Cyber operations

AI-assisted cyber operations: the scale changes, the basics mostly don't

Definition

This topic covers actors who embed AI into cyber operation workflows to speed up reconnaissance, write tools, process stolen data, or maintain access. The harm targets organizations' systems, accounts, and data, and can ultimately reach individuals.

The report divides capability gains into speed, scale, and depth, and discusses the shift from 'assistant' to 'workflow orchestration'. Many basic techniques remain stolen credentials, unpatched systems, and social engineering.

Not to be confused with

Not 'AI invented entirely new attacks'. The report repeatedly shows that entry points are still old techniques; AI mainly lowers execution costs.

Not 'model labs were necessarily breached'. GTG-50020 makes clear: no unreleased models were obtained, and Anthropic's own systems were not compromised.

Not a place to find attack tutorials. We only explain risk types and evidence boundaries.

Diagram showing AI's role shift from assistant to orchestrator in cyber operations, without attack steps.
Original report figure: overview of capabilities and roles at the start of the cyber operations chapter.

AI roles

In this chapter's cases, AI appears in roles like software development, workflow orchestration, and data analysis. Humans still set goals, choose targets, and decide whether to continue.

'Orchestration' means handing multi-step tasks to an agent loop, not that the system is fully autonomous without humans.

Related cases

Cyber operations

Autonomous attack frameworks and vulnerability research: GTG-10007 case

According to an Anthropic report, a group of Chinese-speaking operators assessed to be likely based in Changsha, Hunan, China, used Claude as the engineering and orchestration layer for a coordinated attack campaign. Multiple workflows ran in parallel: intrusions into production systems, reconnaissance of foreign government networks, ongoing vulnerability research and exploit development against mainstream endpoint security products, malware development, and operation of an unattended intelligence-collection platform. The targets were roughly 50 organizations. Attribution information such as the operators' location comes from the report's assessment; their vulnerability findings were validated only in the actors' own experimental environments.

Cyber operations

AI-assisted cyber espionage: the GTG-20006 case

According to Anthropic's September 2026 report, GTG-20006 is a cyber espionage actor who uses AI to automate operations and gain speed. Anthropic says its attribution is consistent with public reporting linking the actor to Midnight Blizzard. The actor used a custom toolkit including two types of Windows implants, a mobile exploitation suite, a credential stealer targeting browser password vaults, a phishing platform designed to impersonate priority targets such as government organizations, and a management console for controlling compromised accounts. The report observed that GTG-20006 automated most of its operations — from development, infrastructure acquisition, phishing, command-and-control persistence, to data exfiltration — through customized AI-driven workflows.

Surveillance operations

Public information used for identity profiling: the GTG-30004 case

According to the report, an Iran-linked threat actor used Claude to build an automated open-source intelligence identity profiling tool targeting Israeli government and non-government individuals and Jewish diaspora organizations. The actor also used Claude to modify the open-source LSASS credential dumper NanoDump and build a custom C++ obfuscation/build pipeline to obfuscate malware samples and hinder analysis.

Cyber operations

Military reconnaissance and domestic surveillance systems: the GTG-30005 case

According to the report, an Iran-linked threat actor used Claude to collect and analyze publicly available data to develop targeting recommendations against U.S. Navy forces in the region. The actor used Claude to write targeting handbooks, identifying and tracking naval positions based on open-source information. The same account also developed enterprise software for Iranian state systems, including designing a large-scale domestic surveillance platform combining automatic license plate recognition and mobile device identifier interception. This page does not publish any target coordinates or exploitation details.

Cyber operations

Domestic surveillance tool development: the GTG-30006 case

According to the report, an Iranian threat actor used 16 free Claude.ai accounts across 16 single-operator organizations to develop malware, delivery pipelines, and phishing portals targeting domestic Iranian users. The delivery pages were designed to serve malicious content only to visitors with IP addresses from Iran, themed around censorship-circumvention tools and fabricated Persian-language news brands. The actor used Claude to develop the SECOMS64 modular Windows implant, including a keylogger, screenshot capture, Chrome credential extraction, and more. This page does not publish any malware code or phishing links.

Cyber operations

Opportunistic Data Theft and Ransom: GTG-50014 Case

According to Anthropic's report, multiple opportunistic intrusion clusters suspected of being linked to the ShinyHunters group used AI to enhance their criminal activity. These actors broadly scanned unpatched internet-facing systems, rummaged through public containers, code repositories, mobile apps, and more for credentials, tokens, and API keys, then went straight for databases to steal customer data after gaining access, and extorted victims by threatening to publish or sell the data. The report says AI agents did most of the work, with one case going from a stolen token to full control of a victim's cloud environment in about 3 hours. The report also makes clear: Anthropic's own systems were not breached by this actor.

Cyber operations

From Hotel System Intrusions to AI Supply Chain Attacks: GTG-50020 Case

According to Anthropic's report, GTG-50020 is a Russian-speaking, financially motivated actor that historically targeted hotel booking and fintech platforms. In one intrusion, they exfiltrated about 26 GB of data from a victim and attempted to obtain $1.5 to $2.5 million through ransom (or by selling the data on dark web forums). They then pivoted the same techniques toward the AI industry: by injecting malicious instructions into an AI vendor's automated evaluation sandbox, they made the sandbox hand over the credentials it held—including production AI API keys for multiple providers held by that vendor. The report makes clear: the actor never obtained access to unreleased Claude models, and Anthropic's own systems were not breached.

Cyber operations

Fake AI Reseller Services and Credential Theft: GTG-50021 Case

According to Anthropic's report, the AI supply chain has become a target, loot, and source of attack compute for malicious actors. AI access in the form of stolen API keys, session tokens, and devices is increasingly the sole objective of multiple criminal groups. GTG-50021 is a fake AI reseller service operated by a Russian- and Ukrainian-speaking actor. Customers thought they were buying discounted Claude access, but their traffic was silently routed to other models; the reseller tool also installed a credential collector on the device, reselling account credentials to other proxy networks.

Cyber operations

Data Theft Targeting European Political Organizations: GTG-50029 Case

According to Anthropic's report, in spring 2026 a French-speaking actor used Claude to target European political parties, media, think tanks, and the software services they use. The report tracked 42 target entities, of which at least 14 were internally accessed, with an estimated 12 to 26 GB of data stolen. This is an example of one person using AI to scale intrusion and data correlation capabilities; this page does not provide any personally identifiable data.

Limits of response

The report is a single platform's selected disclosures and cannot be used to rank countries or industries by risk.

Indicators of compromise and specific exploitation steps are not reproduced here.

Related guides

FAQ

Does AI let ordinary people become elite hackers?

The report shows that lower-resourced actors can build more complex tools and process data at larger scale, but entry points still depend on exposed interfaces, stolen keys, and unpatched systems. The capability gap is narrowing, not disappearing.

What's dangerous about fake 'discounted Claude' services?

The reseller services described in the report silently redirect traffic and collect login state on devices. The risk is credentials being resold, not just 'using a different model'. See the fake reseller case.