Cyber operations · GTG-30005

Military reconnaissance and domestic surveillance systems: the GTG-30005 case

Source notice

This page is a translation of content from pages 106–107 of Anthropic's September 2026 report. This site does not publish any target coordinates, exploit code, or information that could be used for attacks.

According to the report, an Iran-linked threat actor used Claude to collect and analyze publicly available data to develop targeting recommendations against U.S. Navy forces in the region. The actor used Claude to write targeting handbooks, identifying and tracking naval positions based on open-source information. The same account also developed enterprise software for Iranian state systems, including designing a large-scale domestic surveillance platform combining automatic license plate recognition and mobile device identifier interception. This page does not publish any target coordinates or exploitation details.

In a separate investigation, we identified and disrupted an Iran-linked threat actor who used Claude to collect and analyze publicly available data to develop targeting recommendations against U.S. Navy forces in the region. The threat actor used Claude to write targeting handbooks through a Python pipeline built with Claude's assistance, identifying and tracking naval positions based on open-source information. The written materials included lists of U.S. personnel scraped from public military photo captions; publicly available ship and aircraft transponder identifiers; commercial satellite imagery query scripts; and lists of public websites revealing U.S. Navy movements. The threat actor also instructed Claude to write research on ship system vulnerabilities, cataloging known CVEs in maritime VSAT terminals, Cisco communications equipment, and industrial control products.

We banned the actor's accounts, developed detections to reduce future abuse risk, and shared threat intelligence with government authorities to disrupt the threat.

Large-scale domestic surveillance

Separately, the same account conducted enterprise software development for Iranian state systems, including using Claude to design software components of a large-scale domestic surveillance platform combining automatic license plate recognition and mobile device identifier interception. The operator also built analysis tools for a same-day export of a 244-member private Telegram group, including social network analysis of its members.

What the report observed

The report confirms the threat actor used Claude to develop targeting handbooks against U.S. Navy forces, and to develop a large-scale domestic surveillance platform for Iranian state systems.

The report lists the vulnerability CVEs researched, including COBHAM SAILOR 900 VSAT, Cisco Unified Communications Manager, Cisco Ultra-Reliable Wireless Backhaul, Cisco IW3702, and others.

This site does not publish any target coordinates, exploit code, or information that could be used for attacks.

Diagram illustrating the dual use of naval reconnaissance and domestic surveillance.
Original report figure: illustration related to military reconnaissance and domestic surveillance.

Confirmed & unknown

Confirmed

  • The report confirms the threat actor used Claude to collect and analyze public data to develop targeting recommendations against U.S. Navy forces
  • The report confirms the threat actor used Claude to write research on ship system vulnerabilities
  • The report confirms the same account developed a large-scale domestic surveillance platform for Iranian state systems

Unknown

  • Whether the targeting handbooks were used in actual military operations is not stated
  • Whether the domestic surveillance platform was deployed is not stated
  • The threat actor's true identity is not disclosed

Platform response

Anthropic banned the actor's accounts, developed detections to reduce future abuse risk, and shared threat intelligence with government authorities.

Limits of response:Banning accounts cannot prevent the actor from continuing reconnaissance and surveillance activities using other tools.

Takeaways

  • Public data can be collected and analyzed for military reconnaissance, including personnel lists, ship positions, and satellite imagery.
  • AI can accelerate vulnerability research and targeting handbook writing, lowering the barrier to planning military operations.
  • The same account can be used simultaneously for military reconnaissance and domestic surveillance development, indicating the actor's multi-purpose nature.

Sources