Anthropic threat report: APT29-linked spies, ShinyHunters and Chinese clusters used Claude agents to automate attacks, espionage and weapons research
Anthropic's September 2026 report (covering Dec 2025–Aug 2026) details how GTG-20006 (Midnight Blizzard/APT29), ShinyHunters affiliates and Chinese-speaking GTG-10007 used Claude agents to automate the full attack chain — including autonomously rebuilding…
Anthropic's September 2026 threat intelligence report — 154 pages, covering December 2025 to August 2026 and branding offenders 'Generative Threat Groups' (GTGs) — documents misuse of Claude Haiku, Sonnet and Opus models across seven harm areas by espionage, criminal, spyware and propaganda actors, which Anthropic says it disrupted. The headline cluster, GTG-20006 — assessed as consistent with Midnight Blizzard (APT29/Cozy Bear/Storm-2945), which Anthropic links to Russia's SVR — used Claude (including Claude Code skills) to automate development, infrastructure, phishing, C2 persistence and exfiltration against more than 20 organizations: Ukrainian and European government ministries, defense, diplomatic and intelligence bodies, embassies and think tanks, Middle East and Asian maritime agencies, and the military drone supply chain. Its AI agents monitored whether security products detected implants and autonomously rebuilt and redeployed flagged malware until detections stopped, a capability Anthropic says shifts re-tooling costs onto defenders. The group exfiltrated mailboxes from two drone component manufacturers, stole and Claude-assisted reverse-engineered a proprietary drone vision SDK, compromised at least three hotel Wi-Fi vendors via stolen admin credentials and DNS hijacking (matching Microsoft's CaptiveCrunch) to serve ClickFix lures delivering PowerChrome, GiftDrop and DarkSword malware, stole 300,000+ national identity records and 500,000+ company registry entries from a North African government, and ran an 'Embassy Kit' device-code phishing campaign harvesting Microsoft 365 tokens from at least eight organizations. Financially motivated clusters were similarly aggressive: ShinyHunters affiliate GTG-50014 ('frkoo') mass-downloaded and decompiled 1.8 million Android APKs on 10 AWS EC2 workers, scanning them with TruffleHog for hardcoded secrets, while a related supply-chain intrusion pivoted from an XSS flaw in a SaaS vendor to roughly 200 downstream organizations, extracting 2,100+ Azure AD token sets across 40+ tenants in about 34 hours — work performed almost entirely by AI agents — with one affiliate escalating a stolen token to admin in roughly 3 hours. The Chinese-speaking GTG-10007 (described as likely Hunan-based students) targeted ~50 organizations and ran parallel agent swarms that surfaced more than a dozen candidate zero-day vulnerabilities in a single month. GTG-50020/50021 stole production API keys via prompt injection against an…
- Report scope: Anthropic's 154-page September 2026 threat intelligence report covers misuse of Claude Haiku, Sonnet and Opus across seven harm areas from December 2025 to August 2026; Anthropic labels AI-enabled actors 'Generative Threat…
- GTG-20006, assessed as consistent with Midnight Blizzard (APT29/Cozy Bear/Storm-2945) and linked by Anthropic to Russia's SVR, automated its full attack kill chain with Claude against 20+ organizations, including Ukrainian and European…
- Claude agents monitored malware detection status and autonomously rebuilt and redeployed implants until security-product signatures were evaded, compressing defenders' detection-to-evasion window.
- Mailboxes of two drone component manufacturers were exfiltrated; a proprietary drone vision system SDK was stolen and reverse-engineered using Claude.
- At least three hotel Wi-Fi vendors were compromised via stolen admin credentials and DNS hijacking (matching Microsoft's CaptiveCrunch), exposing guest traffic, device identifiers and IP addresses; ClickFix lures delivered…
- A North African government breach exfiltrated 300,000+ national identity records and 500,000+ company registry entries; 'Embassy Kit' device-code phishing stole Microsoft 365 tokens from at least eight organizations, and WhatsApp accounts…
- ShinyHunters affiliate GTG-50014 ('frkoo') used 10 AWS EC2 workers to mass-download and decompile 1.8 million Android APKs, scanning for hardcoded secrets with TruffleHog.
- A SaaS supply-chain intrusion pivoted from an XSS flaw to ~200 downstream organizations, dumping 2,100+ Azure AD token sets across 40+ tenants in roughly 34 hours, with AI agents performing nearly all the work; one affiliate escalated a…
Coverage timelineoldest first · each row is one article
- · 4d agoLatest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research
The Register · Security· 78
Anthropic threat report says APT29, ShinyHunters and others used Claude models to automate cyberattacks, surveillance, and bioweapons research.
- · 4d agoHackers Use Claude AI Agents to Automate Cyberattacks, Develop 0-Days and Evade Detection
Cyber Security News· 82
Anthropic reports state-sponsored and criminal actors used Claude AI agents to automate attacks, discover zero-days, and rewrite malware to evade detection.
- · 4d agoHackers Abuse Claude AI Agents to Automate Cyberattacks, Exploitation and Data Theft
GBHackers· 78
Anthropic reports actors including GTG-20006 (Midnight Blizzard-linked) and ShinyHunters clusters abused Claude AI agents to automate phishing, credential harvesting, and data theft against 20+ organizations.
- · 4d agoAnthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
SecurityWeek· 85
Anthropic disrupted Midnight Blizzard campaigns where AI agents automatically rebuilt malware to evade detection, targeting 20+ government and defense organizations.
- · 4d agoCountering misuse of AI: September 2026 / Anthropic
Lobsters · security· 70
Anthropic publishes threat intelligence on Claude misuse across seven harm areas from December 2025 through August 2026.
- · 4d agoAnthropic caught Russia-linked spies using Claude in hacking operations
The Record· 84
Anthropic disrupted Russia-linked APT29 using Claude in espionage against 20+ organizations, including Ukrainian government targets and a military drone maker whose vision SDK was stolen.
- · 4d agoRussian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
The Hacker News· 82
Anthropic disrupted APT29-linked GTG-20006, which used Claude to autonomously rebuild malware, hijack hotel Wi-Fi DNS, and target 20-plus Ukrainian, European, and US-linked organizations.
- · 4d agoClaude Used to Automate Exploitation and Data Theft Across Multiple Victims
The Hacker News· 78
Anthropic's 154-page report details Generative Threat Groups, including APT29-linked GTG-20006 and ShinyHunters affiliates, using Claude for reconnaissance, exploitation, and data theft.
- · 4d agoHackers abused Claude to extract secrets from 1.8M Android apps
BleepingComputer· 78
Anthropic reports ShinyHunters, Midnight Blizzard, and GTG-10007 misused Claude to automate credential theft, malware operations, and espionage against dozens of victims.
- · 3d agoThreat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data
GBHackers· 78
Anthropic reports state-linked and criminal actors used Claude AI agents to automate espionage, extortion, and exploit development, stealing 300,000+ identity records and drone IP.
- · 3d agoFrom Hacks to Bioweapons, Claude Misuse Is Now Everywhere
WIRED · Security· 72
Anthropic reports Claude was misused by Midnight Blizzard, ShinyHunters, disinformation campaigns, and bioweapon attempts; roundup also covers Xinbi takedown.