Anthropic Says Russian, Chinese Threat Actors Used Its AI Model Claude For Malicious Activity

ZeroHedge
Published
Anthropic Says Russian, Chinese Threat Actors Used Its AI Model Claude For Malicious Activity

The short version

  • The company said the threat actors include suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions…
  • According to its report, most of the cyber operations detected between December 2025 and August 2026 were enabled by AI through direct execution or orchestration.
  • Humans remained involved in selecting targets and reviewing exfiltration, it stated.
  • "The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation…
  • Among the threat actors named by the company was a group linked to Russia-based Midnight Blizzard.

The story

Anthropic Says Russian, Chinese Threat Actors Used Its AI Model Claude For Malicious Activity

Authored by Aldgra Fredly via The Epoch Times,

Anthropic said on Sept. 10 that it had disrupted malicious campaigns involving the use of its artificial intelligence model Claude, including operations allegedly linked to threat actors in China and Russia.

The company said the threat actors include suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals.

According to its report, most of the cyber operations detected between December 2025 and August 2026 were enabled by AI through direct execution or orchestration. Humans remained involved in selecting targets and reviewing exfiltration, it stated.

"The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration," Anthropic said.

Among the threat actors named by the company was a group linked to Russia-based Midnight Blizzard. Anthropic alleged that the group used AI to attack military intelligence targets in Ukraine and Europe, as well as diplomatic and defense organizations and individuals connected to U.S. foreign policy.

Anthropic said it also disrupted distillation attacks against Claude from seven labs based in China, including operators allegedly linked to Alibaba, DeepSeek, Xiaomi, and Moonshot.

The company defined distillation as "an industrial-scale, covert campaign" aimed at illegally extracting the capabilities of an AI model and replicating them in another model.

Operators linked to Alibaba, China's largest e-commerce platform, carried out the largest distillation attack to advance the reasoning capabilities of Alibaba's models, generating more than 151 million exchanges between May and July 2026, the report found. The activity peaked at nearly 3 million exchanges per day launched from over 3,500 accounts that Anthropic deemed fraudulent.

Anthropic also alleged that Chinese AI company Moonshot secretly forwarded customer requests to Claude and then displayed the resulting responses to users as if they were generated by its AI model Kimi.

In one instance, Moonshot allegedly routed nearly 300,000 customer requests to Anthropic's model over a 10-day period using a proxy service network of 5,380 fraudulent accounts, most of which appeared to be located in Singapore and Japan, according to the report.

"Our investigation also revealed that user queries that Moonshot rerouted to Claude included sensitive information about various Moonshot customers," Anthropic said.

"We do not know if Moonshot notified their customers that their requests were being rerouted to Anthropic and exposed to a third party."

The report also identified new categories of threat actors misusing Claude, including those who seek to develop "software for conventional weapons, including firearms, missiles, armed drones, bombs, and other munitions."

Anthropic said it disrupted a "guided weapons engineering cell" operating three weapons development programs in northern Yemen that used Claude "to develop the guidance, navigation, and control (GNC) software that steers and stabilizes a flying vehicle."

According to the report, the threat actors allegedly test-fired a guided rocket but failed, prompting them to seek guidance from Claude to identify the cause of the failure.

Among other newly categorized threat actors was a China-based threat actor that used Claude to advance three parallel projects on "an anti-torpedo weapons system."

Anthropic also identified alleged Russia-based freelance threat actors who sought to build a "full-stack autonomous first-person-view kamikaze drone swarm" and another Russia-based actor who used Claude to research and draft procurement documents for goods likely intended for the Russian government and defense industry customers.

The company said it would continue to strengthen its safeguards and work with partners to prevent misuse of its AI model.

"In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate," it stated.

Tyler Durden Fri, 09/11/2026 - 13:35
Read the full story at ZeroHedgeOriginal

Powered by Gab AI

The Story At A Glance

Reading this article now — analysis appears below

Reading the article

💡 AI analysis provides alternative perspectives on current events

More to read

Recent stories from across the outlets Alto indexes.

Questions Alto can answer

From this story — each link opens a live data page or a tool already filled in.

  1. What is $100 from 1990 worth today?CPI-adjusted dollars — result on the next page
  2. Where does a $75,000 household income rank nationally?Census percentile — national and state
  3. What federal tax bracket is $80,000 (single)?Marginal and effective rate on the next page
  4. What's Alto covering on the Finance desk?Latest headlines on this beat
  5. What else is Alto tracking on Federal Reserve & Interest Rates?Topic hub with related coverage
  6. What else is Alto tracking on Inflation?Topic hub with related coverage

All toolsAll topicsSource directoryStory timelinesHeadline comparisonSearchMost read

From Gab Shop

Official merchandise. Every order funds free speech infrastructure.

Shop all products

Install Alto on your phone

Add Alto to your home screen for breaking news — no app store, no account.

  1. Step 1Open alto.gab.com in SafariMust be Safari — not Chrome or in-app browsers
  2. Step 2Tap the Share buttonSquare with an arrow, at the bottom of Safari
  3. Step 3Tap "More"If you don’t see Add to Home Screen yet
  4. Step 4Tap "Add to Home Screen"Scroll the share sheet if you need to
  5. Step 5Tap "Add"Alto appears on your home screen like any other app.
gab

Talk Markets Freely

Trade ideas, earnings, and the Fed with investors who aren't waiting on a moderator's approval.

What Makes Gab Different

We're not just another social network. We're a platform built on principles that matter.

Freedom of Speech & Reach

All First Amendment protected speech is welcome. No algorithmic throttling or shadow banning.

Family-Friendly Platform

We maintain a clean environment. Explicit adult content is strictly prohibited.

Western Nations Only

Third-world IPs are blocked. No scammers, no spam farms. Built for Western civilization.

Funded By Users

Our users are our investors and customers. You're not the product being sold.

Battle Tested

A decade of standing strong. Banned from app stores, banks—and still here.

American Owned & Operated

We reject foreign censorship demands. Built by Americans, for free people.

Support Alto & Gab

Alto is funded entirely by readers like you. Your donation helps us continue delivering curated news from a right-wing Christian Nationalist perspective, powered by Gab AI.