- by x32x01 ||
Anthropic's latest threat intelligence report shows that AI-assisted cyberattacks are moving far beyond simple coding assistance. Attackers are increasingly using Claude to automate reconnaissance, develop tools, process stolen data, and connect multiple stages of an intrusion into a single workflow.
The report, “Detecting and Countering Misuse of AI: September 2026,” covers malicious activity Anthropic says it identified and disrupted between December 2025 and August 2026. The cases span cyber operations, surveillance, fraud, influence operations, biological misuse, conventional weapons development, and illicit AI distillation.
What makes the report particularly concerning is not that attackers suddenly discovered completely new hacking techniques. Instead, AI is making existing techniques faster, more scalable, and accessible to operators who previously needed much larger teams and more specialized skills.
According to Anthropic, threat actors increasingly use AI across multiple stages of the cyber kill chain, including reconnaissance, tool development, phishing, exploitation, credential collection, data processing, and exfiltration.
Anthropic describes this as a major increase in speed, scale, and depth.
This means an attacker does not necessarily need a large team of specialists to maintain a sophisticated campaign. AI can help connect many technical tasks that previously required different people with different skills.
The report's most important warning can be summarized simply:
Sophisticated attacks no longer necessarily require sophisticated attackers.
Anthropic says the activity was consistent with public reporting connecting the operation to
The important part is how AI was integrated into the operation.
Instead of using Claude only to generate occasional code, the attackers reportedly created AI-driven workflows that helped automate large portions of the operation.
The reported activity included:
If a security product detects a malicious artifact, an AI-assisted workflow can potentially analyze the failure, modify the artifact, and attempt another version.
This reduces the amount of time defenders may have to investigate and respond.
According to the report, attackers obtained sensitive information from drone-related companies, including a proprietary software development kit. They then used AI-assisted analysis to understand the technology, including aspects of the product architecture and hardware.
The campaign reportedly also uncovered information about products that had not yet been publicly announced.
This demonstrates another important use of AI in cyber operations:
AI can make stolen data more valuable by helping attackers analyze it quickly.
Stealing a large technical dataset is one problem. Understanding thousands of files, identifying important components, reconstructing relationships, and finding valuable information is another.
AI can significantly reduce the amount of human effort required for the second part.
Rather than attacking every victim directly, attackers reportedly compromised technology providers that served multiple organizations.
This type of approach can create a powerful multiplier because compromising one service provider may expose multiple downstream victims.
Anthropic also describes the use of DNS manipulation in these campaigns. The attackers reportedly used compromised infrastructure to influence how victims were directed to online services and to collect information about targeted systems.
This is a good reminder that security teams need to consider third-party infrastructure and supply-chain relationships, not just their own servers and endpoints.
The basic idea behind ClickFix attacks is social engineering rather than a traditional software exploit.
A victim may see a fake browser, application, or system message claiming that something needs to be fixed or updated. The page then attempts to persuade the victim to perform an action that ultimately benefits the attacker.
The danger is that users may believe they are following a legitimate troubleshooting instruction.
For defenders, this means endpoint security alone is not enough. Security awareness, browser protections, application controls, and strong endpoint monitoring all play an important role.
According to the report, attackers used automated browser technology and the open-source
The objective was not necessarily to steal the victim's password.
Instead, the attackers attempted to abuse the legitimate device-linking functionality of the messaging platform.
Once another device is successfully linked, an attacker may be able to interact with the account in ways that look similar to a legitimate WhatsApp Web session.
The reported operation also attempted to reduce visible signs that messages were being accessed and then performed large-scale exports of conversations. At least two former senior Ukrainian officials were reportedly among the targets.
The lesson is important:
Account security is not only about protecting passwords.
Organizations also need to monitor unexpected device registrations, suspicious sessions, unusual account behavior, and unauthorized access to messaging platforms.
Authentication answers: “Who are you?”
Authorization answers: “What are you allowed to access?”
A system can correctly authenticate a user while still having a serious authorization flaw.
If an application fails to properly verify whether the authenticated user is allowed to access a specific camera, account, or resource, attackers may be able to access information belonging to other users.
The reported attackers allegedly abused authorization weaknesses to identify users and access active camera streams.
This is a classic example of why security testing should not stop after verifying that login protection works.
According to the report, attackers obtained VPN credentials and used the resulting access to compromise accounts and collect sensitive government information.
The reported data included more than 300,000 national identity records and commercial registry information covering more than 500,000 companies.
The same operation reportedly used Device Code Phishing to target Microsoft 365 accounts.
This is particularly relevant for organizations using cloud identity platforms because compromising an identity token or session can sometimes provide access without requiring the attacker to know the victim's actual password.
The report also describes attempts to obtain authentication material from Windows environments and cloud applications.
Attackers may attempt to obtain authentication material stored by applications or operating systems and then use it to access services as an already authenticated user.
This makes identity security one of the most important parts of modern cybersecurity.
Organizations should therefore pay close attention to:
It is the automation of the entire attack process.
Anthropic says threat actors are increasingly using AI to connect activities that traditionally required multiple specialists.
