Anthropic disrupts Claude-automated Russian espionage campaign

Anthropic disrupts Claude-automated Russian espionage campaign

Anthropic has published "Detecting and countering misuse of AI: September 2026," the latest edition of its Threat Intelligence team's account of how outside actors try to use Claude for harm. The report covers activity the team says it identified and disrupted over the past eight months, following earlier editions from March, August and November 2025. It groups the cases into seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. The threat actors involved range from suspected state-sponsored groups and financially motivated criminals to commercial spyware vendors, state propaganda institutions and politically motivated individuals; examples cited include a network of fake dating apps built to defraud users and surveillance systems designed to identify and monitor dissidents. Across the disrupted cases, only Claude Haiku, Sonnet and Opus models turned up; none involved Claude Fable or Mythos-class models, with a single exception: one illicit distillation case. Anthropic says that in each case it disrupted the activity, used the findings to strengthen its safeguards, and shared intelligence with authorities and industry partners where appropriate, and that it is publishing the report so other AI developers can recognize similar patterns on their own platforms and so governments and civil society get a clearer view of how these threats take shape.

The report's cyber operations section, which the retrieved text develops in the most detail, separately states a six-month lookback for its own case studies (narrower than the eight months given in the introduction), covering the same period from December 2025 through August 2026. Anthropic uses the term "Generative Threat Groups," or GTGs, as its internal designators for actors it observes abusing its models, and measures "uplift": the AI capability boost an actor gets, viewed through speed, scale and depth. Its first trend finding is that sophisticated attacks no longer require sophisticated attackers. The case studies include a hacktivist working from stolen API keys, separate financially motivated individuals, and a state espionage operator, each sustaining multi-victim campaigns that, a year earlier, would have needed many skilled operators and specialist knowledge; Anthropic says sophistication has stopped being a reliable signal of who is actually behind an operation. An autonomous-attack operating model the company first documented in a suspected state-sponsored campaign in November 2025 has since proliferated across every class of actor it investigated, helped along by publicly available offensive agent frameworks, such as PentAGI, that let anyone reproduce similar automation of the cyber kill chain. The second trend is that AI's role in these operations has grown more autonomous: a majority, though not all, of the operations described were enabled by AI through direct execution or orchestration, using multi-agent frameworks for reconnaissance, exploitation and data exfiltration rather than simple chatbot questions and answers, with humans staying in the loop mainly to set targets and review what was exfiltrated.

Anthropic's lead example of both trends is GTG-20006, an actor it says increased its own speed by automating operations with AI. The company's attribution is consistent with public reporting linking the actor to Midnight Blizzard, and one of its operators is a Russian speaker using the handle "JackPoterz," whose tradecraft and targeting Anthropic describes as consistent with Russian state-nexus espionage. The group ran customized AI-driven workflows that automated much of its work, from development and infrastructure acquisition through phishing and command-and-control persistence to data exfiltration, targeting military intelligence bodies in Ukrainian and European governments, diplomatic and defense organizations, and individuals connected to US foreign policy. Its toolkit comprised two families of Windows-based implants, a mobile exploitation kit, a credential-stealing tool aimed at browser password stores, a phishing platform built to mimic government and other priority targets, and an administrative console for managing compromised accounts, with each tool retooled through AI-assisted workflows as needed. AI agents also monitored how well the tools evaded known security products; whenever a security product flagged the malware, the agents autonomously modified and rebuilt it, iterating until it went undetected, before the group staged it on disposable hosting servers for live operations that included phishing, ClickFix lures and DNS hijacking. Separate AI-driven workflows researched and registered the domains and configured the hosting infrastructure behind the phishing operation, then sent the emails and monitored command-and-control channels for successful compromises; Anthropic says the human operator's main role was refining the Claude Code skills that drove these workflows whenever they needed adjustment.

Anthropic's investigation identified more than 20 distinct organizations targeted across GTG-20006's planning, reconnaissance and live operations, including government ministries, defense and intelligence bodies, embassies and diplomatic missions, think tanks, and defense-industrial companies, concentrated in Ukraine and Europe but extending to the Middle East and to maritime-related government agencies in Asia. A common theme was Ukraine and military drone technology providers and supply chains; departing from that theme, two of the reported targets were a Southeast Asian government body handling maritime shipping and tracking, and a North African government technology authority. The most frequently recurring targets were Ukrainian government, military and diplomatic staff, and the actor separately scanned email services and remote-access systems across more than two dozen Ukrainian government organizations. A secondary recurring target was drone supply-chain technology: the group bulk-exported the mailboxes of at least two drone-component manufacturers, targeted a military drone maker, and stole a complete proprietary software development kit for a drone vision system, spending several days reverse-engineering it to recover the product's architecture, hardware bill of materials, supplier dependencies and details of an unannounced product, with particular interest in military drone-control and AI-vision firmware. To reach some targets indirectly, GTG-20006 compromised at least three hospitality vendors that operate hotel guest WiFi, using stolen admin credentials to hijack DNS records so that guests' traffic, device identifiers and IP addresses were routed to the group's own servers; from there, ClickFix-style lures delivered Windows, Android and iOS malware to guest devices. The group combined guest information stolen from hotel management systems with data taken from individual devices to sharpen further targeting, focusing especially on people connected to Ukraine, including government officials and drone manufacturers. The retrieved report text cuts off mid-sentence at this point, referencing an event in July 2026 that it does not otherwise describe.

