From ZeroHedge: Anthropic Says Russian, Chinese Threat Actors Used Its AI Model Claude For Malicious Activity
Anthropic Detects Malicious Use of Claude AI by State-Linked Groups
Anthropic, a leading artificial intelligence company, announced on September 10th that it has successfully disrupted various malicious campaigns utilizing its AI model, Claude. These operations reportedly involved threat actors linked to China and Russia.
According to Anthropic’s report, the groups responsible for these activities include suspected state-sponsored entities, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals.
Advanced AI Exploitation
The company’s findings indicate that most cyber operations detected between December 2025 and August 2026 leveraged AI for direct execution or orchestration. While AI played a significant role, human involvement remained crucial for target selection and reviewing data exfiltration.
“The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration,” Anthropic stated.
Among the named threat actors was a group associated with Russia-based Midnight Blizzard. Anthropic alleged this group used AI to target military intelligence entities in Ukraine and Europe, as well as diplomatic and defense organizations and individuals connected to U.S. foreign policy.
Chinese Distillation Attacks and Data Exploitation
Anthropic also reported disrupting “distillation attacks” against Claude originating from seven Chinese labs, with alleged links to major companies like Alibaba, DeepSeek, Xiaomi, and Moonshot.
Distillation was defined by Anthropic as “an industrial-scale, covert campaign” designed to illegally extract an AI model’s capabilities and replicate them in another model. Operators linked to Alibaba, China’s largest e-commerce platform, conducted the most significant distillation attack to enhance the reasoning capabilities of Alibaba’s own models. This involved over 151 million exchanges between May and July 2026, peaking at nearly 3 million exchanges daily from more than 3,500 fraudulent accounts.
Furthermore, Chinese AI company Moonshot was accused of secretly forwarding customer requests to Claude and presenting the resulting responses to its users as if they were generated by its own AI model, Kimi. In one instance, Moonshot allegedly rerouted almost 300,000 customer requests to Anthropic’s model over a 10-day period, utilizing a proxy service network of 5,380 fraudulent accounts, predominantly located in Singapore and Japan.
“Our investigation also revealed that user queries that Moonshot rerouted to Claude included sensitive information about various Moonshot customers,” Anthropic disclosed. “We do not know if Moonshot notified their customers that their requests were being rerouted to Anthropic and exposed to a third party.”
AI Misuse for Weapons Development
The report also highlighted new categories of threat actors misusing Claude, including those seeking to develop “software for conventional weapons, including firearms, missiles, armed drones, bombs, and other munitions.”
- Anthropic disrupted a “guided weapons engineering cell” in northern Yemen that used Claude to develop guidance, navigation, and control (GNC) software for flying vehicles. These actors allegedly test-fired a guided rocket that failed, prompting them to seek Claude’s guidance to diagnose the issue.
- A China-based threat actor utilized Claude to advance three parallel projects on “an anti-torpedo weapons system.”
- Alleged Russia-based freelance threat actors sought to build a “full-stack autonomous first-person-view kamikaze drone swarm.”
- Another Russia-based actor used Claude to research and draft procurement documents for goods likely intended for the Russian government and defense industry.
Anthropic affirmed its commitment to strengthening safeguards and collaborating with partners to prevent further misuse of its AI model. The company stated that in each detected instance, they disrupted the activity, used the intelligence to enhance their defenses, and shared findings with authorities and industry partners where appropriate.
Source: ZeroHedge