An attacker can potentially use AI to help with reconnaissance, develop tooling, analyze targets, process stolen information, and coordinate repetitive tasks.
That changes the economics of cyberattacks.
The barrier is no longer only technical knowledge. It is also how effectively an attacker can combine AI with existing offensive infrastructure.
Instead, defenders should focus on behavior and outcomes.
Important areas include:
Anthropic says it disrupted the operations described in the report, banned accounts involved in the misuse, improved its safeguards, and shared relevant intelligence with authorities and industry partners where appropriate.
The technology is not necessarily creating entirely new attack techniques.
Instead, it is helping attackers scale existing techniques, automate repetitive work, analyze huge amounts of stolen information, and connect multiple stages of an intrusion.
That could make sophisticated campaigns cheaper and faster to operate.
For defenders, the answer is not simply to block AI.
The more practical approach is to assume that attackers will use AI and build security controls around that reality.
Identity protection, behavioral detection, strong authorization, endpoint visibility, supply-chain security, and rapid incident response are becoming even more important as AI reduces the amount of human effort required to conduct complex cyber operations.
Anthropic's report is therefore less about one dangerous AI model and more about a broader shift in cybersecurity:
AI is changing who can conduct sophisticated cyber operations, how quickly those operations can scale, and how much data attackers can process once they gain access.
The report, “Detecting and Countering Misuse of AI: September 2026,” covers malicious activity Anthropic says it identified and disrupted between December 2025 and August 2026. The cases span cyber operations, surveillance, fraud, influence operations, biological misuse, conventional weapons development, and illicit AI distillation.
What makes the report particularly concerning is not that attackers suddenly discovered completely new hacking techniques. Instead, AI is making existing techniques faster, more scalable, and accessible to operators who previously needed much larger teams and more specialized skills.
AI Is Becoming an Orchestrator, Not Just an Assistant
One of the biggest findings is a shift from using AI for individual tasks to using AI as part of an automated attack workflow.According to Anthropic, threat actors increasingly use AI across multiple stages of the cyber kill chain, including reconnaissance, tool development, phishing, exploitation, credential collection, data processing, and exfiltration.
Anthropic describes this as a major increase in speed, scale, and depth.
This means an attacker does not necessarily need a large team of specialists to maintain a sophisticated campaign. AI can help connect many technical tasks that previously required different people with different skills.
The report's most important warning can be summarized simply:
Sophisticated attacks no longer necessarily require sophisticated attackers.
GTG-20006 and Suspected Russian Espionage
One of the most notable cases is GTG-20006, which Anthropic describes as a suspected Russian state-linked espionage operation.Anthropic says the activity was consistent with public reporting connecting the operation to
Midnight Blizzard. The campaign reportedly targeted organizations in Ukraine and Europe, including government entities, diplomatic organizations, defense-related targets, and parts of the drone supply chain.The important part is how AI was integrated into the operation.
Instead of using Claude only to generate occasional code, the attackers reportedly created AI-driven workflows that helped automate large portions of the operation.
The reported activity included:
- Developing malware and other offensive tooling.
- Supporting phishing infrastructure.
- Processing stolen information.
- Automating parts of reconnaissance.
- Supporting credential theft and account compromise.
- Analyzing collected data.
- Modifying malicious software when security controls detected it.
If a security product detects a malicious artifact, an AI-assisted workflow can potentially analyze the failure, modify the artifact, and attempt another version.
This reduces the amount of time defenders may have to investigate and respond.
Drone Companies Were Also Targeted
Anthropic's report describes attacks against organizations involved in drone technology.According to the report, attackers obtained sensitive information from drone-related companies, including a proprietary software development kit. They then used AI-assisted analysis to understand the technology, including aspects of the product architecture and hardware.
The campaign reportedly also uncovered information about products that had not yet been publicly announced.
This demonstrates another important use of AI in cyber operations:
AI can make stolen data more valuable by helping attackers analyze it quickly.
Stealing a large technical dataset is one problem. Understanding thousands of files, identifying important components, reconstructing relationships, and finding valuable information is another.
AI can significantly reduce the amount of human effort required for the second part.
Hotel Wi-Fi and DNS Hijacking
The report also describes attacks involving hospitality providers and guest Wi-Fi infrastructure.Rather than attacking every victim directly, attackers reportedly compromised technology providers that served multiple organizations.
This type of approach can create a powerful multiplier because compromising one service provider may expose multiple downstream victims.
Anthropic also describes the use of DNS manipulation in these campaigns. The attackers reportedly used compromised infrastructure to influence how victims were directed to online services and to collect information about targeted systems.
This is a good reminder that security teams need to consider third-party infrastructure and supply-chain relationships, not just their own servers and endpoints.
ClickFix and Social Engineering
Another technique mentioned in the reported activity is ClickFix.The basic idea behind ClickFix attacks is social engineering rather than a traditional software exploit.
A victim may see a fake browser, application, or system message claiming that something needs to be fixed or updated. The page then attempts to persuade the victim to perform an action that ultimately benefits the attacker.
