Anthropic has identified various state-sponsored and criminal groups using its Claude AI models to conduct cyberattacks, develop weapons, spread propaganda, and perform mass surveillance on a global scale.
Key Points
- Anthropic identified "Generative Threat Groups" (GTGs) using its models for tasks ranging from malware creation and credential harvesting to autonomous reconnaissance and data exfiltration.
- Chinese-linked actors utilized Claude to profile dissidents, track Uyghur populations, and develop software for electronic warfare and anti-torpedo fire control systems.
- Russian-affiliated groups leveraged the AI to engineer autonomous drone swarms and execute influence operations, including the distribution of content via state-controlled media outlets.
- Iranian-nexus actors employed the technology to build domestic surveillance platforms, profile Jewish organizations, and develop modular Windows malware for credential theft.
- Commercial entities, such as the France-based LKM Company and the Israeli-Singaporean firm S2T, used the models to automate large-scale political disinformation and social media surveillance.
- Anthropic reported that these operations spanned from December 2025 to August 2026, with the company actively neutralizing accounts involved in these malicious activities.