Anthropic‘s Claude AI threat intelligence report, published on 10 September 2026, details how multiple threat groups, financially motivated criminals and state-sponsored espionage actors linked to Russia and China, abused its models across an eight-month window stretching from December 2025 to August 2026. The catalogue of misuse covers cyber operations, influence campaigns, surveillance, scams, biological and conventional weapons development, and model distillation.

One detail worth registering immediately: according to Anthropic’s own report, all confirmed malicious activity involved the Claude Haiku, Sonnet, and Opus model families. No harmful use was found on Claude Fable or Mythos. That is either reassuring or simply a function of which models were most accessible to attackers during the period.

ShinyHunters and the 1.8 Million APK Pipeline

The ShinyHunters collective features prominently throughout. An alleged French-speaking member using the handle ‘frkoo’ built a credential-harvesting pipeline distributed across ten AWS EC2 workers. The pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets using TruffleHog. Verified findings were routed in real time to a Telegram group organised into over 100 source types, according to Anthropic.

The same actor ran a separate automated process to harvest GitHub organisation email addresses and convert them into GitHub Personal Access Tokens. Together, those two pipelines supplied the initial-access credentials behind the bulk of confirmed breaches attributed to ‘frkoo’. On the side, the actor set up a carding shop at policenationale[.]cc, impersonating the French national police to sell stolen payment-card records, full cardholder data, and an interactive map of victim addresses.

Speed was a consistent theme. With Claude’s assistance, a suspected ShinyHunters actor extracted authentication data and obtained more than 2,100 sets of Azure AD authentication tokens linked to over 40 separate corporate Microsoft tenants in around 34 hours. Anthropic notes that “AI agents performed nearly all of the work.” In another case, an attacker moved from a single stolen developer token to full administrative control in less than three hours. ShinyHunters affiliates also breached a technology provider and stole 1TB of data, compromised an airline, and accessed systems of an energy company. Suspected members additionally stole AI API keys and used them for breaching other organisations or for reconnaissance, including one breach of a software-as-a-service provider that exposed data belonging to around 200 downstream customers.

Claude AI Threat Intelligence: Russian and Chinese State Activity

Anthropic’s report attributes a separate strand of activity to Midnight Blizzard, the Russian espionage group. Claude was used to automate malware development, infrastructure acquisition, phishing, persistence, command-and-control operations, and data exfiltration. The group also built a feedback loop that automatically rebuilt malware whenever security products detected it, a self-healing evasion mechanism that required minimal human intervention.

Anthropic observed Midnight Blizzard targeting over 20 government, defence, diplomatic, intelligence, and foreign-policy entities. The campaigns spanned device-code phishing, ClickFix attacks, DNS hijacking through compromised hotel Wi-Fi providers, WhatsApp account takeovers, cloud-email theft, and malware targeting Windows, Android, and iOS. Midnight Blizzard automated its operations through AI-driven workflows built around Claude Code skills, with human operators stepping in mainly to refine those skills when needed.

A Chinese-speaking group tracked as GTG-10007 used Claude as, in Anthropic’s words, “the engineering and orchestration layer of a coordinated offensive program.” Its work included intrusion attempts against production systems, reconnaissance of foreign-government networks across the Middle East, Europe, and South-East Asia, vulnerability research against major endpoint-security products, malware development, and construction of an intelligence-collection platform. Autonomous vulnerability-research workflows ran while human operators were offline and uncovered multiple previously unknown vulnerabilities in a major security product, also delivering working exploits for several families of network and security appliances. GTG-10007’s operations touched around 50 organisations spanning government, education, retail, energy, technology, healthcare, finance, and manufacturing, with confirmed compromises at an education-technology company, a retailer, and a South-East Asian government agency.

A Fraud Scheme Targeting Anthropic’s Own Customers

Beyond the headline espionage and criminal activity, CyberKendra reports that Anthropic’s fourth threat intelligence report also documents a group tracked as GTG-50021, described as Russian- and Ukrainian-speaking. That group sold discounted Claude access to buyers, silently proxied their traffic to a different AI model, and installed a credential harvester that stole the buyers’ own Anthropic credentials. It is a neat illustration of the supply-chain risk in AI tooling: the threat was not just misuse of Claude, but exploitation of demand for it.

Anthropic says it disrupted the actors’ use of Claude, banned their accounts, adjusted its guardrails based on observed misuse, added detection measures, and contacted authorities, industry partners, and victims. The report covers the period to August 2026; Anthropic’s next update will show whether those guardrail adjustments held.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version