Anthropic says AI now lets lone operators run state-level hacking campaigns
Individual hackers are now sustaining campaigns that would have needed many skilled operators a year ago, because artificial intelligence has absorbed the labor that used to set state-backed teams apart.
That’s according to AI model developer Anthropic PBC, which today published its latest threat intelligence report, covering Claude misuse it disrupted between December and August. It also accuses seven Chinese AI labs of illicitly distilling Claude’s capabilities.
The report spans seven harm areas, and the actors in it include suspected state-sponsored groups, financially motivated criminals and commercial spyware vendors. They used Claude Haiku, Sonnet and Opus models. Only one case, a distillation campaign, touched the company’s Fable or Mythos-class models.
None of the intrusions relied on a novel technique, according to the report. Stolen credentials and unpatched edge devices feature throughout, and the grunt work of reconnaissance and tool development went to AI models running in parallel at machine speed. Anthropic said the result is “breaches completed in two to three hours, and dozens of victims handled in parallel by individual operators.” The autonomous operating model it first documented in a suspected Chinese state-sponsored campaign last November has since spread to every class of actor it investigated.
Anthropic said its attribution of one actor, GTG-20006, is consistent with public reporting on the Russian espionage group Midnight Blizzard. Ukrainian government, military and diplomatic staff were its most frequent targets.
The operators bulk-exported the mailboxes of at least two drone component makers, stole a proprietary software development kit for a drone vision system and compromised hotel guest Wi-Fi vendors to reach travelers. Whenever security products flagged the group’s implants, Claude was used to modify and redeploy them, a loop Anthropic said has “inverted the cost back onto defenders.”
Affiliates of the ShinyHunters extortion collective went from a single stolen developer token to full administrative control of a victim’s cloud environment in roughly three hours during one compromise. In another, AI agents did nearly all the work of dumping more than 2,100 Azure Active Directory token sets from over 40 corporate tenants in about 34 hours.
A Chinese-speaking group tracked as GTG-10007, likely based in Changsha, ran what Anthropic calls automated exploit foundries against about 50 organizations. Two of the operators were identified as undergraduate students. The group used “agent swarms” for reconnaissance and post-exploitation work, and one workflow iterating on network appliances produced “more than a dozen possible zero-day findings” in a single month.
GTG-50020, a Russian-speaking financially motivated actor, turned to the AI industry after earlier intrusions against hotel booking and financial technology platforms. Its operators planted malicious instructions in an AI vendor’s automated evaluation sandbox, which handed over production application programming interface keys for several model providers.
A follow-on campaign targeted roughly 30 AI companies in about four days. The stated goal was access to a pre-release Claude model, and Anthropic said every attempted path failed and its own systems were never breached.
On distillation, Anthropic said operators affiliated with Alibaba Group Holding Ltd. ran “the largest distillation attack we have ever measured.” It said a fixed prompt forced Claude Opus 4.6 and 4.7 to write out their chain-of-thought reasoning, and the transcripts were used to train Qwen 3.5, 3.6 and 3.7. The campaign peaked at nearly 3 million exchanges a day from more than 3,500 fraudulent accounts, with more than 151 million counted between May and July.
Moonshot AI and DeepSeek Ltd. are accused of quietly forwarding their own customers’ requests to Claude and saving the answers for training. In one 10-day stretch, Moonshot relayed almost 300,000 requests from users who believed they were talking to Kimi.
Sensitive data came along with them, including footage from hundreds of surveillance cameras in Chengdu uploaded by a user Anthropic assessed as likely affiliated with China’s People’s Liberation Army. A DeepSeek relay exposed live credentials for a Russian government database linked to the country’s Ministry of Defense.
The other four labs named are Xiaomi Corp., Zhipu, SenseTime Group Inc. and MiniMax. Anthropic said MiniMax set up a proxy service through an undisclosed shell company that sells access only to Anthropic and OpenAI Group PBC models. Anthropic first accused Chinese labs of distillation in February.
Elsewhere in the report is Lakana 360, a surveillance platform built with Claude for Mali’s state intelligence service by what Anthropic believes was a single independent consultant. It monitors roughly 25 million SIM cards on all three of the country’s mobile operators and was designed to get around a legal requirement for court orders. Six weapons development cases in China, Russia and Yemen were also disrupted, among them an effort by likely freelance Russia-based developers to build an autonomous kamikaze drone swarm.
Anthropic said it banned the accounts involved and shared intelligence with authorities and industry partners where appropriate. Claude now summarizes its internal reasoning before responding, making stolen transcripts less useful for training. Accounts operating from unsupported countries such as China, Russia and Iran can also be required to verify their identity or lose access.
Image: SiliconANGLE/GPT Image 2.5
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos , powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
theCUBE AIand theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.