts converting government intelligence bulletins into social media-ready content.

GTG-54006, linked to a single actor in Bangladesh's Gaibandha District operating through 29 rotating Claude accounts to avoid detection, generated fabricated Bengali-language news promoting the Awami League. GTG-84006, tied to PMOI/MEK and the National Council of Resistance of Iran, ran an influence operation targeting Iranian audiences globally by impersonating real activists.

The surveillance cases are perhaps the most disturbing. GTG-54009, assessed to be linked to Israeli-Singaporean commercial intelligence firm S2T Unlocking Cyberspace, used Claude to analyse and profile social media activity of users in Iran and the Persian Gulf. GTG-14010, a China state-aligned operation, used Claude to monitor over 100 WhatsApp groups and dozens of Telegram channels to track and profile Uyghurs in Syria, converting bulk conversations into structured Chinese-language data and flagging individuals vulnerable due to financial stress or family separation.

GTG-50027 used Claude to design Lakana 360, a national mass interception platform for Mali's state intelligence service capable of monitoring 25 million SIM cards across three mobile operators and generating dossiers on any phone number, including call records, texts, and voice calls.

GTG-34007, linked to Iranian paramilitary and domestic security agencies, built a government surveillance case management frontend, ran social network analysis across over 155,000 posts on X, and developed a malicious Firefox extension called "al-Najm al-thāqib" to harvest user identities from social platforms.

On the weapons development front, Anthropic says it blocked attempts by actors in northern Yemen to develop guided weapons, two China-based efforts to draft specifications for an anti-torpedo fire control system and build electronic warfare targeting software, and a Russia-based operation to engineer an autonomous first-person-view kamikaze drone swarm.

Anthropics's framing throughout is that it caught and disrupted all of this, which is worth taking with some scepticism given that a 154-page document detailing this volume of abuse is not exactly a ringing endorsement of prior safeguards. The company argues that AI providers now have threat-relevant visibility that governments lack, and that sharing this intelligence publicly helps inform policy and safety decisions.

What it also demonstrates, fairly conclusively, is that the gap between a well-resourced state operation and a single motivated individual with a credit card and a Claude account has narrowed considerably. That is not a comfortable place to be.

WATCH THE SHORT
READ NEXT
FBI Takes Down Chinese State Hacking Tools Used Against NASA, Senate, and DOERussian Intel Is Using Your CCTV Camera to Watch NATO Weapons ShipmentsSpain's Data Watchdog Gets First AI Agent Data Breach Report. Should We Panic?