{"id":23922,"date":"2026-09-12T06:29:34","date_gmt":"2026-09-12T06:29:34","guid":{"rendered":"https:\/\/scannn.com\/september-2026-anthropic-anthropic\/"},"modified":"2026-09-12T06:29:34","modified_gmt":"2026-09-12T06:29:34","slug":"september-2026-anthropic-anthropic","status":"publish","type":"post","link":"https:\/\/scannn.com\/lv\/september-2026-anthropic-anthropic\/","title":{"rendered":"September 2026 \/ Anthropic \\ Anthropic"},"content":{"rendered":"\n<div data-theme=\"ivory\">\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"ai-augmented-cyber-operations\">AI-augmented cyber operations<\/h3>\n<h4 class=\"Body-module-scss-module__z40yvW__reading-column headline-6 post-subsection\" id=\"cyber-operations-from-assistant-to-orchestrator\">Cyber operations: From assistant to orchestrator<\/h4>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Over the past six months, our Threat Intelligence team identified and disrupted a series of cyber operations in which threat actors used Claude. The actors included suspected state-sponsored groups, financially motivated criminals, and politically motivated individuals. This section presents some of those cases.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Throughout these case studies, the report will reference Generative Threat Groups (GTGs). These are Anthropic\u2019s internal designators for actors observed to be abusing AI. The report also attempts to measure uplift, a term we use to describe the AI capability boost, or how much more harm was caused with AI versus without AI. We view uplift through the lens of speed, scale, and depth, and attempt to determine how an actor\u2019s adoption of AI meaningfully impacts each of these traits.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Many commentators focus on the risk of AI developing exploits at scale. While this is a danger, the risk from AI adoption is more pronounced across the cyber kill chain, where adversaries can operate faster, across a broader and deeper surface area, with fewer resources.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The cases span the period from December 2025 through August 2026. In all cases, Claude Haiku, Sonnet, and Opus models were used; no malicious activity was found on Claude Fable or Mythos (which has a <a href=\"https:\/\/www.anthropic.com\/news\/fable-safeguards-jailbreak-framework\">series of safeguards <\/a>in place that greatly reduce its ability to perform harmful cyber tasks). In each case we disrupted the activity involved, strengthened our AI safeguards based on what we learned, and shared intelligence with authorities and industry partners where appropriate.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">In the following report, we begin by discussing the key trends that we\u2019ve observed in these cyber operations, then move to reporting the case studies and how they highlight those trends.<\/p>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"trends\">Trends<\/h3>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"sophisticated-attacks-no-longer-require-sophisticated-attackers\">Sophisticated attacks no longer require sophisticated attackers<\/h3>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators. In the case studies we report below, a hacktivist using stolen API keys, disparate financially motivated individuals, and a state espionage operator each sustained multi-victim campaigns that, even just a year ago, would have required many skilled operators and specialist knowledge.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation. Every layer of offensive operations has been uplifted by AI, from reconnaissance and tool development to data processing and exploitation. An example of this uplift in capabilities is documented in case study GTG-50014 (described below). The net effect of this uplift in capabilities is access to an increased <em>breadth <\/em>and <em>depth <\/em>of knowledge, which in turn drives <em>increased speed <\/em>of capability development and implementation.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">In November 2025, we documented an operating model used by a suspected state-sponsored campaign to carry out autonomous attacks. That operating model has now proliferated across every class of actors we investigated. Publicly available offensive agent frameworks, like <a href=\"https:\/\/github.com\/vxcontrol\/pentagi\">PentAGI<\/a>, reproduce much of the same scaffolding for anyone who downloads them. This scaffolding effectively automates each step of the cyber kill chain. The operators behind observed cases range from state services to lone individuals, across a widening set of countries. An example of this adoption of AI-enabled kill chains is documented in case study GTG-20006. As models continue to evolve and improve, we assess that more actors, from lone wolves to organized entities, will continue to adopt AI frameworks to enable more sophisticated cyber attacks at greater speed and scale.<\/p>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"ais-role-in-cyber-operations-has-become-increasingly-autonomous\">AI\u2019s role in cyber operations has become increasingly autonomous<\/h3>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">A majority of the operations described in this report were enabled by AI via direct execution or orchestration. The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration. Humans remained in the loop by setting the targets of attacks and reviewing exfiltration. An example of this trend is GTG-20006. This actor developed an AI-assisted workflow that automatically rebuilt and re-deployed their toolkit if it was detected by security products.<\/p>\n<h2 class=\"Body-module-scss-module__z40yvW__reading-column headline-4 post-heading\" id=\"gtg-20006-russian-espionage\">GTG-20006: Russian espionage<\/h2>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Historically, cyber espionage actors have followed a pattern of developing and deploying custom toolkits designed to evade detections. Actors would use these tools until defenders identified and built signatures to detect and block them, and there would then begin a new cycle of evasion and detection. Robust defenses and detections therefore created increased costs for adversaries. Now, however, the adoption of AI threatens to quickly and easily subvert defenders\u2019 ability to impose costs on adversaries via static detections alone.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">GTG-20006 is an actor who has increased their speed by automating their operations using AI. Our attribution is consistent with public reporting linking the actor to Midnight Blizzard. One of the operators is a Russian speaker using the handle \u201cJackPoterz\u201d whose tradecraft and targeting are consistent with Russian state-nexus espionage. They ran operations attacking military intelligence targets in Ukrainian and European governments, as well as diplomatic and defense organizations and individuals connected to US foreign policy. We observed GTG-20006 operate through customized AI-driven workflows that automated much of their operations from development, infrastructure acquisition, phishing, persistence through command and control, to data exfiltration.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">GTG-20006 employed a custom toolkit composed of two families of Windows-based implants, a mobile exploitation kit, a credential stealing tool that targets browser password stores, a phishing platform designed to mimic priority targets like government organizations, and an administrative console used to manage compromised accounts. Each of these tools was managed and re-tooled as needed during the cyber operations through AI-assisted workflows.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The actor also used AI to monitor how well their tools evaded detections from known security defenses. If their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections. The agents were designed to continue iterating on GTG-20006\u2019s toolkit until it was undetected. At that point, the tools were staged for live operations from disposable hosting servers where victim traffic was directed to retrieve the malware during their many cyber operations, including phishing, <a href=\"https:\/\/en.wikipedia.org\/wiki\/ClickFix\">ClickFix<\/a>, and DNS hijacking schemes.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The actor also used AI to drive their phishing operations. They developed AI-driven workflows to research then register domains and then configure the hosting infrastructure used to send phishing emails. Additional workflows were developed to send the emails and monitor the C2 channels for successful compromises. The human actor engaged primarily to modify Claude Code skills that drove the workflows when they needed to be refined.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Our investigation identified more than 20 distinct organizations targeted in the actor\u2019s operational planning, reconnaissance, and live operations. They included government ministries, defense and intelligence bodies, embassies and diplomatic missions, think tanks, and defense-industrial companies, concentrated in Ukraine and Europe but extending to the Middle East and maritime related government agencies in Asia. A common theme of the targeting was Ukraine and military drone technology providers and supply chains. Exceptions included a Southeast Asian government entity relating to maritime shipping and tracking, and a North African government technology authority.<\/p>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"cyber-operations\">Cyber operations<\/h3>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The most commonly recurring targets were members of the Ukrainian government, military, and diplomatic staff. The actor scanned email services and remote access systems across more than two dozen Ukrainian government organizations.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">A secondary recurring target for theft was drone supply chain technology. The actor bulk-exported the mailboxes of at least two drone component manufacturers, targeted a military drone maker, and stole a complete proprietary software development kit for a drone vision system. They spent several days reverse-engineering the drone\u2019s vision system, recovering its product architecture, its hardware bill of materials, its supplier dependencies, and details of an unannounced product. Military drone control and AI vision-related firmware appeared to be of particular interest.