Surveillance operations · GTG-34007

Surveillance System Development and Malicious Browser Extensions: GTG-34007 Case

Source notice

This page is an English translation of the relevant content from Anthropic's September 2026 report, pages 101–103. This site does not publish any surveillance logic, extension code, or information that could be used to replicate the surveillance.

According to the report, two units linked to Iranian paramilitary and domestic security agencies used 16 Claude accounts to build surveillance systems and a malicious Firefox browser extension. A seven-department organization claimed to maintain a database of Iranian national identity records and monitored and profiled 6,388 Iranians over one year. Another provincial unit based in Qom developed a malicious Firefox extension called "al-Najm al-thāqib" to mass-collect user identities from major social network platforms. This page does not publish any surveillance logic or extension code.

What happened

We identified and banned 16 Claude accounts operated by two units linked to Iranian paramilitary and domestic security agencies. The two units ran different playbooks on Claude but fed data into the same central infrastructure.

We identified a seven-department organization with offices across Iranian provinces that claimed to maintain a database of Iranian national identity records and monitored and profiled 6,388 Iranians over one year. The operators used Claude as an analyst and production studio to build what appears to be the front end of a government-controlled surveillance case management system, and performed social network analysis on 155,216 tweets.

We also identified a provincial unit based in Qom that used Claude as its engineering department to build domestic surveillance capabilities. The unit's flagship was a malicious Firefox extension called "al-Najm al-thāqib"—deployed to production—which a unit member used to mass-collect user identities from major social network platforms. Both units built extensions and interfaces to the same centralized system called "Arman," a federated model where provincial units feed data into central infrastructure. Users leveraged Claude to provide code, speed, engineering skills, and analysis.

End customer

We assess with high confidence that these units are linked to Iranian paramilitary domestic security entities. The actors used Claude to generate output for national security customers, and we identified evidence of the actors responding to tasks from senior Iranian government officials. We also found evidence that the units vetted candidates for official positions on behalf of the Iranian government.

Both units logged their surveillance collections into "Arman," a shared case management system where a subject's file contains their national ID, beliefs, criminal record, social accounts, and an "operations" tab.

What the report observed

The report confirmed that two units linked to Iranian paramilitary and domestic security agencies used Claude to build surveillance systems.

The report confirmed that a seven-department organization monitored and profiled 6,388 Iranians over one year and performed social network analysis on 155,216 tweets.

The report confirmed that another unit developed a malicious Firefox extension called "al-Najm al-thāqib" to collect user identities from major social network platforms.

The report confirmed that both units fed data into a centralized system called "Arman," which contains subjects' national IDs, beliefs, criminal records, social accounts, and other information.

This site does not publish any surveillance logic, extension code, or information that could be used to replicate the surveillance.

Diagram: the report uses this to illustrate how the two units feed data into the centralized "Arman" system.
Original report figure: illustration related to surveillance system development and malicious browser extensions. Text in the figure is in the original English.

Confirmed & unknown

Confirmed

  • The report confirms two units linked to Iranian paramilitary and domestic security agencies used Claude to build surveillance systems
  • The report confirms one organization monitored and profiled 6,388 Iranians over one year
  • The report confirms the malicious Firefox extension "al-Najm al-thāqib" was deployed to production
  • The report confirms both units fed data into a centralized system called "Arman"

Unknown

  • The full functionality and scale of the surveillance system is not fully disclosed in the report
  • The specific identities of monitored individuals are not disclosed in the report
  • The specific names and affiliations of the two units are not fully disclosed in the report

Platform response

Anthropic banned the 16 Claude accounts and notified relevant parties of its findings.

Limits of response:Banning accounts cannot stop the already-deployed surveillance systems and malicious extensions from running.

Takeaways

  • AI can be used to build large-scale surveillance systems, including identity record databases and social network analysis.
  • Malicious browser extensions can be used to collect user identities from social network platforms and have been deployed to production.
  • A federated surveillance architecture allows provincial units to feed data into a central system, enabling nationwide surveillance.

Sources