US artificial intelligence firm Anthropic released a threat intelligence report detailing dozens of state-linked cyber intrusions, automated weapons design efforts, and covert influence operations that used its flagship model, Claude.
"Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity," the San Francisco-based company said Thursday, asserting that it intervened against unauthorized actors between December and August.
The document outlines activity across seven primary harm categories: cyber operations, foreign influence campaigns, surveillance architectures, fraud, biological misuse, conventional arms development, and model distillation, the unauthorized extraction of an AI system's underlying reasoning by rival developers.
The company said that it dismantled the offending accounts, upgraded internal safety filters, and shared intelligence with government authorities and industry peers where appropriate.
Anthropic claimed foreign intelligence services used multi-agent frameworks to orchestrate cyber espionage and automate offensive operations. A Russian state-linked actor, identified in the report as consistent with the espionage group Midnight Blizzard, allegedly used Claude to target military and diplomatic networks across Ukraine, Europe, and the US.
According to the report, the Russian group deployed automated agents that reverse-engineered proprietary software development kits for military drone vision systems and extracted entire mailboxes from two drone component manufacturers. The company asserted that the operators built autonomous feedback loops.
"If their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections," it said.
The same actor reportedly breached a North African government technology authority, stealing credentials that compromised more than 300,000 national identity records and corporate registry files for more than half a million businesses.
In another case, Anthropic alleged that Chinese-speaking operators linked to regional security research firms and computer engineering students in Hunan province established an autonomous "exploit foundry".
The group reportedly utilized parallel AI swarms to disassemble firmware from commercial network appliances without human intervention, identifying more than a dozen potential zero-day vulnerabilities, undisclosed software security flaws, in a single month.
The firm claimed the cluster also maintained a fleet of 13 automated collection agents to ingest content from target websites, including publicly accessible US military and government contract postings.
Anthropic documented several instances where threat actors allegedly applied its coding and reasoning tools to kinetic weapons programs. In northern Yemen, the company claimed to have disrupted a technical cell that used Claude Code to design guidance, navigation, and control software across three missile initiatives.
The Yemeni projects reportedly included a tactical guided rocket powered by a smartphone-grade flight computer, a multi-stage ballistic missile with an intended range exceeding 2,000 kilometers (1,242 miles), and an advanced variant known as the "R2000" designed to carry a hypersonic glide vehicle.
Anthropic did not publicly identify the group behind the activities. However, media reports have linked them to Yemen’s Houthis, which controls large parts of northern Yemen.
The company noted that after a test-fire of the tactical guided rocket failed, the operators returned to the model within hours to analyze and diagnose the malfunction. The company acknowledged that the cell had already constructed an offline simulation toolkit that functioned independently of the Claude environment. It did not specify which actor in the country was responsible for this usage.
In Russia, Anthropic uncovered an effort by freelance developers linked to a regional university and a federal research center associated with the Russian Academy of Sciences to engineer Serafim, also tracked as DronDoc, a full-stack autonomous first-person-view (FPV) kamikaze drone swarm.
The actors used Claude Code to build coordination logic and onboard small language models designed for autonomous lethal engagement, enabling the drones to identify an explicit "person" target class and issue detonation commands without human intervention. The system's computer vision was trained on scraped Ukrainian combat footage and validated in simulation using strike coordinates in the eastern Donetsk region.
The report also pointed to military applications in Asia, claiming a Chinese researcher linked to the People's Liberation Army (PLA) Academy of Military Sciences built a 16-module electronic warfare suite. The software allegedly calculated radar jamming allocations and modeled engagement envelopes for US-made Patriot and THAAD air defense batteries, eventually configuring a simulation scenario targeting 12 command bunkers, radar sites, and air bases in Taiwan. A separate Chinese defense researcher reportedly used the tool to benchmark domestic anti-torpedo systems against active US Navy undersea warfare programs.
In the Middle East, Anthropic claimed an Iranian threat actor aggregated open-source intelligence to compile targeting handbooks and recommendations against US naval forces. The actor reportedly processed ship transponder signals, commercial satellite imagery, and personnel rosters scraped from public military photographs, while cataloging vulnerabilities in shipboard systems.