The danger is that users may believe they are following a legitimate troubleshooting instruction.
For defenders, this means endpoint security alone is not enough. Security awareness, browser protections, application controls, and strong endpoint monitoring all play an important role.
WhatsApp Accounts and Companion Devices
Anthropic also describes activity involving WhatsApp accounts.According to the report, attackers used automated browser technology and the open-source
WPPConnect project to help connect compromised accounts to attacker-controlled companion devices.The objective was not necessarily to steal the victim's password.
Instead, the attackers attempted to abuse the legitimate device-linking functionality of the messaging platform.
Once another device is successfully linked, an attacker may be able to interact with the account in ways that look similar to a legitimate WhatsApp Web session.
The reported operation also attempted to reduce visible signs that messages were being accessed and then performed large-scale exports of conversations. At least two former senior Ukrainian officials were reportedly among the targets.
The lesson is important:
Account security is not only about protecting passwords.
Organizations also need to monitor unexpected device registrations, suspicious sessions, unusual account behavior, and unauthorized access to messaging platforms.
Authorization Problems Can Expose Camera Streams
Another part of the report involved weaknesses in authorization controls for camera-streaming services.Authentication answers: “Who are you?”
Authorization answers: “What are you allowed to access?”
A system can correctly authenticate a user while still having a serious authorization flaw.
If an application fails to properly verify whether the authenticated user is allowed to access a specific camera, account, or resource, attackers may be able to access information belonging to other users.
The reported attackers allegedly abused authorization weaknesses to identify users and access active camera streams.
This is a classic example of why security testing should not stop after verifying that login protection works.
A North African Government Was Also Targeted
Anthropic also reported activity involving a North African government organization.According to the report, attackers obtained VPN credentials and used the resulting access to compromise accounts and collect sensitive government information.
The reported data included more than 300,000 national identity records and commercial registry information covering more than 500,000 companies.
The same operation reportedly used Device Code Phishing to target Microsoft 365 accounts.
This is particularly relevant for organizations using cloud identity platforms because compromising an identity token or session can sometimes provide access without requiring the attacker to know the victim's actual password.
The report also describes attempts to obtain authentication material from Windows environments and cloud applications.
Why Token Theft Is Becoming More Important
Modern attacks increasingly target sessions, tokens, API keys, and cloud credentials, rather than relying exclusively on password theft.Attackers may attempt to obtain authentication material stored by applications or operating systems and then use it to access services as an already authenticated user.
This makes identity security one of the most important parts of modern cybersecurity.
Organizations should therefore pay close attention to:
- MFA and phishing-resistant authentication.
- Device registration and management.
- OAuth applications and permissions.
- Cloud session monitoring.
- API key protection.
- Unusual mailbox access.
- Large-scale data exports.
- Suspicious authentication patterns.
- Endpoint credential stores.
What Makes the 2026 Report Different?
The most important change is not a single vulnerability or malware family.It is the automation of the entire attack process.
Anthropic says threat actors are increasingly using AI to connect activities that traditionally required multiple specialists.
An attacker can potentially use AI to help with reconnaissance, develop tooling, analyze targets, process stolen information, and coordinate repetitive tasks.
That changes the economics of cyberattacks.
The barrier is no longer only technical knowledge. It is also how effectively an attacker can combine AI with existing offensive infrastructure.
What Security Teams Should Take Away
Organizations should not respond to these developments by focusing exclusively on detecting AI-generated code.Instead, defenders should focus on behavior and outcomes.
Important areas include:
- Detecting unusual authentication and token activity.
- Monitoring new device registrations.
- Protecting VPN and cloud credentials.
- Limiting OAuth permissions.
- Using phishing-resistant MFA.
- Monitoring bulk email and data exports.
- Protecting third-party and supply-chain connections.
- Detecting abnormal DNS changes.
- Monitoring endpoint behavior rather than relying only on signatures.
- Rotating credentials quickly after suspected compromise.
Anthropic says it disrupted the operations described in the report, banned accounts involved in the misuse, improved its safeguards, and shared relevant intelligence with authorities and industry partners where appropriate.
The Bigger Picture
The most worrying conclusion from Anthropic's September 2026 report is that AI is becoming part of the operational infrastructure behind cyberattacks.The technology is not necessarily creating entirely new attack techniques.
Instead, it is helping attackers scale existing techniques, automate repetitive work, analyze huge amounts of stolen information, and connect multiple stages of an intrusion.
That could make sophisticated campaigns cheaper and faster to operate.
For defenders, the answer is not simply to block AI.
The more practical approach is to assume that attackers will use AI and build security controls around that reality.
Identity protection, behavioral detection, strong authorization, endpoint visibility, supply-chain security, and rapid incident response are becoming even more important as AI reduces the amount of human effort required to conduct complex cyber operations.
Anthropic's report is therefore less about one dangerous AI model and more about a broader shift in cybersecurity:
AI is changing who can conduct sophisticated cyber operations, how quickly those operations can scale, and how much data attackers can process once they gain access.
- by x32x01 ||
