Anthropic's Threat Report Finds AI Moving From Assistant to Orchestrator
In a threat intelligence report, Anthropic details malicious uses of Claude that it disrupted between December 2025 and August 2026 across seven areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and distillation. Haiku, Sonnet and Opus models were used in the documented cases.
Most of the operations were enabled by AI through direct execution or orchestration rather than question and answer assistance. Attackers used multi agent frameworks for reconnaissance, exploitation and data exfiltration, with humans remaining in the loop to set targets and review what was taken.
The case Anthropic uses to illustrate the shift is GTG-20006, which it says increased its speed by automating its operations. Anthropic puts its own attribution carefully: it says its attribution is consistent with public reporting linking the actor to Midnight Blizzard, and that one operator is a Russian speaker whose tradecraft and targeting are consistent with Russian state nexus espionage. The operations attacked military intelligence targets in Ukrainian and European governments, diplomatic and defence organisations, and individuals connected to US foreign policy.
The detail that matters for defenders is what the automation replaced. Static detection has historically imposed cost on attackers, who had to rebuild toolkits once signatures caught them. This actor ran an AI assisted workflow that watched whether security products detected its malware and rebuilt and redeployed the toolkit when they did, which removes the delay that made detection expensive for the attacker.
Anthropic says it disrupted the activity in each case, used what it learned to strengthen safeguards, and shared intelligence with authorities and industry partners where appropriate.
We hope you enjoyed this article.
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly, AI Policy Brief or Daily AI Brief.
Also, consider following us on social media:
More from: Cybersecurity
More from: AI Safety
Subscribe to Cybersecurity AI Weekly
Weekly newsletter about AI in Cybersecurity.
Industry analysis
2025 Global Business Services Agenda: Gen AI Takes Center Stage
This industry analysis by The Hackett Group explores the transformative impact of generative artificial intelligence (Gen AI) on global business services (GBS) in 2025. The study highlights the shift from exploration to acceleration of Gen AI initiatives, with 89% of executives advancing these projects to improve customer satisfaction, innovate products, and reduce costs. The report also discusses the challenges and strategies for successful Gen AI adoption, emphasizing the need for a technology-enabled operating model and the importance of reskilling the workforce.
Read more