AI-assisted cyber operations: the scale changes, the basics mostly don't
Definition
This topic covers actors who embed AI into cyber operation workflows to speed up reconnaissance, write tools, process stolen data, or maintain access. The harm targets organizations' systems, accounts, and data, and can ultimately reach individuals.
The report divides capability gains into speed, scale, and depth, and discusses the shift from 'assistant' to 'workflow orchestration'. Many basic techniques remain stolen credentials, unpatched systems, and social engineering.
Not to be confused with
Not 'AI invented entirely new attacks'. The report repeatedly shows that entry points are still old techniques; AI mainly lowers execution costs.
Not 'model labs were necessarily breached'. GTG-50020 makes clear: no unreleased models were obtained, and Anthropic's own systems were not compromised.
Not a place to find attack tutorials. We only explain risk types and evidence boundaries.
Original report figure: overview of capabilities and roles at the start of the cyber operations chapter.
AI roles
In this chapter's cases, AI appears in roles like software development, workflow orchestration, and data analysis. Humans still set goals, choose targets, and decide whether to continue.
'Orchestration' means handing multi-step tasks to an agent loop, not that the system is fully autonomous without humans.
According to an Anthropic report, a group of Chinese-speaking operators assessed to be likely based in Changsha, Hunan, China, used Claude as the engineering and orchestration layer for a coordinated attack campaign. Multiple workflows ran in parallel: intrusions into production systems, reconnaissance of foreign government networks, ongoing vulnerability research and exploit development against mainstream endpoint security products, malware development, and operation of an unattended intelligence-collection platform. The targets were roughly 50 organizations. Attribution information such as the operators' location comes from the report's assessment; their vulnerability findings were validated only in the actors' own experimental environments.
According to Anthropic's September 2026 report, GTG-20006 is a cyber espionage actor who uses AI to automate operations and gain speed. Anthropic says its attribution is consistent with public reporting linking the actor to Midnight Blizzard. The actor used a custom toolkit including two types of Windows implants, a mobile exploitation suite, a credential stealer targeting browser password vaults, a phishing platform designed to impersonate priority targets such as government organizations, and a management console for controlling compromised accounts. The report observed that GTG-20006 automated most of its operations — from development, infrastructure acquisition, phishing, command-and-control persistence, to data exfiltration — through customized AI-driven workflows.
According to the report, an Iran-linked threat actor used Claude to build an automated open-source intelligence identity profiling tool targeting Israeli government and non-government individuals and Jewish diaspora organizations. The actor also used Claude to modify the open-source LSASS credential dumper NanoDump and build a custom C++ obfuscation/build pipeline to obfuscate malware samples and hinder analysis.
According to the report, an Iran-linked threat actor used Claude to collect and analyze publicly available data to develop targeting recommendations against U.S. Navy forces in the region. The actor used Claude to write targeting handbooks, identifying and tracking naval positions based on open-source information. The same account also developed enterprise software for Iranian state systems, including designing a large-scale domestic surveillance platform combining automatic license plate recognition and mobile device identifier interception. This page does not publish any target coordinates or exploitation details.
According to the report, an Iranian threat actor used 16 free Claude.ai accounts across 16 single-operator organizations to develop malware, delivery pipelines, and phishing portals targeting domestic Iranian users. The delivery pages were designed to serve malicious content only to visitors with IP addresses from Iran, themed around censorship-circumvention tools and fabricated Persian-language news brands. The actor used Claude to develop the SECOMS64 modular Windows implant, including a keylogger, screenshot capture, Chrome credential extraction, and more. This page does not publish any malware code or phishing links.
According to Anthropic's report, multiple opportunistic intrusion clusters suspected of being linked to the ShinyHunters group used AI to enhance their criminal activity. These actors broadly scanned unpatched internet-facing systems, rummaged through public containers, code repositories, mobile apps, and more for credentials, tokens, and API keys, then went straight for databases to steal customer data after gaining access, and extorted victims by threatening to publish or sell the data. The report says AI agents did most of the work, with one case going from a stolen token to full control of a victim's cloud environment in about 3 hours. The report also makes clear: Anthropic's own systems were not breached by this actor.
According to Anthropic's report, GTG-50020 is a Russian-speaking, financially motivated actor that historically targeted hotel booking and fintech platforms. In one intrusion, they exfiltrated about 26 GB of data from a victim and attempted to obtain $1.5 to $2.5 million through ransom (or by selling the data on dark web forums). They then pivoted the same techniques toward the AI industry: by injecting malicious instructions into an AI vendor's automated evaluation sandbox, they made the sandbox hand over the credentials it held—including production AI API keys for multiple providers held by that vendor. The report makes clear: the actor never obtained access to unreleased Claude models, and Anthropic's own systems were not breached.
According to Anthropic's report, the AI supply chain has become a target, loot, and source of attack compute for malicious actors. AI access in the form of stolen API keys, session tokens, and devices is increasingly the sole objective of multiple criminal groups. GTG-50021 is a fake AI reseller service operated by a Russian- and Ukrainian-speaking actor. Customers thought they were buying discounted Claude access, but their traffic was silently routed to other models; the reseller tool also installed a credential collector on the device, reselling account credentials to other proxy networks.
According to Anthropic's report, in spring 2026 a French-speaking actor used Claude to target European political parties, media, think tanks, and the software services they use. The report tracked 42 target entities, of which at least 14 were internally accessed, with an estimated 12 to 26 GB of data stolen. This is an example of one person using AI to scale intrusion and data correlation capabilities; this page does not provide any personally identifiable data.
Limits of response
The report is a single platform's selected disclosures and cannot be used to rank countries or industries by risk.
Indicators of compromise and specific exploitation steps are not reproduced here.
The report shows that lower-resourced actors can build more complex tools and process data at larger scale, but entry points still depend on exposed interfaces, stolen keys, and unpatched systems. The capability gap is narrowing, not disappearing.
What's dangerous about fake 'discounted Claude' services?
The reseller services described in the report silently redirect traffic and collect login state on devices. The risk is credentials being resold, not just 'using a different model'. See the fake reseller case.