AI & Computing NewsCyber security NewsNews

Anthropic Says Russian and Chinese Hackers Are Now Letting AI Run the Attacks, Not Just Assist Them

Anthropic disclosed that it disrupted a Russian state-linked espionage campaign and seven Chinese AI labs running industrial-scale efforts to extract Claude's capabilities, warning that cybercriminals are increasingly letting AI orchestrate entire attacks.

Key Takeaways

  • Anthropic’s Threat Intelligence report covers disrupted misuse cases from December 2025 through August 2026, its third public accounting since March 2025
  • A Russia-linked group tied to Midnight Blizzard used Claude to automatically detect when its malware was flagged by security software and rewrite the code until it evaded detection again
  • Operators linked to Alibaba generated more than 151 million exchanges between May and July in what Anthropic called its largest illicit distillation attack yet
  • Anthropic said humans increasingly acted as overseers rather than hands-on operators, with AI directly executing large portions of the attacks

Anthropic’s latest Threat Intelligence report details disrupted attempts to misuse its Claude models over the past eight months, including a Russian state-linked espionage operation and efforts by seven Chinese AI labs to extract and replicate Claude’s capabilities.

The company said the key shift in this batch of incidents is how attacks are carried out: hackers increasingly use AI to execute attacks, while humans mainly supervise periodically rather than handle each step.

Russia’s Midnight Blizzard Used Claude to Outrun Its Own Malware Detection

Anthropic attributed one of the report’s most sophisticated cases to a group consistent with Midnight Blizzard, also tracked as APT29 and linked by the U.S. government to Russia’s SVR foreign intelligence service. 

According to Anthropic, the group used Claude to build an automated system that tested whether malware was flagged by security products, then rewrote the code until it evaded detection, a process that previously required human analysts. 

The targets, per Anthropic, included Ukrainian and European government bodies, along with diplomatic and defense organizations. 

Anthropic also disrupted activity tied to ShinyHunters, a prolific cybercrime group behind major corporate breaches, including TELUS. Though the Crunchyroll incident that happened this March involved TELUS, it was not carried out by ShinyHunters. 

Separately, in one of six newly documented weapons-related cases, Anthropic said a Yemeni cell used Claude Code to develop guidance software for a ballistic missile program. 

Alibaba, Moonshot, and DeepSeek Took Different Roads to the Same Target

On the Chinese side, Anthropic said it disrupted activity from seven labs, specifically naming Alibaba, Moonshot, DeepSeek, and Xiaomi. 

The largest case, described as its biggest illicit distillation attack, involved Alibaba-linked operators generating more than 151 million exchanges with Claude between May and July.

Those campaigns peaked at nearly 3 million interactions a day across more than 3,500 fraudulent accounts to extract Claude’s capabilities for Alibaba’s Qwen models

Moonshot, maker of Kimi chatbot, and DeepSeek reportedly used a subtler approach, routing live customer conversations, including some sensitive information, through Claude and using its responses as training data instead of bulk automated queries. 

Distillation itself isn’t prohibited technology, but Anthropic said both approaches deliberately sidestep its terms of service at a scale far beyond routine research use.

The Real Story Is the Shift From Assistant to Operator

What ties Thursday’s disclosures together isn’t Russia or China, but the broader pattern Anthropic describes: the AI models are increasingly running entire attack operations rather than acting as simple chatbots to answer questions for human attackers. 

They can now evade detection and sustain distillation campaigns for months with limited human involvement. 

That creates a different threat model from traditional cybersecurity, where human judgment guided each decision. 

Anthropic’s willingness to publish this level of detail, including tactics sophisticated enough for competitors to learn from, reflects a calculated bet that transparency now is less costly than a larger, undetected incident later.

Whether it pays off depends not only on Anthropic’s safeguards, but on whether other AI labs openly report similar threats instead of waiting for investigations to expose them.

Source: Detecting and countering misuse of AI

Fawad Malik

Fawad Malik is a digital marketing professional and technology writer with over 15 years of industry experience. He specializes in SEO, SaaS, AI, consumer technology, internet services, and content strategy. He is the Founder and CEO of WebTech Solutions, a digital agency focused on helping businesses grow through modern online strategies. Through NogenTech, Fawad shares practical insights on internet technology, WiFi, apps, AI tools, digital trends, and the latest tech updates for readers worldwide.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button