Advertisement

Claude agents lower barriers for automated cyberattacks

Anthropic says malicious actors are increasingly embedding its Claude artificial intelligence models into autonomous cyberattack workflows that can scan targets, exploit weaknesses, steal credentials and process stolen data with far less human labour.

The company’s September threat intelligence report, released on September 10, details operations disrupted between December 2025 and August 2026 across cyber espionage, financially motivated crime, hacktivism, surveillance and other forms of misuse. Anthropic said the most significant change was not the invention of entirely new attack techniques, but the delegation of large parts of the cyber kill chain to AI agents operating at machine speed.

A majority of the cyber operations described involved Claude directly executing or orchestrating tasks rather than merely answering questions or helping write code. Multi-agent frameworks were used for reconnaissance, exploitation and data exfiltration, while human operators generally retained control over target selection, monetisation and review of stolen information.

Anthropic said the approach has reduced the labour, specialist knowledge and infrastructure once required for sophisticated intrusions. It documented cases where individual operators handled dozens of victims in parallel and breaches were completed within two to three hours. Familiar methods — including stolen credentials, unpatched internet-facing devices, exposed services, SQL injection and phishing — became faster and cheaper to deploy when repetitive work was assigned to AI.

One espionage operation, tracked by Anthropic as GTG-10007, involved Chinese-speaking operators believed to be based in Changsha, Hunan province. The group used Claude as an engineering and orchestration layer for intrusion attempts, foreign-government reconnaissance, malware development and sustained vulnerability research. Anthropic said the operation targeted about 50 organisations spanning government, education, energy, technology, healthcare, finance, retail and manufacturing.

The group compromised an education-technology company and extracted hundreds of megabytes of student personal data from cloud storage, according to Anthropic. It also accessed a retailer’s production systems and retrieved citizen records, including names, telephone numbers and home addresses, from a Southeast Asian government agency. Its automated research programme identified previously unknown vulnerabilities in a major security product and produced working exploits for several network and security appliances.

A separate operation, GTG-20006, was assessed by Anthropic as consistent with publicly documented activity linked to Midnight Blizzard, a Russia-linked espionage actor. Claude-assisted workflows automated infrastructure acquisition, phishing, persistence, command-and-control activity and data exfiltration. The actor also built agents that monitored whether malware had been detected by security products and automatically modified and rebuilt the code until it evaded those detections.

Targets in that campaign included Ukrainian and European government, defence and intelligence organisations, diplomatic missions, think tanks and entities connected to United States foreign policy. Anthropic said the actor also stole mailboxes from drone-component manufacturers and obtained a proprietary software development kit for a drone vision system.

Financially motivated operators suspected of links to the ShinyHunters criminal ecosystem also used Claude to accelerate opportunistic intrusions. Anthropic described one French-speaking operator running 10 cloud-computing workers that downloaded 1.8 million Android application packages, decompiled them and searched for embedded secrets. Stolen credentials and tokens were then used as initial access for breaches and extortion activity.

Anthropic also identified stolen access to AI services as a criminal commodity. Compromised API keys, session tokens and devices were traded through brokers or used directly in attacks, while some malicious sites impersonated AI services and distributed credential-stealing applications. The company said cases in the report involved Claude Haiku, Sonnet and Opus models, and that it found no malicious activity involving Claude Fable or Mythos, which carry stronger cyber safeguards.

The report also described a French-speaking hacktivist who targeted European political parties, media organisations, think tanks and their software providers. Anthropic said the actor used stolen API keys and custom tooling to run multi-victim campaigns that would previously have demanded a larger team of skilled operators.
Previous Post Next Post

Advertisement

Advertisement

نموذج الاتصال