Threat actors are increasingly using Claude-based AI workflows to automate cyberattacks, accelerate data theft, and reduce the technical expertise needed to run complex intrusions.
Anthropic’s report details cyber espionage, financially motivated extortion, supply-chain compromise, and hacktivist activity disrupted between December 2025 and August 2026.
Rather than using an AI chatbot only for occasional coding assistance, the actors deployed multi-agent frameworks that could conduct reconnaissance, identify exposed services, test credentials, create malware, execute commands, harvest data, and stage stolen material for exfiltration.
Threat Actors Use Claude AI Agents to Automate Cyberattacks
Human operators generally retained control of target selection and the review of stolen data, while agents handled repetitive technical tasks at machine speed.
A suspected Russian state-linked espionage cluster, tracked as GTG-20006, reportedly used customized AI-driven workflows throughout its attack chain.

Anthropic said the group targeted Ukrainian and European government entities, diplomatic organizations, defense firms, and military drone supply chains.
The operation allegedly automated infrastructure acquisition, phishing-domain registration, command-and-control monitoring, credential harvesting, lateral movement, and data exfiltration.
The group’s toolkit included Windows implants, browser credential stealers, mobile malware, phishing infrastructure, and administration tools for compromised accounts. Of particular concern, AI agents reportedly monitored whether deployed malware had been detected by security products.
When detections occurred, the workflows modified, rebuilt, and redeployed artifacts until they evaded available controls, a process that could sharply compress defenders’ detection-to-evasion window.
In one campaign, the operators bulk-exported mailboxes belonging to drone-component manufacturers and stole a proprietary drone-vision software development kit.
They then used AI-assisted analysis to reverse engineer the product’s architecture, hardware bill of materials, supplier dependencies, and information about an unannounced product.
The same actor also allegedly stole more than 300,000 national identity records and commercial-registry data for over half a million companies from a North African government technology authority.
Financially motivated actors also used AI to scale opportunistic compromise. Anthropic linked several clusters to suspected ShinyHunters affiliates, which allegedly harvested credentials from Android applications, code repositories, cloud environments, and enterprise systems.
One operator used a fleet of 10 Amazon EC2 workers to download and decompile 1.8 million Android APKs, then scan them for hardcoded secrets.
The actors reportedly stole AI API keys from victim environments and used the keys as both an operational resource and a means of concealment.
Compromised API credentials allowed attackers to run further AI-assisted workloads at the victim’s expense while blending activity with legitimate account usage.
The report also documents an AI-enabled exploit-development operation, GTG-10007, in which Chinese-speaking operators ran persistent agent workflows for vulnerability research, binary analysis, exploit writing, malware development, and foreign-government reconnaissance.
One automated process reportedly generated more than a dozen potential zero-day findings against network appliances in a month by iteratively decompiling firmware, forming vulnerability hypotheses, generating proof-of-concept code, and testing exploits in laboratory environments.
For defenders, the key shift is operational economics. AI does not necessarily introduce entirely new attack techniques; phishing, exposed credentials, unpatched edge devices, insecure APIs, and software vulnerabilities remain common entry points.
But agentic workflows allow adversaries to execute these familiar tactics faster, across more targets, and with fewer operators.
Organizations should treat AI API keys, session tokens, agent integrations, model gateways, and evaluation sandboxes as production-grade secrets.
Security teams should enforce least privilege, rotate exposed keys, monitor abnormal API use, segment AI-connected workloads, and apply detection controls that can identify automated reconnaissance, bulk export activity, and credential abuse.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