The report claimed that state-backed influence networks in Russia, Iran, and the United Arab Emirates integrated Claude into foreign propaganda pipelines. In the Central African Republic, an operative allegedly tied to the Russian Foreign Intelligence Service (SVR) and the Africa Corps network used the model to script pro-Kremlin radio broadcasts for Radio Lengo Songo in Bangui and forge local Defense Ministry documents.
Anthropic further alleged that Russian state-run news organizations, including RT, Sputnik, and RIA Novosti, utilized Claude as an automated sub-editor. These editorial pipelines produced localized propaganda targeting domestic political discourse across Moldova, Latin America, Africa, and global English broadcasts. The pipelines reportedly generated localized news copy, broadcast captions, and defamatory material targeting Moldovan President Maia Sandu ahead of national parliamentary elections in September 2025.
In Iran, state propaganda bodies, including the Islamic Culture and Communications Organization and organs tied to the Islamic Revolutionary Guard Corps (IRGC), allegedly weaponized the model under Tehran's doctrine of "Jihad al-Tabyin," or explanatory jihad.
Anthropic claimed these actors generated statements impersonating IRGC spokespersons and independent voices, compiled profiling databases against political dissidents, drafted contingency funeral plans for the country's Supreme Leader Ali Khamenei — who was killed at the beginning of the US-Israeli war against the country — and fabricated false policy statements attributed to US think tanks such as CSIS, Brookings, and RAND during the ongoing Iran war.
In Africa, Anthropic claimed that an independent technical contractor working for Mali's state intelligence service, the Agence Nationale de la Securite d'Etat, used the model to design "Lakana 360," a nationwide surveillance platform.
The architecture was built to conduct bulk monitoring across 25 million mobile subscribers, capturing voice communications, text messages, and location metadata. Anthropic noted that the developer specifically eliminated court warrant checkpoints from the system module that generated automated intelligence profiles on targeted phone numbers.
The report also uncovered commercial surveillance operations, revealing that Israeli-Singaporean vendor S2T Unlocking Cyberspace used the model to profile social media users across Iran and the Gulf. The platform mapped user locations, classified populations into six demographic categories, generated formal Arabic-language intelligence briefings styled as government reports, and maintained a reserve of more than 255 synthetic personas to infiltrate online communities.
The report highlighted attempts by researchers to exploit the system for dual-use biological work.
Virologists allegedly used commercial intermediaries to conduct gain-of-function research on the chikungunya virus for an overseas military institute, seeking to increase its transmissibility or virulence. Separately, another user explored genetic mutations that could help highly pathogenic avian influenza adapt to mammals and spread through the air.
Furthermore, the company accused Chinese artificial intelligence laboratories, including Moonshot AI and DeepSeek, of executing industrial-scale distillation attacks. These firms allegedly rerouted inbound user prompts to Claude to harvest its chain-of-thought reasoning and train their own architectures.
Anthropic noted that these unauthorized pass-throughs inadvertently exposed sensitive third-party data, including internal closed-circuit television surveillance footage from Chengdu and active database credentials belonging to the Russian Defense Ministry.
While the report detailed extensive foreign exploitation, it omitted any examination of the US military's own integration of Claude onto classified defense networks during recent military engagements.
In July 2025, Anthropic signed a $200 million contract with the Pentagon, making Claude a frontier artificial intelligence model authorized for use on US classified networks through partnerships with data analytics firms such as Palantir. Defense agencies utilized the system to process intelligence data, evaluate logistics, and support operational decision-making.
However, the military partnership collapsed into a public legal clash in early 2026. The original contract barred the Pentagon from utilizing Claude for mass domestic surveillance of American citizens or within fully autonomous weapons systems that select and engage targets without human intervention. In February 2026, the Pentagon demanded that Anthropic lift these restrictions to permit deployment "for all lawful purposes."
Following Anthropic's refusal, US President Donald Trump ordered all federal agencies to phase out the company and US Defense Secretary Pete Hegseth designated Anthropic a "supply chain risk." The designation effectively excluded the company from new defense contracting until a US federal judge struck down the measure.
Despite replacing Claude on classified networks with tools from other technology firms, the Pentagon reportedly continues to employ artificial intelligence across combat commands, including operations connected to the Iran war, which is now in its seventh month.
Anthropic's threat report provided no data regarding whether its models or competing commercial systems were utilized in support of US strikes or naval operations across the Gulf, leaving the full scope of military AI deployment undisclosed.
news_share_descriptionsubscription_contact