Key facts

  • Anthropic's report covers Claude misuse it disrupted between December 2025 and August 2026 across seven harm areas (cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and distillation); it is the fourth such report, after ones in March, August and November 2025.
  • Only Claude Haiku, Sonnet and Opus models appeared in the disrupted cases; Claude Fable and Mythos were absent except for one illicit distillation case report-wide, and Anthropic says Mythos carries safeguards that greatly reduce its ability to perform harmful cyber tasks.
  • The lead cyber case, GTG-20006, is an actor whose attribution Anthropic says is consistent with public reporting linking it to Midnight Blizzard; its AI-driven workflows automated the group's toolkit development, phishing, command-and-control and exfiltration, and autonomously rebuilt malware whenever a security product detected it.
  • Anthropic's investigation found more than 20 organizations targeted, mostly government, defense and diplomatic bodies in Ukraine and Europe; the group also scanned more than two dozen Ukrainian government organizations' email and remote-access systems and stole a complete proprietary software development kit for a drone vision system from a military drone maker.
  • To reach some victims indirectly, GTG-20006 hijacked DNS at three or more hotel WiFi vendors, routing guests' traffic and device data to its own servers before delivering ClickFix-style malware to Windows, Android and iOS devices.

Why it matters

This report is Anthropic's own account of how state-linked and criminal actors are turning its models toward real attacks, and its central finding is structural: AI has closed much of the gap in skill and resources that used to separate well-funded state operations from lone individuals, so that sophistication is no longer a reliable signal of who is behind a given attack. The GTG-20006 case makes that concrete. A single group automated nearly the whole cyber kill chain, from building and retooling its malware to registering phishing domains, running command-and-control and evading detection, with the human operator's task reduced to refining the Claude Code skills that drove those workflows rather than running the operation by hand.

Who it affects

Anthropic's investigation names more than 20 targeted organizations, concentrated in Ukraine and Europe: government ministries, defense and intelligence bodies, embassies and diplomatic missions, think tanks and defense-industrial companies, plus a Southeast Asian government maritime body and a North African government technology authority. Within Ukraine specifically, the group scanned email and remote-access systems at more than two dozen government organizations. Drone-industry targets include at least two component manufacturers whose mailboxes were bulk-exported and a military drone maker whose vision-system software was stolen outright. Hotel guests are affected too: at least three hospitality WiFi vendors were compromised to hijack guests' DNS and route their traffic to the group's servers, a step used to individually target people connected to Ukraine, including government officials and drone manufacturers. More broadly, Anthropic frames the report as being for other AI developers and defenders who might see the same patterns on their own platforms.

How to use it

The report gives defenders concrete, source-backed indicators to watch for: DNS hijacking through compromised third-party WiFi or hosting vendors, ClickFix-style lures, phishing infrastructure built to mimic government targets, and malware that gets automatically rebuilt once detected rather than abandoned. It also names a specific tool worth knowing about, PentAGI, a publicly available offensive agent framework that Anthropic says reproduces much of the same kill-chain automation for anyone who downloads it, independent of Claude. For AI platforms generally, Anthropic's "uplift" framework, judging an actor's AI-driven capability gain by speed, scale and depth, offers a concrete lens for assessing misuse on their own services rather than relying on how sophisticated an actor appears.

How solid is it

This is a self-reported vendor account: Anthropic is describing misuse of its own product, based on its own internal logs and investigation, without an independent audit cited in the retrieved text. The text itself is not fully consistent: the report's introduction gives an eight-month lookback for the Threat Intelligence team's overall work, while the cyber-operations section separately states a six-month lookback, even though both describe the same December 2025 to August 2026 period. The Midnight Blizzard attribution is explicitly hedged as "consistent with public reporting" rather than presented as an independent confirmation. No outcome is given for GTG-20006 beyond "disrupted": the source does not say whether its operators were identified, arrested or referred to law enforcement, or whether the malware rebuild-and-evade loop kept succeeding afterward. A second case cited as an example of the same uplift trend, GTG-50014, is named only as a cross-reference, with no supporting detail in the retrieved text.

Risks and caveats

Six of the report's seven harm categories, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and distillation, are named in the introduction but have no case studies in the retrieved text, which develops only the cyber-operations section in depth. No total financial loss or overall victim count is given for GTG-20006 beyond the specific counts stated (more than 20 organizations, more than two dozen Ukrainian government bodies, at least two drone manufacturers, at least three hospitality vendors). The retrieved text cuts off mid-sentence, referencing an event in July 2026 that it does not describe. The report names no individual Threat Intelligence team members and gives no exact publication day beyond "September 2026." Readers should also keep in mind that terms like "autonomous" and "orchestrator" describing the AI's role are Anthropic's own characterization of activity on its own platform; no independent security researcher is quoted or cited in the retrieved text.

“For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation.”

— Anthropic's Threat Intelligence report, September 2026