Hackers Abuse Claude AI Agents to Automate Cyberattacks, Exploitation and Data Theft
Anthropic reports actors including GTG-20006 (Midnight Blizzard-linked) and ShinyHunters clusters abused Claude AI agents to automate phishing, credential harvesting, and data theft against 20+ organizations.
Anthropic's September 2026 threat intelligence report describes threat actors operating multi-agent workflows built on Claude models to automate the cyber kill chain, from reconnaissance and phishing to exfiltration. The group GTG-20006, assessed as consistent with Midnight Blizzard, targeted Ukrainian and European government, diplomatic, defense, and intelligence entities plus the drone supply chain, with more than 20 organizations identified. Clusters tied to ShinyHunters used 10 AWS EC2 instances to decompile 1.8 million Android APKs for hard-coded secrets and, in a separate SaaS supply chain intrusion, dumped over 2,100 Azure AD token sets across 40+ corporate tenants in about 34 hours. Reported malware families include PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc, the GiftDrop Android RAT, and the DarkSword iOS exploit chain.
- GTG-20006, linked to Midnight Blizzard, hit 20+ organizations including Ukrainian/European governments, defense, intelligence, and drone supply chain.
- AI agents autonomously scanned services, harvested credentials, moved laterally, and rebuilt malware when detections triggered, enabling adaptive evasion.
- ShinyHunters-linked operator used 10 EC2 instances to scan 1.8M Android APKs for secrets via TruffleHog.
- SaaS supply chain intrusion exfiltrated 2,100+ Azure AD token sets across 40+ tenants in 34 hours.
- Anthropic advises treating API keys and OAuth tokens as high-value assets, rotating keys, and enforcing phishing-resistant MFA.
Full article660 words · extracted from gbhackers.com · click to collapse
Threat actors increasingly deploy AI agents as operational systems for cyberattacks, moving beyond simple chatbot assistants. These AI systems automate various stages of the cyber kill chain, including reconnaissance, phishing, exploitation, persistence, and bulk data theft.
Anthropic reported disrupting multiple such operations between December 2025 and August 2026, involving groups suspected to be linked to nation-states, financially motivated criminals, and hacktivists.
Hackers Abuse Claude AI Agents
In its September 2026 threat intelligence report, Anthropic describes a shift in how attackers utilize AI models like Claude, Haiku, Sonnet, and Opus. Instead of requesting isolated code snippets or explanations, operators have begun developing multi-agent workflows that execute recurring tasks across the cyber kill chain.
Anthropic assesses that AI enhances attacker capabilities in three key areas: speed, scale, and depth. This change lowers the barriers associated with staffing, tools, and specialized knowledge that were previously necessary for sustained cyber campaigns.
As a result, sophisticated tradecraft is becoming a less reliable indicator of whether a nation-state, a criminal organization, or an individual hacker orchestrates an intrusion.
In the reported campaigns, human operators still selected victims, set objectives, and reviewed stolen material. However, AI agents handled technical tasks autonomously, such as scanning exposed services, generating and testing scripts, analyzing environments, collecting credentials, and organizing exfiltrated datasets.
One identified group, tracked as GTG-20006 and considered by Anthropic to be consistent with reports on Midnight Blizzard, allegedly targeted Ukrainian and European government entities, diplomatic organizations, defense sectors, intelligence bodies, and the drone supply chain.
This group reportedly employed AI-driven workflows to automate processes such as infrastructure acquisition, domain registration, phishing operations, command-and-control monitoring, credential harvesting, lateral movement, and data exfiltration. Anthropic identified more than 20 organizations as targets of the group’s reconnaissance or active operations.
A particularly alarming capability involved adaptive malware evasion. AI agents monitored whether deployed malware triggered security detections. If a detection occurred, the workflow would modify, rebuild, and redeploy the affected malware until it evaded detection, potentially reducing the time defenders have to respond based on static indicators and signature-based controls.
The campaign utilized phishing, ClickFix lures, and DNS hijacking tactics. It also compromised hospitality vendors that provide guest Wi-Fi, redirected victim traffic through attacker-controlled services, and delivered payloads for Windows, Android, and iOS systems.
Anthropic listed various Windows malware families, including PowerChrome, WUEngine, Shadow C2, MiniPlasma, and CloudSyncSvc, along with the GiftDrop Android RAT and the DarkSword iOS exploit chain.
Anthropic also disrupted clusters affiliated with ShinyHunters. One French-speaking operator allegedly employed 10 AWS EC2 instances to download and decompile 1.8 million Android APKs, searching for hard-coded secrets using TruffleHog. Verified credentials were reportedly routed to Telegram infrastructure, while another pipeline harvested personal access tokens from GitHub.
In a separate supply chain intrusion, AI agents reportedly extracted data from about 200 downstream customers of a compromised SaaS provider, dumping more than 2,100 Azure AD token sets across more than 40 corporate tenants in about 34 hours.
Anthropic said attackers also stole AI API keys from victim environments and reused them as computing resources for subsequent operations; importantly, Anthropic confirmed its own systems were not compromised.
The report emphasizes that security teams should treat AI API keys, cloud sessions, developer tokens, and OAuth credentials as high-value assets.
Organizations should rapidly rotate exposed keys, enforce phishing-resistant multi-factor authentication (MFA), restrict device registration, monitor for bulk mailbox and API exports, and detect anomalous cross-tenant access.
While static signatures remain useful, this activity highlights the need for behavior-based detection, rapid containment, and continuous monitoring for automated reconnaissance and large-scale data collection.
AI is not just accelerating exploit development; it is enabling attackers to link every stage of an intrusion into a faster and more persistent operational loop.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/hackers-abuse-claude-ai-agents-to-automate-cyberattacks/