A Russian espionage crew fed their own malware to an AI and told it to keep rewriting the code until security software stopped catching it. The AI ran that loop on its own. When a build finally slipped past the scanners, the crew staged it and went back to work on their targets, most often Ukrainian government and military staff.
Anthropic published that case today in a threat report on what it caught and shut down on Claude between December of last year and August. Its attribution lines up with public reporting that ties the crew to Midnight Blizzard, a Russian state hacking group. Seven kinds of abuse are in the report, from break-ins and propaganda to missile software and Chinese labs harvesting Claude's answers to train their own models.
Most of it used familiar routes in. Stolen passwords, unpatched servers, phishing mail, the usual. What changed is who can run an operation this big.
A political hacker, a crew in it for money and a state spy service all showed up running the same sort of campaign, the kind that used to need a team of operators. Anthropic's point is that how advanced an attack looks is no longer a reliable clue to who is behind it.
AI kept rebuilding the malware
The AI did much of the job. It researched and registered the phishing domains, set up the hosting that sent the mail, and hauled the stolen files out. The operators still picked every target and reviewed what came back. Some jobs, like renewing stolen tokens, ran with nobody watching at all.
More than 20 organizations show up in the crew's target lists. Most are Ukrainian and European ministries, embassies, defense firms and think tanks. Drone makers got special attention. According to the report, the crew copied the mailboxes of at least two makers of drone parts and stole a complete software kit for a drone's camera system.
They reached some targets indirectly. They broke into at least three companies that run guest wifi networks for hotels. Then they changed where the network sent people, so guests who connected had their traffic and device details sent to the attackers' servers. Fake update prompts were staged to push malware onto Windows laptops, Android phones and iPhones. Microsoft described the same trick in July and called it CaptiveCrunch.
They took over WhatsApp accounts too. They linked their own devices to the accounts and switched read receipts off, so the owner wouldn't notice while whole chats were copied out. At least two former senior Ukrainian officials were targeted that way. The crew also copied a North African government agency's credential database, with more than 300,000 national identity records in it.
A new detection used to force another round of rebuilding. Anthropic's argument is that AI has flipped the cost of that rebuilding onto defenders. A capable crew running that rewrite loop could, in theory, have a working build out before the new detection arrives.
Source: Anthropic on AI-augmented cyber operations, Microsoft on the hotel wifi campaign

One person, 42 targets
In the spring, a single French-speaking attacker went after European political parties, news outlets and think tanks. Anthropic counted 42 targets and says the attacker got inside at least 14 of them. The campaign ran for a month entirely on API keys that other people had left exposed in public containers.
Anthropic says they got in through a bug nobody had written up, a timing flaw in the WordPress reinstall process that created an administrator account without valid credentials. Claude helped write and debug the attack code in one sitting, lab test included. It worked on at least four sites.
What came next was worse. They built a search engine for doxxing and filled it with tens of millions of rows, including national health ID numbers and records from a justice system breach. Then they stood it up as anonymously hosted dark-web services where people tied to the political movement they had targeted could be looked up by name.
Anthropic calls it one of the clearest cases it has seen of AI-assisted coding aimed at a mass attack on privacy. One person built all of it. The attacker also poisoned one victim's backups, so restoring from them would put the attacker's malware back.
Source: Full Anthropic report, PDF
Three hours from login to control
One operator ran ten cloud machines, and Anthropic suspects the operator works with the ShinyHunters extortion crew. The machines downloaded 1.8 million Android installer files, took them apart, and scanned the code for passwords and keys that developers had left inside.
One break-in went from a single stolen developer login to full administrative control of the victim's cloud systems in about three hours. A different operator pulled more than 2,100 sets of Microsoft login tokens from more than 40 companies in about 34 hours. Anthropic says AI agents did nearly all of it. At an airline the operators reached systems holding tens of millions of passenger records.
API keys for AI services turned out to be a prize on their own. The same operators lifted keys out of the companies they hit and ran their next attacks with them. That buys free compute and hides the traffic behind the victim. Elsewhere, a Russian-speaking operator spent four days hitting about 30 AI companies, chasing access to a pre-release Claude model. Every attempt to reach it failed.
A Chinese app studio built more than 20 dating apps. It filled them with Claude-powered characters that were told never to admit they were software. Real people were mixed into the swipe feed to handle the video calls and follow-backs, about one human for every three fake profiles. Over two weeks in April, more than 4,700 of those characters talked to at least 25,000 people.
Source: Anthropic on opportunistic intrusions and fraud
Watching a whole country
In Mali, one Claude subscriber built a system called Lakana 360. Anthropic thinks they were an independent consultant for the state spy agency, and says Claude was the main engineering workforce. The report says it was built to watch about 25 million SIM cards across all three national phone networks.