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Not all targets were direct: to reach their targets indirectly, the actor compromised at least three hospitality vendors that operate hotel guest WiFi. They used compromised admin credentials to modify DNS records so that they pointed to services owned by the actor (a technique known as DNS hijacking). Guests of hotels using the compromised vendors who connected to the hotel WiFi had their traffic, device identifier and IP address sent to the actor\u2019s servers. At that point, <a href=\"https:\/\/en.wikipedia.org\/wiki\/ClickFix\">ClickFix<\/a>-style lures were staged to deliver Windows, Android and iOS malware to the victim\u2019s device. The actor was able to use a combination of guest information stolen from the hotel management systems with the data stolen from individual guests\u2019 devices to focus additional targeting efforts. Particular targets of interest were individuals associated with Ukraine, including government officials and drone manufacturers. Note that in July 2026, Microsoft Threat Intelligence published a report on the method of theft and malware delivery used here, which they referred to as <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/07\/31\/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft\/\">CaptiveCrunch<\/a>.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The actor also took over victims\u2019 WhatsApp accounts, using a platform of <a href=\"https:\/\/en.wikipedia.org\/wiki\/Headless_browser\">headless browsers <\/a>to link victim accounts as companion devices. In part by using the <a href=\"https:\/\/github.com\/wppconnect-team\/wppconnect\">WPPConnect <\/a>open-source WhatsApp automation library, the actor\u2019s configuration suppressed read receipts so victims would not notice while it bulk-exported Russian and Ukrainian language conversations. At least two former high-level Ukrainian officials were targeted in this way.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The actor also targeted surveillance platforms. They found authorization flaws in the application interface of camera streaming services, and from there they enumerated users and harvested tokens that granted them access to the victims\u2019 live camera streams.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The same actor also conducted an intrusion of a North African government technology authority. They stole credentials to a VPN appliance, and used them to take over the organization\u2019s central account server. This allowed them to exfiltrate its full credential database: more than 300,000 national identity records, and the commercial registry data of more than half a million companies operating in the country.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The actor continued to develop a cloud email espionage platform that in part used \u201cEmbassy Kit,\u201d the actor\u2019s framework for managing device code phishing, to operate a Microsoft 365 token theft campaign. This platform, which was used to target diplomatic and government personnel, resulted in the access and exfiltration of mail records from at least eight organizations including a national prosecutor office, a military education institute, and a regional intergovernmental organization.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Windows credential stealers were delivered via fake update-themed social engineering lures, alongside companion payloads with full remote access capabilities. These payloads were designed to freeze the victim machine\u2019s security updates, meaning that new malware detection signatures published by security vendors would not be retrieved or run on the victim\u2019s machine.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The actor used AI at every point in their operations:<\/p>\n<ul class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">\n<li><strong>Reconnaissance:<\/strong> The actor used AI to fingerprint email and remote access systems and to harvest information from public sources, building target lists for phishing.<\/li>\n<li><strong>Initial access:<\/strong> The actor used AI to build and operate the platform that ran these cyber intrusion campaigns. The campaign\u2019s primary access technique was a form of device code phishing that abused legitimate sign-in flows for cloud email services (for further details on device code phishing see <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/04\/06\/ai-enabled-device-code-phishing-campaign-april-2026\/\">this post from Microsoft<\/a>.) The actor used AI to set up the phishing infrastructure and the exploitation tooling, and executed portions of the intrusions directly including running commands against victim systems, harvesting credentials, and moving laterally through networks under the actor\u2019s direction.<\/li>\n<li><strong>Collection and exfiltration:<\/strong> The actor used AI to perform the extraction and organization of hundreds of gigabytes of stolen data. In some cases, exfiltration was achieved via bulk exports from compromised mailboxes.<\/li>\n<li><strong>Maintaining access:<\/strong> The actor used AI to assist in maintaining access to compromised accounts and tenants by automating the registration of actor-controlled devices into the victim organization\u2019s tenant.<\/li>\n<\/ul>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">In on-premises environments, the actor used AI to monitor the stealth and persistence of their implants. When their implants were flagged by security products, the actor used Claude to systematically identify, modify and redeploy the detected artifacts.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The result of the above is that AI has inverted the cost back onto defenders. Previously, defenders might have been able to slow an attacker\u2019s operational tempo via the deployment of a new detection. Now, at least in theory, capable adversaries can \u201cclose the loop,\u201d bypassing traditional security detections faster than defenders can develop and deploy them.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The actor\u2019s malware included the following:<\/p>\n<ul class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">\n<li>Windows malware: PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc;<\/li>\n<li>Android malware: GiftDrop, a rebranded GiftsExpress Android surveillance RAT;<\/li>\n<li>iOS malware: DarkSword, an iOS exploit chain.<\/li>\n<\/ul>\n<h4 class=\"Body-module-scss-module__z40yvW__reading-column headline-6 post-subsection\" id=\"indicators-of-compromise\">Indicators of compromise<\/h4>\n<div class=\"Body-module-scss-module__z40yvW__media-column Body-module-scss-module__z40yvW__inline\">\n<div class=\"CodeBlock-module-scss-module__PbWBnq__codeBlock\">\n<pre class=\"\" style=\"--height:300px;--height-expanded:0px\"><code class=\"plaintext\">ms365-live[.]com\nteams.ms365-live[.]com\nm365-owa[.]com\nowa-ms365[.]com\nms365-device[.]com\nmslivetest.duckdns[.]org\nmy-invite[.]org\nchamber-ua[.]org\nchathamhouse[.]eu\nukrinform-share[.]net\n104.145.210[.]184\n31.57.243[.]154\nstatistic-ms[.]live\nstatic-ms[.]live\n104.194.151[.]133\nad-g[.]org\n104.194.159[.]55\ndocs-viewer[.]org\n144.172.114[.]192\nwa-connect[.]eu\nmygreatmarket[.]org\nmygreatmarket[.]com\n213.145.86[.]112\n2.26.53[.]194\ncdncounter[.]net\nstatic.cdncounter[.]net\nstuseamandesilt[.]org\napi.stuseamandesilt[.]org\ncdn.stuseamandesilt[.]org\nupdate.stuseamandesilt[.]org\nitechx[.]tel\npdfviewer2024.b-cdn[.]net\nmeridian-protocol[.]org\nmeridiangroup-corp[.]com\nprojectnightcrawler[.]dev\nmetricwave[.]org\nmgsend[.]org\n148.135.195[.]111\n185.198.234[.]26\n185.198.234[.]101\n149.54.42[.]106\n104.194.149[.]228\n38.146.28[.]132\n38.146.28[.]75\nwa-meeting[.]com\nrussianearabroad[.]com\nrussianearabroad[.]org\nanna.manager@russianearabroad[.]net\nevents@embassy-protocol[.]int\nmsedgeupdate_v3[.]exe\nmsedgeupdate[.]exe\nversion[.]dll\nWUEngine[.]exe\nDiagHost[.]exe\nclient_20260507093021_4286d211_x64[.]exe\nfix_network[.]apk\nbe99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c\n918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593<\/code><\/pre>\n<\/div>\n<\/div>\n<h2 class=\"Body-module-scss-module__z40yvW__reading-column headline-4 post-heading\" id=\"gtg-50014-shinyhunters-smash-and-grab-opportunists\">GTG-50014: ShinyHunters smash-and-grab opportunists<\/h2>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">While some cyber threat actors may conduct targeted intrusions, seeking specific information for espionage or other purposes, others are less focused and deliberate in their operations. These opportunistic hackers have historically used broad-based scanning techniques to identify and probe unpatched internet-facing systems, before exploiting these vulnerabilities to compromise or take over the target systems. We\u2019ve identified several advanced threat actors who used AI to uplift their opportunistic criminal activity, using Claude\u2019s capabilities to accelerate their ability to rapidly scan, exploit, and take over target systems.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Opportunistic attacks come in many forms: racing N-day patches for mass exploitation; rummaging through public container stores, code repos, mobile applications, websites and more looking for credentials, tokens, and API keys; mass scan and exploitation of vulnerable internet facing devices; the creation of service accounts on novice service providers with poor security to escape their containers; prompt injection of LiteLLM or OpenClaw deployments; and more.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Many actors scour the internet for ways into networks and services, stealing data for sale and extortion and later reselling access. This was the case before AI. With AI, however, the pre-existing ecosystem of criminal cyber conduct has increased in scale and severity. With AI, diverse target environments are made trivial to understand and adjust to; unique and obscure configurations are made clear and exploitable. The old adage of \u201csecurity through obscurity\u201d is no longer viable in this new AI-assisted world: everything connected to the internet is a potential target for exploitation.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Once actors gain access, they typically move straight to databases and look for customer data. If the target is a software-as-a-service (SaaS) provider, they often use the stolen data to access the end customers, and make extortion demands, telling the provider that all of their data and their customers\u2019 data will be leaked or sold online if they do not pay.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">We identified and disrupted multiple clusters of financially motivated cybercrime activity conducted by operators suspected to be affiliates of the <a href=\"https:\/\/en.wikipedia.org\/wiki\/ShinyHunters\">ShinyHunters <\/a>collective, known for several large-scale data theft operations followed by pay-or-leak extortion demands. Although the affiliates appear disparate, and seem to be operating with their own tooling and operational workflows, analysis of their approaches and objectives shows that they are part of the same overall operation.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><figcaption class=\"caption\">Figure 1. The attack lifecycle shared by the clusters of suspected ShinyHunters affiliates that we disrupted, from harvesting credentials to extortion.