Anthropic Disrupts 'Generative Threat Groups': APT29-Linked Hackers and ShinyHunters Automated Attacks with Claude
Anthropic's 154-page threat report says that between December 2025 and August 2026 state-sponsored hackers, criminals, and other actors misused its Claude models — including APT29/Midnight Blizzard-linked GTG-20006 running AI agents that autonomously rebuilt…
Anthropic has disclosed how its Claude models were misused from December 2025 through August 2026 by state-sponsored hackers, cybercriminals, spyware vendors, and propaganda operators, labeling the clusters 'Generative Threat Groups' in a 154-page report; the company says it disrupted the activity, and WIRED notes the report also covers influence operations disrupted before building authentic audiences and attempts at bioweapon development. The most detailed cluster, GTG-20006 — aligned with Russia-linked Midnight Blizzard (APT29/Cozy Bear) — ran an AI-driven loop in which agents monitored implants against security products and autonomously rebuilt and redeployed detected malware, targeting 20-plus Ukrainian, European, and US-linked military-intelligence, diplomatic, and defense organizations plus Middle East and Asian maritime agencies. It compromised at least three hotel guest Wi-Fi vendors via DNS hijacking (exposing guest traffic, device identifiers, and IP addresses), used ClickFix lures delivering Windows, Android, and iOS malware including PowerChrome, GiftDrop, and DarkSword, ran 'Embassy Kit' device-code phishing that stole Microsoft 365 tokens from at least eight government organizations, took over WhatsApp accounts using headless browsers, and exfiltrated 300,000-plus national identity records and data on 500,000-plus companies from a North African government technology authority along with a proprietary drone-vision SDK; stolen hotel and device data was then used to target Ukraine-linked officials and drone manufacturers. A ShinyHunters affiliate (GTG-50014, member 'frkoo') mass-downloaded and decompiled 1.8 million Android APKs on 10 AWS EC2 workers, scanning with TruffleHog for hardcoded secrets; ShinyHunters-linked actors also stole AI API keys and breached a SaaS provider affecting about 200 downstream customers, and BleepingComputer reports one AI-assisted operation extracted 2,100-plus Azure AD tokens across 40-plus Microsoft tenants in roughly 34 hours. Chinese-speaking GTG-10007, described as likely Hunan-based students, hit roughly 50 organizations: BleepingComputer says its autonomous vulnerability research uncovered zero-days in a major endpoint security product, while GBHackers says it generated over a dozen potential zero-day findings against network appliances in one month. GTG-50029, a lone French-speaking actor, exploited a previously undocumented WordPress re-installation race condition to create rogue admin accounts.…
- Anthropic's 154-page report covers Claude misuse from December 2025 to August 2026 and brands AI-enabled actors 'Generative Threat Groups' spanning espionage, cybercrime, and propaganda; Anthropic says it disrupted the activity.
- GTG-20006, aligned with Midnight Blizzard (APT29/Cozy Bear), used AI agents to monitor detection status and autonomously rebuild and redeploy malware against 20-plus Ukrainian, European, and US-linked government and defense targets, plus…
- The group compromised at least three hotel guest Wi-Fi vendors via DNS hijacking, exposing guest traffic, device identifiers, and IP addresses, and used ClickFix lures delivering Windows, Android, and iOS malware including PowerChrome,…
- Its 'Embassy Kit' device-code phishing stole Microsoft 365 tokens from at least eight government organizations; WhatsApp accounts were taken over using headless browsers.
- A North African intrusion exfiltrated 300,000-plus national identity records and 500,000-plus company registry entries from a government technology authority, plus a proprietary drone-vision SDK; stolen hotel and device data was used to…
- ShinyHunters affiliate GTG-50014 (member 'frkoo') mass-downloaded and decompiled 1.8 million Android APKs on 10 AWS EC2 workers, using TruffleHog to find hardcoded secrets.
- ShinyHunters-linked actors stole AI API keys and breached a SaaS provider affecting about 200 downstream customers; one AI-assisted operation extracted 2,100-plus Azure AD authentication tokens across 40-plus Microsoft tenants in roughly…
- Chinese-speaking GTG-10007, described as likely Hunan-based students, targeted roughly 50 organizations; sources describe its autonomous research as uncovering zero-days in a major endpoint security product (BleepingComputer) and as over a…
Coverage timelineoldest first · each row is one article
- · 7d agoRussian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
The Hacker News· 82
Anthropic disrupted APT29-linked GTG-20006, which used Claude to autonomously rebuild malware, hijack hotel Wi-Fi DNS, and target 20-plus Ukrainian, European, and US-linked organizations.
- · 7d agoClaude Used to Automate Exploitation and Data Theft Across Multiple Victims
The Hacker News· 78
Anthropic's 154-page report details Generative Threat Groups, including APT29-linked GTG-20006 and ShinyHunters affiliates, using Claude for reconnaissance, exploitation, and data theft.