Anthropic Threat Report Details AI-Assisted Espionage and 151M-Exchange Claude Distillation by Seven China-Based Labs; ByteDance's HarnessDev Shows LLM-Built Agent Harnesses Trail…
Anthropic's eight-month threat report documents AI-assisted espionage against 20+ organizations, self-rewriting malware, and unauthorized distillation by seven China-based labs (largest: 151 million exchanges); new in this merge, ByteDance Seed's HarnessDev…
Anthropic's threat intelligence report, published September 11, 2026 and covering December 2025 through August 2026, documents Claude misuse across seven categories including cyber operations, surveillance, fraud, and unauthorized model distillation. A Russian-speaking espionage actor tracked as GTG-20006 used AI agents to rewrite and recompile malware evading antivirus detection, targeting more than 20 organizations in Ukraine and Europe and stealing a drone vision system SDK; Anthropic warns AI autonomy makes previously unprofitable attacks viable and weakens sophistication-based attribution. Anthropic also says it identified and disrupted six illicit distillation campaigns since February 2026 run by seven China-based labs: Alibaba, DeepSeek, Moonshot, Z.ai (Zhipu), MiniMax, Xiaomi, and SenseTime. The largest, GTG-16005, involved 151 million exchanges targeting Claude Opus 4.6/4.7 chain-of-thought transcripts, peaking near 3 million per day from more than 3,500 fraudulent accounts; The Decoder attributes the campaign to Alibaba's Qwen lab, dates it May-July 2026, and says it was used to train Qwen 3.5, 3.6, and 3.7. DeepSeek routed 12.1 million exchanges to Claude Opus, including PLA-linked users analyzing CCTV footage; relayed traffic also included users with credentials tied to the Russian Ministry of Defense. Moonshot (GTG-16002) relayed roughly 300,000 customer requests via 5,380 fraudulent accounts in Singapore and Japan. Labs used proxy/relay services with fictitious identities, fake or stolen credit cards, harvested API keys, and purchased conversation transcripts from third-party resellers without user consent. A ShinyHunters-linked hacker separately decompiled 1.8 million Android apps to mine hardcoded secrets. Anthropic is countering by banning reseller accounts, summarizing internal reasoning before responding, and introducing 'preserved thinking' in Fable 5.1, which encrypts reasoning and prevents context edits before it. New in capability research: researchers from ByteDance Seed, SUTD, Georgia Tech, M-A-P, and TokenWave.AI introduced HarnessDev, a benchmark that grades the runnable agent harness an LLM writes rather than its answers, using Creation and Evolution stages across SWE-bench Pro, Terminal-Bench 2.1, MLE-bench, EQ-Bench3, and BrowseComp (2,207 instances). Of six creator models - Opus 4.8, GPT-5.5, Gemini 3.1 Pro, DeepSeek V4 Pro, Qwen 3.7 Max, and Seed 2.0 Pro - Opus 4.8 posted the best average of 67.8 versus an 86.2…
- Anthropic's threat intelligence report (published September 11, 2026; covering December 2025-August 2026) documents Claude misuse across seven categories including cyber operations, surveillance, fraud, and unauthorized model distillation.
- Russian-speaking espionage actor GTG-20006 used AI agents to rewrite and recompile malware to evade antivirus detection, targeting 20+ organizations in Ukraine and Europe and stealing a drone vision system SDK; Anthropic warns AI autonomy…
- Anthropic disrupted six illicit distillation campaigns since February 2026 run by seven China-based labs: Alibaba, DeepSeek, Moonshot, Z.ai (Zhipu), MiniMax, Xiaomi, and SenseTime.
- Largest campaign GTG-16005: 151 million exchanges targeting Claude Opus 4.6/4.7 chain-of-thought transcripts, peaking near 3 million/day from 3,500+ fraudulent accounts; The Decoder attributes it to Alibaba's Qwen lab, dates it May-July…
- DeepSeek routed 12.1 million exchanges to Claude Opus, including PLA-linked users analyzing CCTV footage; relayed traffic also included users with credentials tied to the Russian Ministry of Defense.
- Moonshot (GTG-16002) relayed ~300,000 customer requests to Claude via 5,380 fraudulent accounts in Singapore and Japan.
- Labs used proxy/relay services with fictitious identities, fake or stolen credit cards, harvested API keys, and purchased user-Claude transcripts from third-party resellers without consent; proxy services resell harvested transcripts to…
- A ShinyHunters-linked hacker decompiled 1.8 million Android apps to mine hardcoded secrets.
Coverage timelineoldest first · each row is one article
- · 7d agoHow hackers used Claude for missiles, drone swarms, and surveillance, while Chinese labs mined it for training data
The Decoder· 80
Anthropic's threat report details eight months of Claude misuse: AI-assisted espionage against 20+ organizations, self-rewriting malware, and Chinese labs distilling Claude via fraudulent accounts.