<\/figcaption><\/figure>\n<\/div>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">One French-speaking operator going by the aliases of (MeowSHA | frkoo | blazespider) ran a distributed credential-harvesting pipeline across a fleet of 10 AWS EC2 workers. This pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with <a href=\"https:\/\/github.com\/trufflesecurity\/trufflehog\">TruffleHog<\/a>. Verified findings were routed in real time to a Telegram group organized into over 100 source types. A parallel GitHub organization email harvester fed a second stream of stolen GitHub Personal Access Tokens. These two credential pipelines supplied the initial-access credentials for the bulk of the confirmed breaches associated with frkoo.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Operational security discipline by the operators was mixed. frkoo managed an EC2-based credential-harvesting pipeline, exposed their own EC2 staging IP, multiple Telegram bot tokens, a Squid proxy with hardcoded credentials and at least one public paste-site upload directly within a victim environment. They also registered a domain name impersonating the French national police, policenationale[.]cc (though we believe this served as branding for the criminal storefront rather than as a phishing lure). The subdomain autoshop.policenationale[.]cc served as the web frontend for the actor\u2019s carding autoshop: a storefront selling stolen payment-card records (\u201cfiches\u201d) enriched with BIN lookups, full cardholder PII, and an interactive geolocation map of victim addresses. The shop was delivered to customers through a Telegram Mini App (@Soraki_Bot) backed by the actor\u2019s \u201cSoraki\u201d platform, a PostgreSQL\/GraphQL stack that also aggregated multiple French breach datasets (including a ~400,000-record telecom\/ISP dataset with IBANs and BICs) into a searchable service.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Across the collective of operators, during multiple target intrusions, a target\u2019s AI API keys were stolen from the target\u2019s enterprise software vendors. One of the stolen API keys was then used by the attacker for roughly three weeks to conduct secondary attacks, which targeted other organizations including compromising a French retail chain and probing a Web3 identity platform. They also continued post-breach attacks against a nonprofit victim, and in the case of frkoo, continued development work on their own carding shop that masqueraded as a French police department site.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">One of the more serious compromises was of a technology provider. The operators exfiltrated more than a terabyte of data, including hundreds of thousands of national identifiers and millions of payment card records, then staged the stolen material on a public website to pressure the victim into paying a ransom. At an airline, the threat actors accessed systems holding tens of millions of passenger records. At an energy company, the operators claimed that they could remotely control the charging current of electric-vehicle chargers installed in customers\u2019 homes.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Another affiliate appeared to specialize in supply-chain theft, where a company is compromised in order to reach the downstream data of their customers. After breaching a software-as-a-service provider, the operators used that foothold to extract data belonging to roughly 200 of the SaaS company\u2019s downstream customer organizations. It then conducted a session-store dump containing over 2,100 Azure AD token sets spanning more than 40 corporate tenants in about 34 hours. AI agents performed nearly all of the work.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">In a different compromise, the actor leveraged Claude in a supply chain compromise of a software-as-a-service (SaaS) vendor to accelerate reconnaissance and to enable data exfiltration. The actor exploited a cross-site scripting vulnerability to gain access, escalated privileges, and ultimately exfiltrated data from thousands of downstream customer organizations. The actor used Claude by helping to identify, understand, and use developer and authentication APIs, create and convert privileged tokens, and build tools to enable bulk exports and cross-tenant data collection. Against a different target, the same attacker also claimed to have collected legitimate HackerOne bug-bounty payouts of $2,000 and $5,000 from two of the companies they infiltrated and extorted, treating BugBounty disclosure programs and intrusion as additional revenue streams against the same targets they were compromising. They also appeared to scrape HackerOne and BugBounty submissions as a form of reconnaissance during focused attacks on specific targets.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">This threat actor\u2019s operational tempo was relatively consistent. One breach of an enterprise software company took only hours from first access to bulk data theft. Another compromise escalated from a single stolen developer token to full administrative control of a victim\u2019s cloud environment in roughly three hours. This was followed by iteratively scraping internal datastores, and in the case of supply chain attacks, iteratively accessing and scraping the end customer\u2019s data as well. We detected and banned accounts associated with the ShinyHunters associates, implemented measures to detect and disrupt future misuse from the actors, and engaged government authorities, industry partners, and victims to remediate threats posed by the actors.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The use of AI during intrusions and data theft operations often resembles \u201c<a href=\"https:\/\/www.anthropic.com\/news\/detecting-countering-misuse-aug-2025\">vibe hacking<\/a>,\u201d wherein operators direct AI to achieve general goals like using a credential for an entity or retrieving data from a broad set of targets, then allow the AI to evaluate the environment, author and execute scripts, provide summaries, and repeatedly execute until the task is complete. Very often, the operator may not directly understand each target environment or the complexities of finding and accessing valuable information, instead deferring the specifics to the AI.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Security practitioners use the phrase \u201cliving off the land\u201d to describe attacks that use tools that are already present in the victim\u2019s environment. The opportunistic hackers described in this section have applied the same principles to AI. The operators treated the AI supply chain itself as both a target and a resource. They stole AI API keys from multiple target environments and used them to provide additional AI compute. In every instance, the API keys involved were stolen from Anthropic customers\u2019 environments. Anthropic\u2019s own systems were not compromised by this actor. We examine this pattern in detail in the section on the AI supply chain.<\/p>\n<h4 class=\"Body-module-scss-module__z40yvW__reading-column headline-6 post-subsection\" id=\"attack-lifecycle-and-ai-integration\">Attack lifecycle and AI integration<\/h4>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1920\" height=\"500\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fed4f8197b659c784685ee2be7b6f02efb523ee91-1920x500.jpg&amp;w=1920&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fed4f8197b659c784685ee2be7b6f02efb523ee91-1920x500.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fed4f8197b659c784685ee2be7b6f02efb523ee91-1920x500.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 2. The attack lifecycle and AI integration.<\/figcaption><\/figure>\n<\/div>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\"><strong>Sourcing and recon.<\/strong> Most intrusions began from compromised credentials. The actor also engaged in extensive scanning, vishing, phishing and domain spoofing operations to trick employees into giving access to systems.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1999\" height=\"823\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fd5167078d1d9356e40f423a712471b3d4f859c18-1999x823.jpg&amp;w=2048&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fd5167078d1d9356e40f423a712471b3d4f859c18-1999x823.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fd5167078d1d9356e40f423a712471b3d4f859c18-1999x823.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 3. Sourcing and recon.<\/figcaption><\/figure>\n<\/div>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\"><strong>Discover.<\/strong> Exposed access tokens were also discovered at industrial scale through a wide variety of automated scraping and mining projects. These included analyzing application binaries, code repositories and integrations, client side code, credential stores, container images, metadata endpoints, open storage and victim-deployed AI agents. An example of this is with one actor project that downloads all APK files from Google Play Store and searches them for exposed session tokens or other access mechanisms that could be abused for access.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1999\" height=\"1193\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F501c3ff9d2bbd9362435907d7235e114db66031a-1999x1193.jpg&amp;w=2048&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F501c3ff9d2bbd9362435907d7235e114db66031a-1999x1193.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F501c3ff9d2bbd9362435907d7235e114db66031a-1999x1193.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 4. Discover.<\/figcaption><\/figure>\n<\/div>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\"><strong>Validate\/qualify.<\/strong> Everything found is tested and qualified before use or resale, such as batch cloud key validation, purpose built login oracles, live replay against production, grading for resale value, and offline cracking.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1999\" height=\"792\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F9ce01ce0e7381c9e67125c0c12089f542a137ebc-1999x792.jpg&amp;w=2048&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F9ce01ce0e7381c9e67125c0c12089f542a137ebc-1999x792.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F9ce01ce0e7381c9e67125c0c12089f542a137ebc-1999x792.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 5. Validate\/qualify.<\/figcaption><\/figure>\n<\/div>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\"><strong>Expand in-victim.<\/strong> One working credential is used to expand access within the victim, and used for things like whole-cluster secret dumps, admin-token amplification, CI\/CD injection, database and session-table dumps, mining dumps for signing keys, and vendor-OAuth fan-out to every downstream tenant.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1999\" height=\"866\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F6a6bd5fa483b30c5bfe9fbc894d9a8de93501d02-1999x866.jpg&amp;w=2048&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F6a6bd5fa483b30c5bfe9fbc894d9a8de93501d02-1999x866.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F6a6bd5fa483b30c5bfe9fbc894d9a8de93501d02-1999x866.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 6. Expand in-victim.<\/figcaption><\/figure>\n<\/div>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\"><strong>Exfil channels.