Garp Independent AI & technology journalism
Sunday, September 27, 2026 Sign In · Join Subscribe
Latest Don’t be fooled by this summer of AI hype 

AI news, research, models, robotics, chips, startups, and infrastructure coverage.

Updated daily

Home  /  AI News  /  How hackers used Claude for missiles, drone swarms, and surveillance, while Chinese labs mined it for training data

AI News

How hackers used Claude for missiles, drone swarms, and surveillance, while Chinese labs mined it for training data

How hackers used Claude for missiles, drone swarms, and surveillance, while Chinese…

Anthropic’s new threat report documents eight months of Claude abuse: espionage, nationwide surveillance, weapons software, and distillation by Chinese AI labs. Anthropic’s threat intelligence report covers December 2025 through August 2026 and breaks misuse into seven categories: cyber operations, influence operations, surveillance, fraud, biological misuse, conventional weapons, and unauthorized model distillation.

The models most affected were Haiku, Sonnet, and Opus, while the newer Fable and Mythos models showed up in only a single distillation case. Anthropic says it documents novel misuse rather than the typical kind.Ad The core finding from the cyber chapter is that sophisticated attacks no longer require sophisticated attackers, and sophistication is no longer a reliable signal for attribution. The techniques themselves are familiar, including stolen credentials, unpatched devices, SQL injection, and phishing. What changed is the economics, since reconnaissance, exploitation, and tool-building now get handed off to models that run in parallel at machine speed.Ad Autonomy lowers the cost side of an attacker’s math, Anthropic says, and makes previously unprofitable targets worth pursuing. Malware that rebuilds itself when antivirus tools catch it Anthropic tracks a Russian-speaking espionage actor as GTG-20006 that used a feedback loop. AI agents kept checking whether the malware in play was being flagged by common security products, and when an antivirus tool caught it, the agents rewrote and recompiled the malicious code on their own until it slipped past detection again.Ad That shifts the burden back onto defenders, Anthropic says, because writing new detection signatures no longer slows an attacker down if that attacker cycles through changes faster than new signatures can be rolled out. More than 20 organizations were targeted, including government ministries, intelligence services, embassies, and defense contractors, with a focus on Ukraine and Europe. The drone supply chain came up repeatedly, and the actor stole a complete proprietary SDK for a drone vision system, among other things. Access sometimes ran through third parties, such as compromised hotel guest Wi-Fi providers whose guest devices were then loaded with malware, a method Microsoft described in July 2026 as CaptiveCrunch.Ad For clusters Anthropic attributes to the ShinyHunters collective (GTG-50014), industrial credential mining was the focus. One hacker downloaded 1.8 million Android apps, decompiled them, and searched for hardcoded secrets. Anthropic describes the approach as “vibe hacking,” where a human sets a rough goal and the model assesses the environment and iterates until the task is done. One of the hackers said he collected HackerOne bounties on top of extorting two companies.Ad Chinese labs route their own customers’ requests to Claude On distillation, Anthropic identified attacks from seven more Chinese labs since its first disclosure in February. Distillation as a training method is legitimate, but Anthropic defines the illegitimate version as industrial-scale, covert campaigns that extract model capabilities without authorization, usually enabled by networks of fake accounts using stolen credit cards and API keys, routed through what it calls “transfer stations.”