Anthropic details Claude misuse for weapons, mass surveillance, and Chinese distillation

Anthropic's newest threat intelligence report covers December 2025 through August 2026 and sorts eight months of Claude misuse into seven categories: cyber operations, influence operations, surveillance, fraud, biological misuse, conventional weapons, and unauthorized model distillation. Haiku, Sonnet, and Opus were the models most involved; the newer Fable and Mythos models turned up in only a single distillation case. Anthropic says the report documents novel misuse rather than the typical kind. Its central finding on the cyber side is that sophisticated attacks no longer require sophisticated attackers, since techniques like stolen credentials, unpatched devices, SQL injection, and phishing are unchanged, but reconnaissance, exploitation, and tool building can now be handed to models running in parallel at machine speed. That autonomy lowers the cost side of an attacker's math and makes previously unprofitable targets worth pursuing.
Anthropic tracks a Russian-speaking espionage actor, GTG-20006, that ran a feedback loop: AI agents checked whether its malware was being flagged by security products and, when one caught it, rewrote and recompiled the code on their own until it evaded detection again, shifting the burden back onto defenders since new detection signatures no longer help if the attacker cycles faster than they can be issued. The actor targeted more than 20 organizations, including government ministries, intelligence services, embassies, and defense contractors, focused on Ukraine and Europe, and stole a complete proprietary SDK for a drone vision system from the drone supply chain that came up repeatedly in its targeting. Access sometimes ran through compromised hotel guest Wi-Fi providers, a method Microsoft described in July 2026 as CaptiveCrunch. A separate cluster Anthropic attributes to the ShinyHunters collective (GTG-50014) focused on industrial credential mining: one hacker downloaded and decompiled 1.8 million Android apps to search for hardcoded secrets, in what Anthropic calls vibe hacking, where a human sets a rough goal and the model assesses the environment and iterates until the task is done. That hacker said he collected HackerOne bug bounties on top of extorting two companies.
On distillation, Anthropic identified attacks from seven more Chinese labs since its first disclosure in February. Distillation itself is a legitimate training method, but Anthropic defines the illegitimate version as industrial-scale, covert campaigns that extract a model's capabilities without authorization, typically run through networks of fake accounts using stolen credit cards and API keys and routed through what it calls transfer stations. The largest campaign Anthropic has ever measured is attributed to Alibaba's Qwen lab (GTG-16005): a fixed prompt got Claude to write out its reasoning traces before answering, and the transcripts were turned into fine-tuning data for the Qwen 3.5, 3.6, and 3.7 models. The campaign peaked at almost three million exchanges a day from more than 3,500 fraudulent accounts, totaling over 151 million exchanges between May and July 2026, mostly on agentic tasks and software development.
Stranger were the cases where labs relayed their own customers' requests to Claude. Moonshot AI (GTG-16002) relayed nearly 300,000 customer requests to Anthropic over ten days across 5,380 fraudulent accounts while its users believed they were talking to a Kimi model. DeepSeek (GTG-16001) used strings to detect requests coming from harnesses like Claude Code, flagged those users, and routed selected ones to Claude Opus: more than 12.1 million exchanges in 14 days. Among the rerouted traffic, Anthropic found a user likely tied to the People's Liberation Army who had Claude analyze CCTV archive footage from hundreds of cameras in Chengdu, including cameras outside PLA facilities, for a single target. Through DeepSeek, Claude also received requests from an operator with live credentials to a database linked to the Russian Ministry of Defense, and work on a case management system for a Chinese public security bureau that matches movement profiles against police records.
Xiaomi (GTG-16008) took a different approach, storing requests and coding sessions from users of its own MiMo models and replaying those conversations through Claude to generate training data; Anthropic found no evidence that Claude's answers were served back to Xiaomi's users, but the relayed requests still carried personal data, names, contact details, and company information for hundreds of people in at least a dozen languages. Zhipu, known outside China as Z.ai, rotated through 273 accounts and pushed more than 770,000 exchanges over ten days through a CoT cleaner, a tool that turns captured reasoning traces into training data; to train its GLM-5.3 model on cyber tasks, the lab first targeted Anthropic's Fable model, gave up once Fable's cyber safeguards degraded performance, and switched deliberately to models it judged to have weaker protections. SenseTime bought transcripts from third parties rather than capturing Claude data itself, and MiniMax ran a proxy network through a shell company that offered only Anthropic and OpenAI models, none of its own.
The surveillance chapter centers on Mali, where a single consultant used Claude as the primary engineering workforce for Lakana 360, a platform meant to monitor roughly 25 million SIM cards across all three national mobile carriers. It identifies people by voice across SIM swaps, flags encryption and VPN users, and links individuals to the national biometric civil registry; suspending the Claude account interrupted only the development work, not the operation, because the platform runs on local models on premises. Anthropic documents a similar pattern with Iranian units that claim to have surveilled and profiled 6,388 Iranians within a year.
The weapons chapter is new for this report. A cell in northern Yemen (GTG-87001) put Claude Code in place of human engineers for the guidance, navigation, and control software of three missile programs, including a multistage missile with a target range over 2,000 kilometers; the group ran several Claude instances in parallel and spread the work across sessions so no single one revealed the intent, and after a test launch apparently failed, the actors returned to Claude within hours to diagnose the cause. A second case (GTG-27005), likely freelance Russian actors, built an autonomous FPV kamikaze drone swarm carrying a small language model that performs terminal-phase targeting by camera; the platform was designed for autonomous lethal effect, letting the onboard model select targets in the person class and trigger detonation with no human in the loop, and its image classifier was trained on captured Ukrainian combat footage. A Chinese case (GTG-17002) involved a suite of roughly 16 modules for electronic warfare and suppression of enemy air defenses, whose simulation defaulted, midway through the project, to twelve targets in Taiwan.