<\/strong> Material moves out over six channels: consumer cloud storage, a private NAS over mesh-VPN, Telegram bot streams, staging inside victim clouds, C2 channels, and plain bulk API pulls.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1999\" height=\"792\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F880dd51cfdf39c25162963dbf03608811faf4010-1999x792.jpg&amp;w=2048&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F880dd51cfdf39c25162963dbf03608811faf4010-1999x792.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F880dd51cfdf39c25162963dbf03608811faf4010-1999x792.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 7. Exfil channels.<\/figcaption><\/figure>\n<\/div>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\"><strong>Warehouse.<\/strong> Loot is warehoused for reuse and sale: a self-hosted estate that re-serves stolen databases, loot trees for each victim, a Telegram warehouse that also serves as the storefront, and working key stores.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1999\" height=\"760\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F360fd2e670b587c3dc2f91c5f1ba8b0284abb790-1999x760.jpg&amp;w=2048&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F360fd2e670b587c3dc2f91c5f1ba8b0284abb790-1999x760.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F360fd2e670b587c3dc2f91c5f1ba8b0284abb790-1999x760.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 8. Warehouse.<\/figcaption><\/figure>\n<\/div>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\"><strong>Mint\/persist.<\/strong> New credentials and durable access are minted so the operation outlives rotation: cloud API keys in victim accounts, platform developer keys, forged sessions and 2FA codes, network backdoors.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1999\" height=\"760\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fc5504af2b3b96d4b74f7b9c6b4b220ea8bf0f0a3-1999x760.jpg&amp;w=2048&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fc5504af2b3b96d4b74f7b9c6b4b220ea8bf0f0a3-1999x760.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fc5504af2b3b96d4b74f7b9c6b4b220ea8bf0f0a3-1999x760.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 9. Mint\/persist.<\/figcaption><\/figure>\n<\/div>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\"><strong>Monetize.<\/strong> Monetization: resale channels and key pools, direct financial theft, extortion over the stolen data, dual-hat bounty income, and bulk data held for leverage.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1999\" height=\"760\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fbb32ff7c140deed4174bf8fe87ba5a053a999567-1999x760.jpg&amp;w=2048&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fbb32ff7c140deed4174bf8fe87ba5a053a999567-1999x760.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fbb32ff7c140deed4174bf8fe87ba5a053a999567-1999x760.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 10. Monetize.<\/figcaption><\/figure>\n<\/div>\n<h4 class=\"Body-module-scss-module__z40yvW__reading-column headline-6 post-subsection\" id=\"common-workflows-observed\">Common workflows observed<\/h4>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1813\" height=\"1999\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F9ca8558aea18b56c588e1fb34b6b8cbd01bf093a-1813x1999.jpg&amp;w=1920&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F9ca8558aea18b56c588e1fb34b6b8cbd01bf093a-1813x1999.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F9ca8558aea18b56c588e1fb34b6b8cbd01bf093a-1813x1999.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 11. Common workflows observed.<\/figcaption><\/figure>\n<\/div>\n<h4 class=\"Body-module-scss-module__z40yvW__reading-column headline-6 post-subsection\" id=\"indicators-of-compromise\">Indicators of compromise<\/h4>\n<div class=\"Body-module-scss-module__z40yvW__media-column Body-module-scss-module__z40yvW__inline\">\n<div class=\"CodeBlock-module-scss-module__PbWBnq__codeBlock\">\n<pre class=\"\" style=\"--height:300px;--height-expanded:0px\"><code class=\"plaintext\">updatebeacon.duckdns[.]org\nesvfecawvjmchjslqyemho2fiduc59wzn.oast[.]fun\nsoraki-proxy.20245aad98d27b1b1a2f0f103e1d7ee0.workers[.]dev\nsoraki[.]cc\nsoraki[.]work\npolicenationale[.]cc\nemailsecure[.]email\nmozilla[.]ws\nsignin-1psswoord[.]com\non-pssword[.]com\nari-chain[.]com\narichain[.]network\nbitmart-mystery[.]com\ndefi-claim[.]xyz\nservice-infos[.]info\n0x0[.]st \/\/ Exfiltration file uploads via curl<\/code><\/pre>\n<\/div>\n<\/div>\n<h4 class=\"Body-module-scss-module__z40yvW__reading-column headline-6 post-subsection\" id=\"exfiltration-locations\">Exfiltration locations<\/h4>\n<div class=\"Body-module-scss-module__z40yvW__media-column Body-module-scss-module__z40yvW__inline\">\n<div class=\"CodeBlock-module-scss-module__PbWBnq__codeBlock\">\n<pre class=\"\" style=\"--height:300px;--height-expanded:0px\"><code class=\"plaintext\">fuckyoubasil[@]s3.ap-tokyo.megas4[.]com\nhttps[:]\/\/s3.eu-central-1.s4.mega[.]io\/fuckyoubasil\/\nhttps[:]\/\/s3.ap-tokyo.megas4[.]com\/&lt;victim-name&gt;\n&lt;victim-name&gt;.s3.ap-tokyo.megas4[.]com<\/code><\/pre>\n<\/div>\n<\/div>\n<h4 class=\"Body-module-scss-module__z40yvW__reading-column headline-6 post-subsection\" id=\"telegram-group-ids\">Telegram group IDs<\/h4>\n<div class=\"Body-module-scss-module__z40yvW__media-column Body-module-scss-module__z40yvW__inline\">\n<div class=\"Table-module-scss-module__Z3bHXa__root\">\n<div aria-label=\"Table 1. Telegram group IDs.\" class=\"Table-module-scss-module__Z3bHXa__tableWrapper\" role=\"region\" tabindex=\"0\">\n<table class=\"Table-module-scss-module__Z3bHXa__table\">\n<tbody>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<th class=\"body-3\"><strong>Indicator<\/strong><\/th>\n<th class=\"body-3\"><strong>Type<\/strong><\/th>\n<th class=\"body-3\"><strong>Description<\/strong><\/th>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">-1003893854338<\/td>\n<td class=\"body-3\">Telegram group\/chat ID<\/td>\n<td class=\"body-3\">Private group named \u201cClintonHog.\u201d Received the first wave of verified stolen credentials from the actor\u2019s APK secret-scanning pipeline.<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">-1003311614569<\/td>\n<td class=\"body-3\">Telegram group\/chat ID<\/td>\n<td class=\"body-3\">Private group named \u201cChatMignon.\u201d Primary exfiltration channel: 471 forum topics, one per secret-detector type, receiving verified stolen credentials in real time.<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">8632748474<\/td>\n<td class=\"body-3\">Telegram bot account ID<\/td>\n<td class=\"body-3\">Bot posting pipeline findings into group -1003893854338 (\u201cClintonHog\u201d).<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">8664033117<\/td>\n<td class=\"body-3\">Telegram bot account ID<\/td>\n<td class=\"body-3\">Bot posting pipeline findings into group -1003311614569 (\u201cChatMignon\u201d).<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">8628746407<\/td>\n<td class=\"body-3\">Telegram bot account ID<\/td>\n<td class=\"body-3\">Bot delivering AWS SES credential-validation results directly to the operator\u2019s user account.<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">8709258476<\/td>\n<td class=\"body-3\">Telegram bot account ID<\/td>\n<td class=\"body-3\">Bot delivering AWS SNS SMS-abuse test results directly to the operator\u2019s user account.<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">8179098353<\/td>\n<td class=\"body-3\">Telegram user ID<\/td>\n<td class=\"body-3\">Operator account receiving the SES\/SNS bot output.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div><figcaption class=\"caption\">Table 1. Telegram group IDs.<\/figcaption><\/div>\n<\/div>\n<h4 class=\"Body-module-scss-module__z40yvW__reading-column headline-6 post-subsection\" id=\"attacker-egress-ips\">Attacker egress IPs<\/h4>\n<div class=\"Body-module-scss-module__z40yvW__media-column Body-module-scss-module__z40yvW__inline\">\n<div class=\"Table-module-scss-module__Z3bHXa__root\">\n<div aria-label=\"Table 2. Attacker egress IPs.\" class=\"Table-module-scss-module__Z3bHXa__tableWrapper\" role=\"region\" tabindex=\"0\">\n<table class=\"Table-module-scss-module__Z3bHXa__table\">\n<tbody>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<th class=\"body-3\"><strong>IP<\/strong><\/th>\n<th class=\"body-3\"><strong>Start Date<\/strong><\/th>\n<th class=\"body-3\"><strong>End Date<\/strong><\/th>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">162.128.129[.]106<\/td>\n<td class=\"body-3\">2026-02-20<\/td>\n<td class=\"body-3\">2026-03-10<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">195.178.110[.]131<\/td>\n<td class=\"body-3\">2026-03-12<\/td>\n<td class=\"body-3\">2026-04-30<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">45.148.10[.]242<\/td>\n<td class=\"body-3\">2026-04-06<\/td>\n<td class=\"body-3\">2026-04-27<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">92.118.39[.]3<\/td>\n<td class=\"body-3\">2026-04-10<\/td>\n<td class=\"body-3\">2026-04-19<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">185.65.134[.]246<\/td>\n<td class=\"body-3\">2026-04-19<\/td>\n<td class=\"body-3\">2026-05-04<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">185.65.134[.]199<\/td>\n<td class=\"body-3\">2026-04-19<\/td>\n<td class=\"body-3\">2026-04-28<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">193.32.249[.]161<\/td>\n<td class=\"body-3\">2026-03-21<\/td>\n<td class=\"body-3\">2026-04-18<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">193.32.249[.]164<\/td>\n<td class=\"body-3\">2026-04-18<\/td>\n<td class=\"body-3\">2026-05-06<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">193.32.249[.]170<\/td>\n<td class=\"body-3\">2026-03-20<\/td>\n<td class=\"body-3\">2026-04-06<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">104.36.50[.]54<\/td>\n<td class=\"body-3\">2026-04-24<\/td>\n<td class=\"body-3\">2026-04-24<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">104.193.135[.]207<\/td>\n<td class=\"body-3\">2026-04-05<\/td>\n<td class=\"body-3\">2026-04-05<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">2a04:cec0:1185:34f2:a150:7081:caed[:]448e<\/td>\n<td class=\"body-3\">2026-04-06<\/td>\n<td class=\"body-3\">2026-04-07<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">2a01:e0a:2e2:aa40:b15d:5d28:6f4a[:]8d53<\/td>\n<td class=\"body-3\">2026-04-20<\/td>\n<td class=\"body-3\">2026-04-21<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">91.171.138[.]169<\/td>\n<td class=\"body-3\">2026-04-19<\/td>\n<td class=\"body-3\">2026-04-21<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">176.177.12[.]62<\/td>\n<td class=\"body-3\">2026-04-19<\/td>\n<td class=\"body-3\">2026-04-20<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div><figcaption class=\"caption\">Table 2. Attacker egress IPs.