Claude AI used to automate cyberattacks, create new flaws
Anthropic's AI models were abused by attackers to automate attacks, invent new hacking tools, and bypass security. This lets even small groups or lone attackers launch sophisticated campaigns that would have needed expert teams just a year ago.
- Report priority
- High
- Involves
- Anthropic
What is known
- Attackers use Anthropic's Claude AI to automate hacking steps, invent new ways to break into systems, and rewrite malware to slip past defenses.
- The AI helps them plan attacks faster, find new vulnerabilities, and evade detection.
- This lets even small groups or lone attackers launch complex campaigns that would have needed expert teams before.
What to do
If you rely on Claude AI for security work, review Anthropic's latest security updates and guidelines for safe usage.
Reported details
A new report from Anthropic's Threat Intelligence team details how adversaries, including state-sponsored espionage groups, financially motivated attackers, and lone actors, have weaponized Claude AI models to automate entire cyberattack chains. Between December 2025 and August 2026, attackers used AI to generate zero-day exploits, rewrite malware to evade detection, and streamline reconnaissance, exploitation, and data exfiltration. The report highlights how publicly available offensive AI frameworks like PentAGI have democratized advanced attack techniques, reducing the skill gap between elite operators and amateur actors.
One case study tracks GTG-20006, a group linked to Midnight Blizzard, which used Claude to automate phishing infrastructure, malware generation, and command-and-control operations against Ukrainian and European targets. The group also employed AI to dynamically adjust malware to bypass security defenses, monitoring detection rates in real time. The findings underscore how AI accelerates every phase of an intrusion, compressing attack timelines and lowering the barrier for sophisticated cyber operations.