Lakana 360 collects call records, texts and voice calls. It matches people by the sound of their voice across different SIM cards. The report says that defeats the trick of switching burner phones. It flags people who use a VPN, then matches everything against the national biometric registry and other state records.
One part of the system builds a file on any phone number you give it, and that part was supposed to need a court order. According to the report, the people running it asked for that requirement to be taken out. The records were set to be kept indefinitely. Anthropic banned the account, but the platform runs on-premises with a local model, so the ban doesn't reach it.
In China, a religious affairs unit once had many teams of analysts. Anthropic says it is now a single office, turning out thousands of investigations a month with an AI assistant. It used Claude and a set of internal templates to produce files, some of them daily. Targets ranged from Catholic cardinals across Asia to church leaders in Taiwan, Tibetan groups in exile and Falun Gong members.
The files held birth dates, birthplaces, social accounts, scandals and anything that could be used to pressure the person. A second Chinese group asked for the route and end point of a pro-democracy march in Vancouver before it happened. One police academy student ran into a refusal and reworded the request. Back came guidance naming 10 private citizens to pull in for questioning and keep under watch.
Iran shows up building surveillance tools. One unit shipped a Firefox add-on dressed up as a prayer times app that quietly collected people's identities from social networks. That unit and a second one fed into one central case system. A person's file there holds their national ID, their beliefs, their police record, their accounts and a tab labelled action.
Source: Anthropic on state surveillance operations
A rocket, a swarm, a target list
Anthropic details six weapons cases in the report, three in China, two in Russia and one in Yemen. Four used Claude to write software for the weapons themselves. The other two used it to shop for restricted parts and to dig up intelligence on somebody else's weapon.
A cell in northern Yemen used Claude Code in place of software engineers on three programs at once, one of them a guided rocket. They test-fired it. It seems to have failed, and within hours they were back asking Claude why.
In Russia, a group that Anthropic takes to be a small freelance team started work in mid-May on software for a self-flying swarm of kamikaze drones they called Serafim. An onboard model was meant to pick its own targets, including a class for a person, and order the blast with nobody in the loop.
They trained the drones' camera system on scraped footage from the war in Ukraine, with a fixed point in the Donetsk region as the demonstration strike target. Anthropic puts that work at the simulation and bench stage, not a flying swarm.
In China, a researcher built about 16 software modules for jamming radar and planning attacks on air defenses, then worked through 12 versions. Partway through, the researcher changed the software's default practice scenario to 12 targets in Taiwan, among them a command bunker, an early warning radar site, Patriot batteries and major air bases. The account traces back to Chinese research bodies, Anthropic says, including the army's own Academy of Military Sciences.
Across the four weapons-building cases the shape is the same. The actors already knew their hardware and used Claude for the software. They split the work across sessions, so no single chat showed the whole picture.
Source: Anthropic on conventional weapons cases
Anthropic says labs served Claude as their own
Anthropic says seven Chinese labs ran what it calls illicit distillation. They reached Claude through thousands of fake accounts and through proxy services. One lab, the report says, simply bought transcripts from vendors that had logged other people's chats. What they wanted was Claude's answers, and its step-by-step reasoning, as training data.
The biggest run Anthropic has ever measured came from operators tied to Alibaba. It peaked near 3 million exchanges a day across more than 3,500 fake accounts. Two labs went further. Anthropic says DeepSeek and Moonshot forwarded some customer requests to Claude and returned its answers through their own services.
Anthropic says that DeepSeek's customers were likely unaware, and that it doesn't know whether Moonshot told its own customers. According to the report, requests relayed through DeepSeek exposed live login credentials for a Russian government database at an agency tied to Russia's defense ministry.
Anthropic says requests relayed through Moonshot carried surveillance video from hundreds of cameras in Chengdu. A likely military user had sent it in to ask whether the person they were tracking was acting oddly.
Anthropic says Zhipu tried to pull hacking skills out of Fable, its best publicly available Claude. Fable's safeguards degraded those attempts until Zhipu stopped trying. Anthropic then watched Zhipu employees switch to an older Claude and to another US lab's top model, which Zhipu had assessed as having weaker safeguards.
Anthropic competes with every lab named here and is the only source for these claims.
Source: Anthropic on illicit distillation

Anthropic mostly sees what runs on its own models. Every case here is one where somebody picked Claude and got caught, so this is a sample of one company's traffic, not the whole problem.
Bans didn't fix the worst of it. The ban never touched Mali's platform, the Yemeni cell can already run flight simulations without Claude, and Anthropic expects more attackers to adopt the same kind of automated attack framework.