<\/figcaption><\/div>\n<\/div>\n<h2 class=\"Body-module-scss-module__z40yvW__reading-column headline-4 post-heading\" id=\"gtg-10007-exploit-foundries-and-autonomous-attack-frameworks\">GTG-10007: Exploit foundries and autonomous attack frameworks<\/h2>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Historically, cyber operations have been limited in their scale and impact by two key constraints: the supply of working offensive exploits, and the supply of skilled operators capable of deploying those exploits. We have identified multiple threat actors who have effectively established automated exploit foundries with AI. In doing so, they have designed and implemented autonomous workflows by which they can direct Claude to conduct vulnerability and exploit research agentically around the clock. Across multiple instances, we identified Claude being used to meaningfully accelerate the pace of vulnerability research, testing, and exploit design.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">We identified and investigated a sustained espionage operation, tracked as GTG-10007, conducted by Chinese-speaking operators likely residing in Changsha in China\u2019s Hunan province. Two of the operators were identified as undergraduate students at a Chinese university in Hunan studying curriculum in a School of Computer &amp; Communication Engineering. One had a prior internship at a Chinese security company, Sangfor, and was actively interviewing for a role at a different Chinese security company, QiAnXin, for an offensive cyber operations role. Multiple operators within this group used Claude as the engineering and orchestration layer of a coordinated offensive program involving a variety of tasks: intrusion attempts against production systems; reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia; a standing vulnerability-research and exploit development effort against major endpoint-security products; malware development; and an intelligence-collection platform. Notably, a team ran parallel workstreams that had shared tooling and infrastructure bases and persistent campaign records that maintained context between working sessions; it also had collection and vulnerability research capabilities that kept operating while its owners were away.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The actor targeted roughly fifty organizations, spanning education, retail, energy, technology, healthcare, finance, manufacturing, as well as multiple government agencies globally. The actor compromised an education-technology company, extracting hundreds of megabytes of bulk student personal data from the company\u2019s cloud storage. They also gained access to a retail company\u2019s production systems, reaching internal hosts and demonstrating their ability to modify the live environment. Finally, they targeted a Southeast Asian government agency, retrieving citizen records including names, phone numbers, and home addresses.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The group maintained an autonomous vulnerability research program. Its centerpiece was sustained research against a major security product (of a class of software deployed specifically to detect intrusions) which produced multiple previously-unknown vulnerabilities that were validated by the actor in their own lab environment. The same research effort produced working exploits for several families of network and security appliances. In a separate workflow, the actor was observed conducting cyber operations involving exploitation attempts against those same appliances owned by multiple government organizations globally. We banned accounts associated with the actors and deployed additional monitoring to detect and ban related activity.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Distinct workstreams were run in parallel. One workflow conducted cyber operations involving exploitation and intrusions, another performed foreign-government reconnaissance, another reverse-engineered security products in search of new vulnerabilities, another developed and tested custom malware, and another built and maintained collection infrastructure.<\/p>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"autonomous-espionage\">Autonomous espionage<\/h3>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The operators routinely ran \u201cagent swarms,\u201d where a lead AI agent decomposed reconnaissance and post-exploitation work and dispatched it to many subagents running in parallel. The operation maintained persistent campaign memory. Target lists, harvested credentials, engagement state, and standing instructions were saved across working sessions, so each session could be resumed mid-campaign with the program\u2019s accumulated context. The cluster built and operated an intelligence-collection platform that ran unattended bulk harvesting of open-source material aligned with state intelligence priorities (including publicly accessible military doctrine and official publications, regional defense reporting, and policy sources).<\/p>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"appliance-zero-day-research-binary-reversing-and-exploit-development-loop\">Appliance zero-day research: Binary reversing and exploit-development loop<\/h3>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The following is a brief description of the loop the actor used in its zero day exploit foundry operations. The actor configured autonomous AI-driven workflows to target appliance firmware and binaries. The workflow started with loading firmware and binaries into a decompiler through a tool server. An assistant agent surveyed the image, and walked decompilation and cross-reference chains (over thousands of decompile calls, with back-to-back decompile sequences dominating the call stream). It then formed vulnerability hypotheses against a knowledge base it curated over time and prior proof-of-concept lookups. From there, the workflow tasked the writing of exploit code against those hypothesized vulnerabilities, and tested the code against lab copies of the target product. The workflow iterated over edits of the exploit code until success, at which point the chain landed in the operator\u2019s private exploit portfolio.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Vendor firmware images were obtained and decrypted with a purpose-built skill, unpacked into root filesystems, and loaded into disassembler and audit sessions. Vulnerability patterns were hunted component-by-component with parallel agents instructed to require evidence and use project memory. One workflow iterating continuously on network appliances yielded more than a dozen possible zero day findings in a single month.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1920\" height=\"471\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F72970785999715f22b78c4fc2d0e2f20786fdfd3-1920x471.jpg&amp;w=1920&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F72970785999715f22b78c4fc2d0e2f20786fdfd3-1920x471.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F72970785999715f22b78c4fc2d0e2f20786fdfd3-1920x471.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 12. Appliance zero-day research: binary reversing and exploit-development loop.<\/figcaption><\/figure>\n<\/div>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"attack-surface-and-osint-reconnaissance-loop\">Attack-surface and OSINT reconnaissance loop<\/h3>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Other AI workflows ran continuously to conduct reconnaissance. This workflow took input for scan scopes seeded from target verticals and ran through an asset search engine via a dedicated tool server and bundled probing tools that fingerprinted the results. The identified exposed surface was mapped and entry points were qualified against known vulnerabilities. Each round\u2019s findings fed a persistent project memory, and expanded the target set for the next sweep. The actor used the framework to target multiple foreign government and diplomatic agencies, in addition to over a dozen domestic Chinese companies.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1920\" height=\"471\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Ff3ddd5297b62ba79c500e9d921a6bafbf7dfb954-1920x471.jpg&amp;w=1920&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Ff3ddd5297b62ba79c500e9d921a6bafbf7dfb954-1920x471.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Ff3ddd5297b62ba79c500e9d921a6bafbf7dfb954-1920x471.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 13. Attack-surface and OSINT reconnaissance loop.<\/figcaption><\/figure>\n<\/div>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"autonomous-collection-fleet-loop\">Autonomous collection-fleet loop<\/h3>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">A fleet of thirteen standing collection AI agents ran on a scheduled job to identify and download content from target websites, including publicly accessible US military and government sites like contract postings, and social media personas. The workflow did this through layered crawlers, anti-bot bypass techniques, and commercial proxy exits. An adjacent pipeline summarized and scored the retrieved content with an intelligence report-styled framing. From there, the workflow digests were delivered to a distribution portal.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1920\" height=\"471\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F966baae8ca495387317bcf4fe8c4147522584903-1920x471.jpg&amp;w=1920&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F966baae8ca495387317bcf4fe8c4147522584903-1920x471.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F966baae8ca495387317bcf4fe8c4147522584903-1920x471.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 14. Autonomous collection-fleet loop.<\/figcaption><\/figure>\n<\/div>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"hands-on-intrusions\">Hands-on intrusions<\/h3>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The operator engaged primarily in development, workflow output consumption related areas and during intrusion events produced from the autonomous exploitation workflows or in cases where access was obtained through weak or harvested credentials and exposed consoles. With access to internal networks, the AI assistant enumerated hosts, escalated via credential reuse and exposed management surfaces, harvested credentials and data stores, and staged material back to operator infrastructure then pivoted to the next host on what was harvested. Despite targeting entities globally in AI workflows, the actor concentrated hands-on efforts exclusively on domestic China victims.<\/p>\n<h2 class=\"Body-module-scss-module__z40yvW__reading-column headline-4 post-heading\" id=\"ai-supply-chain-as-target-loot-and-attack-compute\">AI supply chain as target, loot, and attack compute<\/h2>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Access to the uplift granted by AI is highly sought after by malicious actors and the broader criminal economy. Access to AI in the form of compromised API keys, session tokens, and devices has increasingly become the sole objective of multiple criminal groups. These groups then often sell that access through brokers, which often feed into fraudulent AI reseller networks that rotate in new stolen API keys and session tokens until they exhaust their usage. Malicious actors also use or purchase these stolen API keys and session tokens from brokers for their cyber attack operations.