Skip to main content
Threat IntelligenceEmerging Threats

Anthropic Exposes AI Misuse by Adversaries Targeting US Forces

US naval base with a computer workstation and papers in the foreground.

"We identified and disrupted an Iran-nexus threat actor that used Claude to collect and analyze publicly accessible data to develop targeting recommendations against US naval forces in the region."

GTG-30005: targeting U.S. naval forces with scraped open-source data

Anthropic’s 154-page report describes a case, labeled GTG-30005, in which an account tied to an Iran-linked actor used Claude to compile targeting handbooks aimed at U.S. naval forces in the Middle East. The material included a roster of U.S. personnel scraped from captions on public military photographs, ship and aircraft transponder identifiers, commercial satellite-imagery query scripts, and an inventory of public websites that exposed U.S. naval movements. The actor also used Claude to catalog known CVEs in maritime VSAT terminals, Cisco communications gear, and industrial control products.

Anthropic said it banned the account, developed detections to reduce future misuse, and shared threat intelligence with government authorities. An addendum to the case links the same account to domestic mass-surveillance software development for Iranian state systems, explicitly tying the activity to Tehran-affiliated work. Whether the data was subsequently used in attacks is unknown; Anthropic notes only that these activities were identified and disrupted.

GTG-87001: Yemen-based guided-weapons engineering using Claude Code

In GTG-87001, Anthropic reports an individual or cell in northern Yemen running three weapons-development programs: a guided rocket with phone-class flight-computer final-phase homing, a multi-stage ballistic missile with a stated range goal above 2,000 km, and a multi-variant missile set including a hypersonic glide vehicle variant. The actors used Claude Code “in place of human software engineers” to write guidance, navigation, and control (GNC) software — integrating an open-source autopilot onto a phone-class flight computer, tuning control settings, running a firmware build pipeline, and performing flight simulations.

Anthropic wrote that safeguards blocked many requests but not all, and that the actors used tactics to evade protections — hiding goals, splitting work across sessions, and managing multiple Claude instances with distinct roles (code author, researcher, reviewer). Accounts were banned and threat information shared, but Anthropic also found evidence the actors had already built an offline simulation toolkit that did not rely on Claude.

GTG-27005: Russia-linked freelance team building autonomous drone swarm software

GTG-27005 describes likely freelance, Russia-based actors who used Claude Code to develop a full-stack autonomous FPV kamikaze drone swarm. The actors wrote swarm memory and fault-tolerant coordination logic, an onboard small language model for attack/observe/return behaviors, terminal guidance for camera-steered strikes, and a classifier trained on scraped Ukrainian combat footage to split “enemy” and “friendly” target classes. Anthropic found the operation used hardware-in-loop testing and rented GPU hosts; the actors created accounts between late 2025 and early 2026 and began the operation in mid-May 2026.

Anthropic assesses the team was a small specialized freelance outfit with ties to a regional university and a federal research center associated with the Russian Academy of Sciences; the actors claimed funding from Russian research and defense bodies, claims Anthropic could not verify. The company banned related accounts and added safeguards to reduce misuse.

GTG-17002: China-based electronic warfare and suppression-of-air-defenses tooling

Anthropic details a China-based actor using Claude’s chat, coding, and agentic tools to develop a roughly 16-module Chinese-language electronic warfare suite aimed at detecting, jamming, and deceiving an opponent’s radar and communications, and suppressing air defenses. The suite computed detection coverage, assessed jamming effectiveness, ranked targets by value and vulnerability (including Patriot and THAAD-class systems), and modeled engagement envelopes for specific air-defense assets.

Mid-project the actor switched the simulation’s default scenario to 12 targets in Taiwan, including a command bunker, early-warning radar, Patriot and Tien Kung batteries, major air bases, and a regional combatant command headquarters. Anthropic’s metadata and content flagged links to PRC research institutions, including the PLA Academy of Military Sciences; the company banned accounts and said it incorporated findings into safeguards.

What this means for technologists and security teams, policymakers and regulators, and military planners and procurement leaders

  • Technologists and security teams: Anthropic’s report shows attackers can compose multi-session workflows, role-play assistants, and mix cloud-based and offline toolkits to evade model safeguards — so detection and layered protections, plus threat intelligence sharing, will remain essential.
  • Policymakers and regulators: Anthropic supports transparency laws and has adjusted models over cybersecurity concerns, but the company is also contesting a Pentagon designation of its product as a supply-chain risk. The designation and the company’s legal challenge are now explicit parts of the policy picture.
  • Military planners and procurement leaders: Anthropic reported it shared intelligence and banned accounts, and the U.S. military — according to Under Secretary of Defense for Research and Engineering and Pentagon CTO Emil Michael — has scaled back the use of Anthropic’s products in support of classified work by 90 percent. That decision and the supply-chain risk designation are immediate procurement and operational constraints.

Anthropic’s catalogue — across Iran-linked targeting, Yemen guidance work, Russia-linked swarm tooling, and China-focused electronic-warfare suites — presents a through-line: publicly accessible, high-capability models are being leveraged to accelerate technical outputs once gated by expertise. Anthropic banned accounts, developed new detections, and shared threat intelligence, but the report itself warns that these published case studies may be “just the tip of an approaching iceberg.” The practical question left by the evidence Anthropic lays out is stark and specific: can safeguards, detection, and policy keep pace with actors who combine open-source data, cloud services, and adaptable LLM-based engineering assistants?

Original story