VECTOR WIREAI INTELLIGENCE
UTC
Refresh Models Deals Regulatory Sources

Anthropic disrupts Russian state hackers using Claude to evade malware detection

Anthropic disclosed that state-sponsored and criminal hackers used Claude for cyber attacks, malware evasion, and weapons design, and that attackers…

Anthropic disclosed that cybercriminals and state-sponsored hackers have been using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 20261. The company said it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude to develop an AI-assisted workflow designed to outpace detection efforts2.

Anthropic attributed the Russian operation to a cyber espionage group it designated GTG-20006, using a taxonomy the company has introduced called Generative Threat Groups, or GTGs. The GTG designation spans state-sponsored groups, financially motivated criminals, and commercial entities.

Beyond using Claude as a tool, criminal groups are increasingly targeting AI vendors' own infrastructure, according to Anthropic3. That targeting included an attempt to steal a pre-release Claude model.

ANALYSIS The disclosure marks a notable shift in how a frontier AI lab communicates about adversarial use of its own products: Anthropic is not only reporting misuse but assigning formal threat-group identifiers, borrowing a convention long used by cybersecurity firms to track nation-state actors.

The reported attempt to steal a pre-release model points to a second vector of risk for AI labs, where the labs themselves become targets rather than merely providers of tools that threat actors exploit.