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">A criminal AI supply chain has established a range of pathways to farm victim API keys and session tokens. One such approach involved masquerading as real AI service providers to deliver malware. The actor stood up websites that purported to be an intermediary service between multiple AI models and offered discounted access to frontier AI models. Site visitors would be compromised in a variety of ways, the most persistent one was by having the victims download and install malicious client side applications often spoofing as popular AI harnesses including Claude Code but were in fact credential harvesters that would gather all of the victim\u2019s credentials and authenticated session tokens on their device and send them to the attacker. That included any AI related session tokens or API keys on the victim\u2019s device. As the victim\u2019s API keys or account may be identified as compromised and reset, the credential harvester continued to identify any new sessions on the device and sent them to the actor. In so doing the actor effectively mimicked the same fraudulent reseller networks they were supplying compromised credentials to but instead used this scheme to have victims continuously feed their credentials to the attacker and subsequently be sold to the fraudulent resellers.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">GTG-50021 is a group that engaged in similar activity. They are a Russian and Ukrainian speaking group, one of whom went by the alias \u201ckl1zy.\u201d They ran a fraudulent AI reseller operation offering cheap Claude access\u2014which turned out to be neither cheap nor actually Claude. Customers believed they were buying discounted Claude access, but their traffic was in fact silently proxied to a different AI model while the reseller\u2019s tooling installed a credential harvester, stealing their Anthropic account credentials and selling them onward to other AI proxy resellers for malicious use.<\/p>\n<h4 class=\"Body-module-scss-module__z40yvW__reading-column headline-6 post-subsection\" id=\"gtg-50021-indicators-of-compromise\">GTG-50021 indicators of compromise<\/h4>\n<div class=\"Body-module-scss-module__z40yvW__media-column Body-module-scss-module__z40yvW__inline\">\n<div class=\"CodeBlock-module-scss-module__PbWBnq__codeBlock\">\n<pre class=\"\" style=\"--height:300px;--height-expanded:0px\"><code class=\"plaintext\">awstore[.]cloud\nkiro[.]cheap\nsys-tools[.]cfd\naws-us-east-3[.]com\nholdboost[.]store\ndeltaclient[.]xyz\niymkjuzymkapovrntoxy.supabase[.]co<\/code><\/pre>\n<\/div>\n<\/div>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">There are also groups that attempt to target the AI ecosystem and supply chain itself, seeking to gain access to restricted models via AI vendors, evaluators, and trusted access programs. For example, multiple actors were observed compromising AI wrapper services\u2019 implementation of LiteLLM\u2014they used prompt injection to exfiltrate the production API keys used in their cloud-hosted container environments.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Fraudulent resellers have increasingly been supplied by compromised access. Most commonly, this comes from legitimate customers who have inadvertently exposed their API keys and session tokens in their products, applications and public code such as GitHub, mobile application install files, Docker containers, websites, and chatbots. Malicious actors are constantly mining these sources for exposed keys and analyzing them for authentication abuse vectors.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Operators who obtain AI credentials gain three things at once:<\/p>\n<ul class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">\n<li><strong>Loot<\/strong>: Stolen keys and accounts have resale value in established markets;<\/li>\n<li><strong>Compute<\/strong>: Having the credentials means that their attack workloads can run at someone else\u2019s expense;<\/li>\n<li><strong>Cover<\/strong>: The activity is attributed to the credential\u2019s legitimate owner.<\/li>\n<\/ul>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">A hacktivist campaign (described later in this report) ran for a month entirely on stolen API keys. ShinyHunters affiliates, on obtaining a victim\u2019s AI keys during an intrusion, switched their own attack workloads onto the victim\u2019s keys. GTG-50020, after compromising an AI vendor\u2019s evaluation sandbox, took its production keys first.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">AI API keys and session tokens are targets; the integrations customers build around AI such as sandboxes, proxies, and resellers are part of the attack surface. Organizations should treat AI keys and agent integrations with the same level of seriousness as they do production credentials\u2014because attackers treat them with the same level of seriousness, too. AI access should be purchased only through authorized channels. An alleged discount that requires routing traffic and credentials through an unknown intermediary introduces tremendous risk to user data and systems.<\/p>\n<h2 class=\"Body-module-scss-module__z40yvW__reading-column headline-4 post-heading\" id=\"gtg-50020-from-hotel-bookings-to-the-ai-supply-chain\">GTG-50020: From hotel bookings to the AI supply chain<\/h2>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">GTG-50020 is a Russian-speaking, financially-motivated actor who had historically conducted intrusions against hotel booking and financial technology platforms. In one intrusion, they exfiltrated roughly 26 gigabytes of data from one victim and sought payment in extortion attempts (or from selling the data on darkweb forums) of between $1.5 and 2.5 million.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">They then redirected the same tradecraft towards the AI industry. By injecting malicious instructions into an AI vendor\u2019s automated evaluation sandbox, the actor caused the sandbox to hand over the credentials it held\u2014including the production AI API keys from multiple providers belonging to that vendor.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Those stolen keys were then abused by the actor: they continued their intrusion attempts against the vendor and other unrelated targets simultaneously. In effect, when they obtained the target\u2019s API keys, they automatically switched to using the victim\u2019s keys instead of their own. A follow-on campaign run from the same infrastructure attacked roughly thirty AI companies in about four days with similar techniques. They identified one successful attack path and repeated it against all thirty targets, adapting slightly to account for differences across the targets. The actor\u2019s stated goal, pursued across more than a dozen avenues, was access to a pre-release Claude model. The actor never gained access; every attempted path failed. In all of this, the keys involved were customers\u2019 keys stolen from customers\u2019 environments. The actor never compromised Anthropic\u2019s own systems.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">This case is the clearest demonstration to date that the AI supply chain has become a deliberate criminal target. The actor pursued AI vendors for their production API keys, and had an explicit ambition\u2014which, to be clear, was never realized\u2014to gain access to pre-release AI models.<\/p>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"human-directed-ai-pentest-loop\">Human-directed AI pentest loop<\/h3>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The operator maintained a per-target scope file that launched a custom workflow to delegate work to parallel reconnaissance and exploitation agents. The agent\u2019s findings were re-tested for working access; if viable, they were merged into an incremental report. This workflow iteratively looped against the next target domain.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1920\" height=\"496\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F0c118bda9102ec213c6035fb16a4847509c49e1b-1920x496.jpg&amp;w=1920&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F0c118bda9102ec213c6035fb16a4847509c49e1b-1920x496.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F0c118bda9102ec213c6035fb16a4847509c49e1b-1920x496.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 15. Human-directed AI pentest loop.<\/figcaption><\/figure>\n<\/div>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"autonomous-exploitation-pipeline\">Autonomous exploitation pipeline<\/h3>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The actor used a containerized open-source pentest platform fronted by a local model gateway. It was aimed at a target\u2019s web applications. Worker agents ran injection, XSS, authentication-bypass, and SSRF testing without human supervision, collecting potential findings and credentials into the operator\u2019s workspace. This loop was run with exploitation enabled against production systems, meaning it both attempted to identify vulnerabilities and actively exploit them for access in the same workflows.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1920\" height=\"471\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fd67f43c0159621c1e7b84b5cc5245f0e2bed40a2-1920x471.jpg&amp;w=1920&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fd67f43c0159621c1e7b84b5cc5245f0e2bed40a2-1920x471.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fd67f43c0159621c1e7b84b5cc5245f0e2bed40a2-1920x471.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 16. Autonomous exploitation pipeline.<\/figcaption><\/figure>\n<\/div>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"fraud-account-factory\">Fraud account factory<\/h3>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Residential proxies and antidetect browser profiles were provisioned, after which bots drove signup flows on exchange and marketplace targets. Commercial CAPTCHA-solving services, automated inbox polling, and automated identity-verification steps defeated onboarding controls, and the resulting verified accounts were banked for later operations.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1920\" height=\"471\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F08c5bd02a2fc4c27002bc17f5f07c29e38000d59-1920x471.jpg&amp;w=1920&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F08c5bd02a2fc4c27002bc17f5f07c29e38000d59-1920x471.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F08c5bd02a2fc4c27002bc17f5f07c29e38000d59-1920x471.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 17. Fraud account factory.<\/figcaption><\/figure>\n<\/div>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"kyc-interception-cloak\">KYC interception cloak<\/h3>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The actor also engaged in credential theft and phishing campaigns. Victims were directed to lookalike verification domains whose reverse proxy relayed the real know your customer (KYC) flow, so the victim completed genuine identity verification while the operator captured the verified session and documents from the proxy relay in the middle. The captured session was then used by the actor from their machines to access the target service and data.