Surveillance operations · GTG-30004
Public information used for identity profiling: the GTG-30004 case
This page is a translation of content from pages 105–106 of Anthropic's September 2026 report. Actor linkage is the report's assessment. This site does not provide any personal profile fields or target lists.
According to the report, an Iran-linked threat actor used Claude to build an automated open-source intelligence identity profiling tool targeting Israeli government and non-government individuals and Jewish diaspora organizations. The actor also used Claude to modify the open-source LSASS credential dumper NanoDump and build a custom C++ obfuscation/build pipeline to obfuscate malware samples and hinder analysis.
What happened
We identified an Iran-linked threat actor who used Claude to build an automated open-source intelligence identity profiling tool targeting Israeli government and non-government individuals and Jewish diaspora organizations. Separately, the actor used Claude to make its malware harder to identify as malware.
What AI did
In one workflow, the threat actor built and used Claude to orchestrate an open-source intelligence and reconnaissance tool to profile hundreds of individuals in Israeli and Jewish diaspora communities. The threat actor ran an automated identity profiling tool that enriched pre-existing target lists. The actor attempted to generate open-source intelligence products about Israeli and American individuals. The threat actor used Claude to accelerate its ability to collect and analyze open-source data.
In a parallel workflow across multiple Persian-language sessions, the threat actor modified the open-source LSASS credential dumper NanoDump and used Python to build a custom C++ obfuscation/build pipeline that renames identifiers and injects dummy functions, likely aimed at obfuscating malware samples and hindering analysis.
What the report observed
The report confirms the existence of the automated open-source intelligence profiling tool, as well as the modification of NanoDump and the construction of the obfuscation pipeline.
This site does not provide any personal profile fields or target lists.

Confirmed & unknown
Confirmed
- The report confirms the actor used Claude to build an automated open-source intelligence profiling tool
- The report confirms targets included Israeli government and non-government individuals and Jewish diaspora organizations
- The report confirms the actor modified NanoDump and built an obfuscation pipeline
Unknown
- Whether the profiling tool was used in actual operations is not stated
- Whether the profiled individuals were aware is not stated
- Whether the modified malware was used in actual attacks is not stated
Platform response
Anthropic banned the relevant accounts.
Limits of response:Banning accounts cannot recover already collected open-source intelligence data, nor prevent the actor from continuing activities using other tools.
Takeaways
- Public information can be used by automated tools for identity profiling, allowing detailed profiles to be built even without intrusion.
- AI can be used simultaneously for intelligence collection and malware development, lowering the technical barrier.
- Obfuscation pipelines make malware harder to detect and analyze.
Sources
- Anthropic report (English PDF) (p. 105–106)
- Anthropic report page