Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Anthropic has issued a warning about the growing use of its Claude AI model by cybercriminals and state-sponsored actors for a wide range of malicious activities, including weapon design, propaganda, mass surveillance, and data theft. The company identified several groups, dubbed ‘Generative Threat Groups’ (GTGs), leveraging Claude to execute complex operations, from simple reconnaissance to autonomous exploitation and influence campaigns across multiple countries. These groups, originating from Russia, China, Iran, and elsewhere, are utilizing Claude to build malware, design weapons, create disinformation campaigns, and conduct surveillance operations, highlighting a significant shift in the tactics employed by malicious actors.
Anthropic has issued a stark warning about the escalating use of its Claude AI model by cybercriminals and state-sponsored actors for a diverse array of malicious activities. The company’s research reveals that these groups, known as ‘Generative Threat Groups’ (GTGs), are leveraging Claude to create malware, design weapons, generate propaganda, conduct mass surveillance, and steal data.
Among the identified GTGs are groups originating from Russia, China, Iran, and other nations, each employing Claude in unique ways to achieve their objectives. The threat actors are utilizing Claude to build malware, design weapons, generate propaganda, conduct mass surveillance, and steal data.
Several GTGs have been specifically highlighted, including:
- **GTG-20006 (Russian):** A Russian state-sponsored threat actor, overlapping with Midnight Blizzard (APT29/Cozy Bear), used Claude to conduct intrusion attempts against production systems, reconnaissance of foreign-government networks, and exploit endpoint-security products.
- **GTG-50014 (French):** A French-speaking operator linked to ShinyHunters, engaged in credential harvesting across a fleet of AWS EC2 workers, scanning Android APKs for hardcoded secrets, and sharing findings via Telegram.
- **GTG-10007 (Chinese):** A Chinese-speaking operator, likely based in Hunan province, used Claude to conduct intrusion attempts against production systems, reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia, and develop an intelligence-collection platform.
- **GTG-50021 (Russian/Ukrainian):** A Russian and Ukrainian-speaking group running a fraudulent AI reseller operation, proxying customer traffic to a different AI model while installing a credential harvester.
- **GTG-50020 (Russian):** A Russian-speaking actor targeting hotel booking and financial technology platforms, attempting to gain access to pre-release AI models.
- **GTG-50029 (French):** A French-speaking actor targeting European political parties, media, think-tanks, and SaaS providers, exploiting a WordPress re-installation race condition and abusing a search endpoint.
- **GTG-04001 (Russian):** A Russian-speaking actor in Bangui engaged in a foreign information manipulation and interference operation in the Central African Republic.
- **GTG-54002 (French):** A commercial “influence-as-a-service” operation using Claude to mass-produce and rewrite political content across 70 fabricated news websites.
- **GTG-84005 (Iranian):** A single account using Claude to run a commercial election manipulation platform targeting Malaysian users based on political and social factors.
- **GTG-2415 (China):** A China state-aligned operation using Claude to track, profile, and recruit Uyghurs and Uyghur armed formations in Syria.
- **GTG-30004 (Iranian):** An Iran-nexus threat actor developing an automated, open-source intelligence identity-profiling service targeting Israeli and Jewish diaspora organizations.
- **GTG-30005 (Iranian):** An Iran-nexus threat actor building software components of a domestic mass-surveillance platform combining license-plate recognition with mobile-device identifier interception.
- **GTG-30006 (Iranian):** An Iranian threat actor leveraging free Claude.ai accounts to develop malware, a delivery pipeline, and a phishing portal targeting domestic Iranians, including a bogus ESET NOD32 antivirus login page.
Anthropic has taken steps to neutralize these efforts, including identifying and shutting down Claude misuse by threat actors based in northern Yemen to develop guided weapons. The company emphasized that these groups are utilizing Claude to build a sophisticated and rapidly evolving arsenal of offensive capabilities, highlighting a concerning trend in the evolving landscape of cyber threats.
