AI-Powered Threats Exploit Digital Trust Through Autonomous Breach Techniques
A PRC-linked group used Claude Code as an autonomous operator for espionage, while researchers identified the first Android malware leveraging generative AI.
Anthropic disclosed a PRC-linked campaign (GTG-1002) where the threat actor used its Claude Code model as an autonomous operator, integrating it with offensive tools via Model Context Protocol servers. This marks a shift from AI as a coding assistant to an autonomous breach operator. Separately, researchers identified PromptSpy, the first Android malware to use generative AI (Google Gemini) for device-specific reconnaissance and execution, and Trellix noted AI agents are automating the full kill chain from credential harvesting to lateral movement.