Skip to main content
Emerging ThreatsMalware & Ransomware

AI Enables Small Actors to Launch Sophisticated Hacking Campaigns

Dimly lit, cramped room with outdated laptop and blurred screen display.

“The cases we share here aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date,” the Anthropic report reads.

Between December 2025 and August 2026, Anthropic says, its investigators observed Claude models being misused across seven distinct harm areas — from cyber operations and influence campaigns to surveillance and biological misuse. The company says it disrupted each operation, strengthened safeguards and shared intelligence with authorities and industry partners where appropriate.

JackPoterz and Russian-aligned espionage

Anthropic devotes the most detailed case study to an actor using the handle “JackPoterz,” whose behavior the report says aligned with Russian state espionage and matched techniques linked to Midnight Blizzard. The actor deployed a multi-component toolkit: two families of Windows implants, a mobile exploitation kit, a credential-stealing tool targeting browser password stores, a phishing platform aimed at priority targets like government organizations, and an administrative console to manage compromised accounts.

The campaign hit more than 20 government and defense organizations across Ukraine and Europe, along with diplomatic and defense bodies and people connected to U.S. foreign policy. Anthropic reports that AI agents monitored whether security products flagged the malware and, when detections appeared, autonomously modified and rebuilt the malware to evade those detections. The actor also exfiltrated substantial data: more than 300,000 national identity records from a North African government agency and registry data on more than half a million companies. Separate intrusions bulk-exported mailboxes at drone component manufacturers and yielded a complete software development kit for a drone vision system; the operator then spent days reconstructing its architecture and details of an unannounced product. The report also says the actor compromised hotel Wi‑Fi vendors to conduct DNS hijacking of guests and took over WhatsApp accounts with headless browsers.

Chinese undergraduates and an automated exploit foundry

Anthropic attributes another cluster of activity to Chinese-speaking operators, in part carried out by two undergraduates at a Chinese university. The duo used Claude to automate vulnerability research around the clock. One workflow targeting network appliance firmware “yielded more than a dozen possible zero day findings in a single month,” the report says.

Operationally, the researchers ran “agent swarms” in which a lead agent divided work among parallel subagents and preserved campaign memory between sessions — a pattern Anthropic highlights as enabling continuous, high-throughput discovery that would previously have required more personnel and specialist expertise.

ShinyHunters affiliates and a rapid cloud-token dump

Clusters linked to affiliates of the ShinyHunters criminal collective show how AI shortened traditional criminal timelines. In one supply-chain compromise, operators dumped more than 2,100 Azure access tokens spanning more than 40 corporate tenants in roughly 34 hours. Anthropic reports that “AI agents performed nearly all of the work.”

In a related incident, a compromise shifted from a single stolen developer token to full control of a victim’s cloud environment in about three hours — a rapid escalation that the report uses to illustrate how automation multiplies the impact of otherwise isolated credential theft.

Distillation attacks by Chinese labs, and silent forwarding

Anthropic documents what it calls distillation attacks dating to February, carried out by seven labs based in China, naming Alibaba, DeepSeek, Moonshot AI, Xiaomi and Zhipu among them. Operators affiliated with Alibaba ran the largest campaign measured by Anthropic, peaking “at nearly 3 million exchanges per day launched from more than 3,500 fraudulent accounts” to harvest outputs of Claude Opus models for training their Qwen systems.

Moonshot and DeepSeek, Anthropic says, silently forwarded customers’ requests to Claude and returned the model’s answers as their own, exposing user data that had not been agreed for sharing. The report says those practices exposed sensitive content, including surveillance footage of a tracked individual pulled by a user likely affiliated with the People’s Liberation Army, and that the practices are “likely inconsistent with privacy laws and the labs’ own terms of service.”

Anthropic’s disclosure of these incidents follows a joint advisory earlier this week from the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI accusing Chinese AI companies of a deliberate and “systematic” effort to illegally distill U.S. frontier AI models and their capabilities.

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: Expect detection-evasion workflows that include AI-driven rebuilding of malware and continuous exploit discovery via agent swarms; protect API keys, developer tokens and cloud credentials aggressively, and monitor for unusual token exfiltration patterns like mass Azure-token dumps.
  • Policymakers and regulators: The report underscores the cross-border character of automated distillation and data harvesting; the joint NSA–CISA–FBI advisory and Anthropic’s findings point to a regulatory focus on unauthorized model-distillation and platform-level safeguards for user data.
  • Affected enterprises and procurement leaders: Anthropic’s cases show rapid escalation from a single stolen developer token to full cloud takeover in roughly three hours and large-scale theft of corporate and government data; procurement and risk teams should evaluate contractual protections, telemetry-sharing arrangements and incident-response playbooks that assume fast, AI-enabled adversary playbooks.

Anthropic frames its findings as an early view of a changing threat landscape: “As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer,” the report says, and adds that the old idea of “security through obscurity” is no longer viable. The company provides the detailed cases to show how small teams and lone actors, aided by AI, can execute campaigns once associated with state tradecraft — and it says it has taken steps to disrupt the activity and share intelligence where appropriate.

The report leaves a clear, practical question: if skill barriers now fall as capabilities rise, can defenders scale detection, credential hygiene and legal oversight fast enough to blunt campaigns that can run at thousands of exchanges per day and convert one stolen token into full control within hours? Read Anthropic’s full write-up via the original CyberScoop story linked below.

Original story on CyberScoop