Surveillance operations · GTG-30004

Public information used for identity profiling: the GTG-30004 case

Source notice

This page is a translation of content from pages 105–106 of Anthropic's September 2026 report. Actor linkage is the report's assessment. This site does not provide any personal profile fields or target lists.

According to the report, an Iran-linked threat actor used Claude to build an automated open-source intelligence identity profiling tool targeting Israeli government and non-government individuals and Jewish diaspora organizations. The actor also used Claude to modify the open-source LSASS credential dumper NanoDump and build a custom C++ obfuscation/build pipeline to obfuscate malware samples and hinder analysis.

What happened

We identified an Iran-linked threat actor who used Claude to build an automated open-source intelligence identity profiling tool targeting Israeli government and non-government individuals and Jewish diaspora organizations. Separately, the actor used Claude to make its malware harder to identify as malware.

What AI did

In one workflow, the threat actor built and used Claude to orchestrate an open-source intelligence and reconnaissance tool to profile hundreds of individuals in Israeli and Jewish diaspora communities. The threat actor ran an automated identity profiling tool that enriched pre-existing target lists. The actor attempted to generate open-source intelligence products about Israeli and American individuals. The threat actor used Claude to accelerate its ability to collect and analyze open-source data.

In a parallel workflow across multiple Persian-language sessions, the threat actor modified the open-source LSASS credential dumper NanoDump and used Python to build a custom C++ obfuscation/build pipeline that renames identifiers and injects dummy functions, likely aimed at obfuscating malware samples and hindering analysis.

What the report observed

The report confirms the existence of the automated open-source intelligence profiling tool, as well as the modification of NanoDump and the construction of the obfuscation pipeline.

This site does not provide any personal profile fields or target lists.

Diagram illustrating how the actor conducted both profiling and malware development simultaneously.
Original report figure: illustration related to open-source intelligence profiling and malware development.

Confirmed & unknown

Confirmed

  • The report confirms the actor used Claude to build an automated open-source intelligence profiling tool
  • The report confirms targets included Israeli government and non-government individuals and Jewish diaspora organizations
  • The report confirms the actor modified NanoDump and built an obfuscation pipeline

Unknown

  • Whether the profiling tool was used in actual operations is not stated
  • Whether the profiled individuals were aware is not stated
  • Whether the modified malware was used in actual attacks is not stated

Platform response

Anthropic banned the relevant accounts.

Limits of response:Banning accounts cannot recover already collected open-source intelligence data, nor prevent the actor from continuing activities using other tools.

Takeaways

  • Public information can be used by automated tools for identity profiling, allowing detailed profiles to be built even without intrusion.
  • AI can be used simultaneously for intelligence collection and malware development, lowering the technical barrier.
  • Obfuscation pipelines make malware harder to detect and analyze.

Sources