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1920\" height=\"471\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F57702ff9f64d0a10b7c3c12f0debec33dd185124-1920x471.jpg&amp;w=1920&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F57702ff9f64d0a10b7c3c12f0debec33dd185124-1920x471.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F57702ff9f64d0a10b7c3c12f0debec33dd185124-1920x471.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 18. KYC interception cloak.<\/figcaption><\/figure>\n<\/div>\n<h4 class=\"Body-module-scss-module__z40yvW__reading-column headline-6 post-subsection\" id=\"attacker-egress-ips\">Attacker egress IPs<\/h4>\n<div class=\"Body-module-scss-module__z40yvW__media-column Body-module-scss-module__z40yvW__inline\">\n<div class=\"Table-module-scss-module__Z3bHXa__root\">\n<div aria-label=\"Table 3. Attacker egress IPs.\" class=\"Table-module-scss-module__Z3bHXa__tableWrapper\" role=\"region\" tabindex=\"0\">\n<table class=\"Table-module-scss-module__Z3bHXa__table\">\n<tbody>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<th class=\"body-3\"><strong>IP<\/strong><\/th>\n<th class=\"body-3\"><strong>Start<\/strong><\/th>\n<th class=\"body-3\"><strong>End<\/strong><\/th>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">141.133.125[.]208<\/td>\n<td class=\"body-3\">2026-05-21<\/td>\n<td class=\"body-3\">2026-05-23<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">167.250.111[.]136<\/td>\n<td class=\"body-3\">2026-05-23<\/td>\n<td class=\"body-3\">2026-06-03<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">178.16.54[.]141<\/td>\n<td class=\"body-3\">2026-05-21<\/td>\n<td class=\"body-3\">2026-06-16<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">37.27.103[.]22<\/td>\n<td class=\"body-3\">2026-05-26<\/td>\n<td class=\"body-3\">2026-06-13<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">194.163.183[.]216<\/td>\n<td class=\"body-3\">2026-05-23<\/td>\n<td class=\"body-3\">2026-05-24<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">202.66.167[.]230<\/td>\n<td class=\"body-3\">2026-05-21<\/td>\n<td class=\"body-3\">2026-06-04<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">146.103.101[.]253<\/td>\n<td class=\"body-3\">2026-05-21<\/td>\n<td class=\"body-3\">2026-06-13<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">146.103.97[.]169<\/td>\n<td class=\"body-3\">2026-05-21<\/td>\n<td class=\"body-3\">2026-05-25<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div><figcaption class=\"caption\">Table 3. Attacker egress IPs.<\/figcaption><\/div>\n<\/div>\n<h2 class=\"Body-module-scss-module__z40yvW__reading-column headline-4 post-heading\" id=\"gtg-50029-hacktivists-targeted-european-political-and-affiliated-entities\">GTG-50029: Hacktivists targeted European political and affiliated entities<\/h2>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">AI has helped to close the capability gap turning low-level \u201chacktivists\u201d into advanced persistent threats. As demonstrated repeatedly throughout our case studies, AI capabilities raise the baseline as well as reduce the resource requirements for offensive cyber operators. In this section, we provide details of a hacktivist campaign we investigated and disrupted, in which small well-motivated operations were able to achieve significant goals due to the integration of AI in their operations.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">In the spring of 2026, a single French-speaking actor was observed using Claude to target European political parties, media, think-tanks, and the SaaS providers used by these organizations.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">This actor built their own custom Rust-based scanner designed to scan and validate public containers for exposed API keys. Once keys were validated, the actor\u2019s tool was designed to rotate key usage across a local proxy layer. This enabled the actor to blend their traffic in with the traffic from the legitimate owner of the stolen API keys. As we saw in the case studies above, access to an exposed API removes the barrier to entry for a rogue actor.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">GTG-50029 provides another example of an actor embracing the use of AI across the kill chain. The actor used AI\u2019s agentic coding skills in a framework that helped it manage sub-agents; the sub-agents were themselves responsible for pre- and post-authentication reconnaissance, code review, and vetting findings from different AI models.<\/p>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"novel-exploitation-and-purpose-built-tooling\">Novel exploitation and purpose-built tooling<\/h3>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The campaign\u2019s signature technique to initially access their target systems was exploiting a previously undocumented WordPress re-installation race condition that created a rogue administrator account without valid credentials. The actor used Claude to develop and debug the exploit in the same session, including creating a lab harness. It succeeded against at least four victim websites.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">In one case, the actor compromised a political campaign management platform via an exposed search endpoint. The actor tasked their agents with iterating across this endpoint and ultimately exfiltrated approximately 140,000 records that included users\u2019 political opinions.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Against another target, the actor implanted a webshell hidden among font assets. A webshell is a small script placed on a web server that lets an attacker send commands remotely to be run by the server, effectively a backdoor reachable through the website itself. The actor built the webshell on the fly as they identified the vulnerability enabling the upload. They also used a WordPress \u201cmust-use\u201d plugin, a type of plugin that runs on every page load and can\u2019t be switched off from the admin dashboard, that harvested submitted credentials, encrypted them with per-site public keys, and staged them for pickup. Additionally, GTG-50029 poisoned the victim\u2019s backups, presumably to maintain persistence. If the victim moved to restore their previous environment from backups, they would be re-infected.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Finally, the actor compromised a media outlet by deploying a browser-exploitation C2 framework that hooked the organization\u2019s readers through an injected script. This enabled the actor to fingerprint thousands of visiting browsers. We observed the actor specifically hunting for the editorial staff\u2019s sessions and credentials via this framework.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The actor\u2019s signature tool was \u201cfafsearch,\u201d a purpose-built doxxing platform. This platform provided a compiled search engine, complete with ingestion pipelines, the ability to cross-reference individual breach dumps against exfiltrated data, normalization for national identity numbers and phone numbers, ranking logic, tests, and a containerized deployment. The actor loaded this platform with tens of millions of rows, including data such as national health identifiers and information from justice system breaches, and fused it with material they\u2019d obtained as part of their own intrusions. They published the result as a set of anonymously hosted dark-web services where individuals affiliated with the targeted political movement could be looked up by name.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">This is one of the clearest cases we have seen of AI-assisted software engineering applied directly to a mass attack on privacy\u2014and the entire platform was created by just one person.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Across 42 tracked target entities, the actor gained internal access to at least 14. The actor accessed and exfiltrated an estimated 12 to 26 GB of database dumps including information on political party donors and member records, a 15,000-message mailbox, student application records (including data from minors), payment-provider data. The actor also set up live credential interception. With the exfiltrated data, the actor staged per-victim encrypted archives on an actor-run Tor leak site.<\/p>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"actor-egress-ip-infrastructure\">Actor egress IP infrastructure<\/h3>\n<div class=\"Body-module-scss-module__z40yvW__media-column Body-module-scss-module__z40yvW__inline\">\n<div class=\"Table-module-scss-module__Z3bHXa__root\">\n<div aria-label=\"Table 4. Actor egress IP infrastructure.\" class=\"Table-module-scss-module__Z3bHXa__tableWrapper\" role=\"region\" tabindex=\"0\">\n<table class=\"Table-module-scss-module__Z3bHXa__table\">\n<tbody>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<th class=\"body-3\"><strong>Indicator<\/strong><\/th>\n<th class=\"body-3\"><strong>Role<\/strong><\/th>\n<th class=\"body-3\"><strong>First seen<\/strong><\/th>\n<th class=\"body-3\"><strong>Last seen<\/strong><\/th>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">139.59.2[.]243<\/td>\n<td class=\"body-3\">Key-validation box (DigitalOcean)<\/td>\n<td class=\"body-3\">2026-02-06<\/td>\n<td class=\"body-3\">2026-06-12<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">158.173.46[.]118, 146.70.116[.]131, 149.22.83[.]6, 138.199.60[.]29, 138.199.6[.]208, 103.216.220[.]19, 103.124.165[.]199, 103.141.60[.]144, 2001:ac8:27:89::a02d, 2001:ac8:29:84::a01d<\/td>\n<td class=\"body-3\">Commercial VPN\/DC attack exits (Mullvad\/M247\/31173\/Datacamp; AL\/AT\/AR\/CH\/BG\/SK\/DE) \u2014 primary-key ops window<\/td>\n<td class=\"body-3\">2026-03-25<\/td>\n<td class=\"body-3\">2026-05-20<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">34.156.199[.]132, 34.156.95[.]176<\/td>\n<td class=\"body-3\">Exfiltration endpoints in hijacked GCP projects<\/td>\n<td class=\"body-3\">2026-04<\/td>\n<td class=\"body-3\">2026-05<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">136.144.242[.]56<\/td>\n<td class=\"body-3\">Staging &amp; scan box used on EU political organizations<\/td>\n<td class=\"body-3\">2026-05-17<\/td>\n<td class=\"body-3\">2026-05-21<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">163.172.157[.]53, 2001:bc8:711:5854:dc00:1ff:fe18[:]ba53<\/td>\n<td class=\"body-3\">Persistent dedicated server, Scaleway FR used in late-phase operations<\/td>\n<td class=\"body-3\">2026-06-26<\/td>\n<td class=\"body-3\">2026-07-04<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div><figcaption class=\"caption\">Table 4. Actor egress IP infrastructure.<\/figcaption><\/div>\n<\/div>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"actor-owned-or-actor-controlled-domains-and-services\">Actor-owned or actor-controlled domains and services<\/h3>\n<div class=\"Body-module-scss-module__z40yvW__media-column Body-module-scss-module__z40yvW__inline\">\n<div class=\"Table-module-scss-module__Z3bHXa__root\">\n<div aria-label=\"Table 5. Actor-owned or actor-controlled domains and services.