Anthropic Says Russian, Chinese Threat Actors Used Its AI Model Claude For Malicious Activity
Authored by Aldgra Fredly via The Epoch Times,
Anthropic said on Sept. 10 that it had disrupted malicious campaigns involving the use of its artificial intelligence model Claude, including operations allegedly linked to threat actors in China and Russia.
The company said the threat actors include suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals.
According to its report, most of the cyber operations detected between December 2025 and August 2026 were enabled by AI through direct execution or orchestration. Humans remained involved in selecting targets and reviewing exfiltration, it stated.
“The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration,” Anthropic said.
Among the threat actors named by the company was a group linked to Russia-based Midnight Blizzard. Anthropic alleged that the group used AI to attack military intelligence targets in Ukraine and Europe, as well as diplomatic and defense organizations and individuals connected to U.S. foreign policy.
Anthropic said it also disrupted distillation attacks against Claude from seven labs based in China, including operators allegedly linked to Alibaba, DeepSeek, Xiaomi, and Moonshot.
The company defined distillation as “an industrial-scale, covert campaign” aimed at illegally extracting the capabilities of an AI model and replicating them in another model.
Operators linked to Alibaba, China’s largest e-commerce platform, carried out the largest distillation attack to advance the reasoning capabilities of Alibaba’s models, generating more than 151 million exchanges between May and July 2026, the report found. The activity peaked at nearly 3 million exchanges per day launched from over 3,500 accounts that Anthropic deemed fraudulent.
Anthropic also alleged that Chinese AI company Moonshot secretly forwarded customer requests to Claude and then displayed the resulting responses to users as if they were generated by its AI model Kimi.
In one instance, Moonshot allegedly routed nearly 300,000 customer requests to Anthropic’s model over a 10-day period using a proxy service network of 5,380 fraudulent accounts, most of which appeared to be located in Singapore and Japan, according to the report.
“Our investigation also revealed that user queries that Moonshot rerouted to Claude included sensitive information about various Moonshot customers,” Anthropic said.
“We do not know if Moonshot notified their customers that their requests were being rerouted to Anthropic and exposed to a third party.”
The report also identified new categories of threat actors misusing Claude, including those who seek to develop “software for conventional weapons, including firearms, missiles, armed drones, bombs, and other munitions.”
Anthropic said it disrupted a “guided weapons engineering cell” operating three weapons development programs in northern Yemen that used Claude “to develop the guidance, navigation, and control (GNC) software that steers and stabilizes a flying vehicle.”
According to the report, the threat actors allegedly test-fired a guided rocket but failed, prompting them to seek guidance from Claude to identify the cause of the failure.
Among other newly categorized threat actors was a China-based threat actor that used Claude to advance three parallel projects on “an anti-torpedo weapons system.”
Anthropic also identified alleged Russia-based freelance threat actors who sought to build a “full-stack autonomous first-person-view kamikaze drone swarm” and another Russia-based actor who used Claude to research and draft procurement documents for goods likely intended for the Russian government and defense industry customers.
The company said it would continue to strengthen its safeguards and work with partners to prevent misuse of its AI model.
“In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate,” it stated.
Tyler Durden
Fri, 09/11/2026 – 13:35









