The Pulse
Anthropic details autonomous cyberattacks and Claude distillation
Anthropic’s September 2026 report describes AI-assisted cyber operations, autonomous attack workflows and illicit efforts to extract Claude’s capabilities. No named-person quotation appears in the report; the page was checked for attributab

AI.info Team ·
Claude moves from assistant to attack orchestrator
Anthropic says threat actors used Claude in cyber operations between December 2025 and August 2026. The company’s September 2026 threat intelligence report describes suspected state-sponsored groups, financially motivated criminals and politically motivated individuals using Claude for reconnaissance, vulnerability research, phishing, malware development, exploitation and data exfiltration.
Many of the operations went beyond ordinary chatbot assistance. Anthropic says multi-agent frameworks handled reconnaissance, exploitation and data theft, while human operators remained involved in setting targets and reviewing exfiltrated material. The company says it disrupted the activity, strengthened its safeguards and shared intelligence with authorities and industry partners where appropriate.
The report covers seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and illicit distillation. Claude Haiku, Sonnet and Opus models were used in the cases described. Anthropic says no malicious cyber activity involved Claude Fable or Mythos, although one illicit-distillation case involved a Fable-class model.
AI-assisted campaigns target dozens of organizations
One operation, tracked as GTG-10007, involved Chinese-speaking operators likely residing in Changsha, in China’s Hunan province. Anthropic says two operators were identified as undergraduate students at a Chinese university in Hunan. The group used Claude as the engineering and orchestration layer for intrusion attempts, reconnaissance of foreign-government networks, vulnerability research against security products, malware development and intelligence collection.
The actors targeted roughly 50 organizations across education, retail, energy, technology, health care, finance and manufacturing, as well as government agencies. Anthropic says they compromised an education-technology company and extracted hundreds of megabytes of student data from cloud storage. They also reached the production systems of a retail company and retrieved citizen records, including names, phone numbers and home addresses, from a Southeast Asian government agency.
The operation maintained parallel workstreams with shared tooling, infrastructure and persistent campaign records. Anthropic says some collection and vulnerability-research capabilities continued operating while the operators were away, preserving context between sessions.
Exploit research becomes an automated pipeline
Anthropic describes multiple automated exploit foundries built around persistent AI workflows. In the GTG-10007 case, agents loaded firmware and software binaries into decompilers, traced references through thousands of calls, formed vulnerability hypotheses and produced exploit code for testing against laboratory copies of target products.
One workflow focused on network and security appliances and yielded more than a dozen possible zero-day findings in a single month. The report says the findings were validated in the actors’ own lab, while related workflows produced working exploits for several families of network and security appliances. The same actors conducted exploitation attempts against appliances owned by government organizations.
A separate campaign, GTG-20006, was associated with Russian-speaking operators and linked by Anthropic to public reporting about Midnight Blizzard. The group targeted military intelligence organizations in Ukraine and Europe, diplomatic and defense bodies, and people connected to U.S. foreign policy. Anthropic says more than 20 organizations appeared in the group’s operational planning, reconnaissance or live operations.
GTG-20006 used AI-driven workflows across development, infrastructure acquisition, phishing, persistence and data exfiltration. The actors also monitored whether their malware was detected. When security products identified a tool, AI agents modified and rebuilt it, repeating the process until the malware evaded the existing detections.
Distillation campaigns target Claude
Anthropic says it has identified and disrupted illicit distillation campaigns involving seven China-based laboratories since its first disclosure in February 2026. The campaigns targeted generally available models. Anthropic says it has not observed attempts against Mythos 5 or Mythos Preview, which are not publicly accessible.
Distillation is a legitimate training method in which a smaller model learns from the outputs of a more capable model. Anthropic defines illicit distillation as an industrial-scale, covert effort to extract and reproduce a model’s capabilities without authorization. The company says such campaigns often use fraudulent accounts, stolen payment cards, compromised credentials and API keys.
Anthropic says the campaigns sought capabilities in agent use and tool use, coding, data analysis and logical reasoning. Its research found that a model distilled from a frontier model can develop dangerous capabilities in cyber or biological domains even when the harvested exchanges contain little material directly related to those subjects. Safety protections applied to Claude do not automatically transfer to an unauthorized model trained on Claude’s outputs.
Zhipu, Xiaomi and other labs
Anthropic attributes more than 3 million exchanges over a 17-day period in June and July 2026 to Zhipu, which operates internationally under the name Z.ai. The company says Zhipu rotated through 273 fraudulent accounts to extract reasoning traces from Claude and recorded more than 770,000 exchanges through a cleaning pipeline. Zhipu also used Claude to judge model outputs, normalize reasoning transcripts, filter training data, write tasks, provide solutions and implement tests.
Anthropic separately attributes more than 12.1 million exchanges over 14 days in July to a campaign involving DeepSeek. The company says some relayed requests included live credentials for a Russian government database and material related to a Chinese police surveillance system.
Anthropic says Xiaomi replayed user conversations and coding sessions from its MiMo models to Claude. More than 400,000 requests passed through more than 1,500 accounts during March and April 2026. The relayed traffic included names, contact information, corporate data and other sensitive information from hundreds of Xiaomi users in at least a dozen languages. Anthropic says it has no indication that U.S. persons’ data was exposed.
The report also describes a secondary market in which proxy services provide access to restricted models while saving user exchanges for resale. Anthropic says SenseTime obtained Claude transcripts from third-party data vendors, while MiniMax built a shell-company proxy service that offered access to Anthropic and OpenAI models but not Chinese models. The company says it uses metadata, irregular-activity signals and organization-level attribution to identify coordinated campaigns and take enforcement action.