\" class=\"Table-module-scss-module__Z3bHXa__tableWrapper\" role=\"region\" tabindex=\"0\">\n<table class=\"Table-module-scss-module__Z3bHXa__table\">\n<tbody>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<th class=\"body-3\"><strong>Indicator<\/strong><\/th>\n<th class=\"body-3\"><strong>Role<\/strong><\/th>\n<th class=\"body-3\"><strong>First seen<\/strong><\/th>\n<th class=\"body-3\"><strong>Last seen<\/strong><\/th>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">frntrs-analytics.dedyn[.]io<\/td>\n<td class=\"body-3\">BeEF browser-C2 hostname (deSEC dynamic DNS, actor-held API token)<\/td>\n<td class=\"body-3\">2026-05-13<\/td>\n<td class=\"body-3\">2026-06<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">frntrs-analytics-863060591218.europe-west1.run[.]app<\/td>\n<td class=\"body-3\">Cloud Run origin behind C2 domain<\/td>\n<td class=\"body-3\">2026-05-13<\/td>\n<td class=\"body-3\">2026-06<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">prod-artfkt[.]com<\/td>\n<td class=\"body-3\">Actor-registered operational domain<\/td>\n<td class=\"body-3\">observed Apr-May 2026<\/td>\n<td class=\"body-3\">\u2014<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">fafwatch[.]xyz<\/td>\n<td class=\"body-3\">Actor-registered doxing adjacent domain<\/td>\n<td class=\"body-3\">observed Apr-May 2026<\/td>\n<td class=\"body-3\">\u2014<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">3ell6n47y3ct4a3x67fbuz62q2mk2l4vo6eacho2suzftdshsnrfopyd[.]onion<\/td>\n<td class=\"body-3\">CRS credential-vault API<\/td>\n<td class=\"body-3\">2026-05<\/td>\n<td class=\"body-3\">2026-07 (live at close)<\/td>\n<\/tr>\n<tr class=\"Table-module-scss-module__Z3bHXa__row\">\n<td class=\"body-3\">6mshbvhvzhdgumwwazf4jcep2xx4kdk6n4wgffc46msu2gc3j3t2fpad[.]onion<\/td>\n<td class=\"body-3\">Actor\u2019s Tor LLM-gateway (third-party model routing)<\/td>\n<td class=\"body-3\">2026-06<\/td>\n<td class=\"body-3\">2026-06<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div><figcaption class=\"caption\">Table 5. Actor-owned or actor-controlled domains and services.<\/figcaption><\/div>\n<\/div>\n<h2 class=\"Body-module-scss-module__z40yvW__reading-column headline-4 post-heading\" id=\"prevailing-trends\">Prevailing trends<\/h2>\n<h3 class=\"Body-module-scss-module__z40yvW__reading-column headline-5 post-section\" id=\"overview\">Overview<\/h3>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Despite the fact that each of the case studies above shared no connection, there are two broad developments that are relevant to each of them.<\/p>\n<h4 class=\"Body-module-scss-module__z40yvW__reading-column headline-6 post-subsection\" id=\"ai-tradecraft-is-proliferating-diffusion-of-ai-enabled-cyber-operations\">AI tradecraft is proliferating: Diffusion of AI-enabled cyber operations<\/h4>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Just as in the legitimate economy, AI has diffused through the cyber battlefield. Multiple groups including GTG-10002, <a href=\"https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage\">as previously reported<\/a>, developed and utilized their own autonomous attack frameworks; while other groups including GTG-50020 and GTG-50029 leveraged publicly available offensive agent frameworks like <a href=\"https:\/\/github.com\/vxcontrol\/pentagi\">PentAGI<\/a>. These public frameworks reproduced much of the same scaffolding for anyone who downloads them, and several operations in this report ran on them or on derivatives.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">A marketplace supporting the battlefield has formed as well. We discovered GTG-50021 creating fraudulent resellers offering discounted Claude access, while silently proxying user traffic to a different model, and harvesting the Anthropic credentials of anyone who signed up.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Diffusion is occurring across different classes of threat actors, different regions, and different types of mission. The capabilities described in this report should be assumed to be available to any actors who are motivated to use them. We continue to invest in resources, tooling, and personnel to develop more effective ways to stay ahead of these adversaries and disrupt their access before harm is realized. But we anticipate that we will continue to face persistent threats from highly-motivated, (and sometimes sophisticated state-sponsored) malicious cyber actors, and will continue to work with private- and public-sector partners to share threat information and best practices to mitigate these threats.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">This report details campaigns directed by both smaller criminal groups and state-sponsored organizations. The diffusion of AI has leveled the playing field giving both classes of actors access to the same set of advanced capabilities. The main distinguishing feature between these classes of actors is no longer sophistication but intent. Previously, state-sponsored actors were able to leverage access to greater resources to deploy more advanced cyber capabilities. The advance of AI provides non-state actors access to the same capabilities previously only accessible to state actors. A hacktivist using stolen API keys (GTG-50029), a financially motivated crew harvesting credentials from mobile applications (GTG-50014), and a state-nexus espionage operator (GTG-20006) all showed similar methodology: they ran multi-victim campaigns using agentic AI that would previously have required teams of operators. They built custom tools, executed intrusions, and processed stolen data at volumes no individual human operator could manage manually.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The attacks themselves are familiar, involving stolen credentials, unpatched edge devices, exposed services, SQL injection, and phishing. None of the operations in this report depended on some entirely novel technique that defenders have never seen. Instead, the <em>economics <\/em>of the attacks have changed. The kind of labor that previously set the well-resourced operations apart from everyone else\u2014reconnaissance, exploitation, tool development, and data processing\u2014are all now delegated to AI models, which run in harnesses at machine speed and in parallel. The results are visible in the numbers reported above: breaches completed in two to three hours, and dozens of victims handled in parallel by individual operators.<\/p>\n<h4 class=\"Body-module-scss-module__z40yvW__reading-column headline-6 post-subsection\" id=\"ais-increasingly-autonomous-role-in-cyber-operations\">AI\u2019s increasingly autonomous role in cyber operations<\/h4>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The AI use in the cases in this report spans a wide range of levels of autonomy. At one end, actors used Claude conversationally: it acted as an engineering assistant in the creation of malware, phishing kits, and surveillance tooling. Further along the spectrum, threat actors directed Claude to execute operations (such as running commands against victim networks, harvesting credentials, and exfiltrating data) with a human making each individual targeting decision (GTG-20006). At the far end, operations ran autonomously, with minimal human input or supervision: these included multi-agent frameworks conducting reconnaissance, exploitation, and theft against multiple victims, in parallel, for hours or days at a time (GTG-50014, GTG-50020, GTG-50029). We also observed a collection fleet running on a pre-set schedule with no human in the loop (GTG-10007), as well as scheduled jobs renewing stolen access tokens and harvesting victim cloud storage with no human involvement (GTG-20006).<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">It\u2019s important to bear in mind two caveats. First, humans have retained the decisions that matter most to them: for example, they\u2019re still heavily involved in target selection, monetization of findings, and review of results. Second, autonomy and harm are separate axes: <em>Autonomy <\/em>multiplies the scale and speed of an operation, and reduces operating costs and complexity, but <em>severity <\/em>is still determined by a multitude of factors. Several of the most serious compromises we report here came from operations where a human directed every step. In economic terms, AI autonomy compresses the cost side of attacker ROI calculations, lowering the skill threshold and labor required per campaign, while leaving potential payoffs largely unchanged. This favorable shift in unit economics makes previously marginal targets viable and encourages higher-volume, lower-touch operations.<\/p>\n<h4 class=\"Body-module-scss-module__z40yvW__reading-column headline-6 post-subsection\" id=\"appendix-a\">Appendix A<\/h4>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The following is a list of skills developed by threat actors to build out their AI-enabled workflows.<\/p>\n<div class=\"Body-module-scss-module__z40yvW__media-column\">\n<figure class=\"ImageWithCaption-module-scss-module__Duq99q__e-imageWithCaption\"><img loading=\"lazy\" alt=\"\" loading=\"lazy\" width=\"1920\" height=\"1778\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcset=\"\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F5b3c1191e266cbbe020d44dfb9acdbc1bedf5b9f-1920x1778.jpg&amp;w=1920&amp;q=75 1x, \/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F5b3c1191e266cbbe020d44dfb9acdbc1bedf5b9f-1920x1778.jpg&amp;w=3840&amp;q=75 2x\" src=\"https:\/\/www.anthropic.com\/_next\/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F5b3c1191e266cbbe020d44dfb9acdbc1bedf5b9f-1920x1778.jpg&amp;w=3840&amp;q=75\"\/><figcaption class=\"caption\">Figure 19. Skill breakdown.<\/figcaption><\/figure>\n<\/div>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\"><a href=\"#main\">Back to top<\/a><\/p>\n<\/div>\n<p><a href=\"https:\/\/www.anthropic.com\/threat-intelligence-report-september-2026?utm_source=tldrai\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>AI-augmented cyber operations Cyber operations: From assistant to orchestrator Over the past six months, our Threat Intelligence team identified and disrupted a series of cyber operations in which threat actors used Claude. The actors included suspected state-sponsored groups, financially motivated criminals, and politically motivated individuals. This section presents some of those cases. Throughout these case [&hellip;]<\/p>\n","protected":false},"author":16,"featured_media":23923,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[143],"tags":[],"class_list":["post-23922","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai"],"_links":{"self":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts\/23922","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/comments?post=23922"}],"version-history":[{"count":0,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts\/23922\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/media\/23923"}],"wp:attachment":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/media?parent=23922"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/categories?post=23922"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/tags?post=23922"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}