The biology chapter is the most self-critical part of the report. Anthropic documents five anonymized cases of working scientists where Claude assisted with potentially dangerous dual-use projects. In one, its biosecurity classifier blocked a grant application for gain-of-function work on the chikungunya virus planned at a military research institute, but the platform's operator had already built a fallback that routed Claude's rejected requests to a competitor's model, and Claude itself wrote most of that fallback's code. Other projects went largely unimpeded, including a drafted application on immune evasion genes in orthopoxviruses. Anthropic's conclusion is that classifiers cannot both enable useful work and prevent harm, because a user's intent in dual-use research cannot be reliably detected. In response, it launched Claude Fable 5 with stricter safeguards for dual-use biology requests, and against distillation, the preserved thinking feature introduced with Fable 5.1 is meant to stop new API accounts from manipulating the context. The only safe path to frontier biology capabilities, Anthropic says, runs through programs for verified users.
Key facts
- Anthropic's threat report covers December 2025 through August 2026 and adds a weapons chapter for the first time, alongside cyber operations, surveillance, fraud, biological misuse, and unauthorized distillation.
- A Yemen cell (GTG-87001) used Claude Code for the guidance and control software of three missile programs, one with a range over 2,000 kilometers, while a separate group (GTG-27005) built an autonomous drone swarm whose onboard model could pick person-class targets and detonate with no human in the loop.
- Seven more Chinese labs, including Alibaba's Qwen, Moonshot AI, and DeepSeek, ran unauthorized distillation campaigns; Qwen's alone reached over 151 million exchanges from more than 3,500 fraudulent accounts between May and July 2026.
- Rerouted through DeepSeek, a user likely tied to the People's Liberation Army had Claude analyze CCTV footage from hundreds of cameras in Chengdu, including some outside PLA facilities.
- In Mali, a single consultant used Claude to help build Lakana 360, a platform meant to monitor roughly 25 million SIM cards; suspending the account stopped the development work but not the platform, which runs on local models on premises.
Why it matters
This is the first weapons chapter in an Anthropic threat report, and it documents Anthropic's own cases for the first time: a Yemen cell using Claude Code for actual missile guidance software, and a separate group building an autonomous drone swarm whose onboard model can select a human target and trigger detonation with no person in the loop. The report also shows that account suspension is a limited defense against well-resourced actors: self-repairing malware defeats detection built on signatures, and seven more Chinese AI labs kept extracting Claude's capabilities at industrial scale, in several cases by quietly rerouting their own customers' traffic into it. Frontier labs are now defending against weaponization and unauthorized capability transfer as live, parallel problems.
Who it affects
Anthropic and rival frontier labs, now defending against both misuse and unauthorized distillation at once; the seven named Chinese labs (Qwen, Moonshot AI, DeepSeek, Xiaomi, Zhipu, SenseTime, and MiniMax), now publicly tied to unauthorized use of a competitor's model; ordinary users of Kimi, MiMo, and GLM products whose queries were relayed to or replayed through Claude without their knowledge; and the people on the other end of the misuse cases: roughly 25 million SIM card holders in Mali, 6,388 profiled Iranians, more than 20 organizations targeted by espionage in Ukraine and Europe, and the twelve simulated targets in Taiwan that a Chinese electronic-warfare project defaulted to.
How to use it
There is no product here to adopt, but two takeaways are actionable. Security teams should treat self-repairing malware as a sign that writing a new detection signature no longer buys time once an attacker's model can iterate faster than the signature ships. And anyone building on top of a wrapper product (a chat app, an API reseller, a fine-tuning service) should note the underlying model can be swapped without notice: Moonshot's customers believed they were talking to a Kimi model while their requests actually went to Claude, and DeepSeek quietly rerouted flagged users to Claude Opus behind the scenes.
How solid is it
The report is Anthropic's own disclosure, so the company is both the source and the party grading its own product's misuse and its own defenses; there is no independent investigation of the underlying evidence here. Cases carry specific tracking codes (GTG-20006, GTG-16005, and others) and hard figures (exchange counts, account counts, durations) that read as pulled from Anthropic's own logs rather than estimated. Confidence varies by case: DeepSeek's and Moonshot's rerouting is stated as fact, while the drone swarm's attribution to Russian actors is qualified as likely rather than confirmed. Individual people go unnamed throughout, at the Chinese labs, at Microsoft, and among the hackers discussed, identified only by company, lab, or threat-group codename.
Risks and caveats
Several gaps limit how far this can be checked. No cause or resolution is given for the failed Yemen missile test launch, only that the actors returned to Claude within hours to investigate, and no current operational status (ongoing, halted, or seized) is given for the Yemen missile programs, the drone swarm, or the Chinese electronic-warfare suite. No financial figures of any kind (cost, damages, revenue, or bounty amounts) appear anywhere in the source. The competitor's model that the biology platform's fallback used is not named, and neither is the consultant behind Mali's Lakana 360 platform. Enforcement looks uneven: no penalty against any of the seven distillation labs is mentioned, and the only account suspension described, Mali's, stopped the development work but left the surveillance platform itself running.