
AI research company Anthropic has published its latest threat intelligence report, “Detecting and Countering Misuse of AI: September 2026,” detailing how malicious actors attempted to weaponize its Claude models across cyber operations, influence campaigns, surveillance, biological research, weapons development, fraud, and model distillation. The report covers activity detected and disrupted between December 2025 and August 2026, spanning suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, and propaganda institutions operating across Russia, China, Iran, and other regions.
According to the report, none of the misuse cases involved Anthropic’s most capable Fable or Mythos-class models, with one exception in the distillation section. The company emphasizes that the disclosed operations are not representative of typical misuse but were selected as the most sophisticated and novel threat activity identified to date. In each case, Anthropic banned the associated accounts, strengthened its safeguards based on investigative findings, and shared intelligence with authorities and industry partners.
The report’s central conclusion is that AI has shifted from an advisory tool to an operational orchestrator in cybercrime. In the majority of operations, threat actors deployed multi-agent frameworks that autonomously executed reconnaissance, exploitation, credential harvesting, and data exfiltration, with humans primarily selecting targets and reviewing results.
Notable cases include GTG-20006, linked to the Russian state-nexus group Midnight Blizzard, which ran AI-driven workflows across phishing, malware development, and evasion—automatically rebuilding its toolkit whenever security products flagged it. Separately, suspected ShinyHunters affiliates used AI to industrialize credential harvesting, decompiling 1.8 million Android applications for secrets and completing breaches in as little as two to three hours.
Beyond cyber operations, the report documents influence campaigns targeting elections and public opinion in Moldova, Kenya, Malaysia, and Bangladesh; state-aligned surveillance operations in China, Iran, and Mali, including a platform built to monitor roughly 25 million mobile subscribers; and weapons development efforts, including a guided rocket program in Yemen and an autonomous drone swarm project in Russia.
The biological misuse section presents five cases of dual-use research, including gain-of-function work on chikungunya virus and avian influenza adaptation studies, which the company says its classifiers largely contained.
Finally, the report details illicit distillation campaigns attributed to Chinese labs—including Alibaba, DeepSeek, Moonshot AI, Xiaomi, and Zhipu—which it accuses of covertly routing user queries to Claude, harvesting reasoning traces, and using the outputs to train competing models. In several instances, this relay exposed sensitive corporate and government data to third parties without users’ knowledge.
Anthropic frames the disclosure as both a warning and a roadmap, arguing that as models grow more capable, collective detection and defense efforts across the AI industry and governments will be essential to staying ahead of persistent adversaries.
The post Anthropic’s New Threat Intelligence Report Reveals AI’s Growing Role In Cybercrime, Influence Campaigns And State-Sponsored Operations appeared first on Metaverse Post.