Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

anthropiccybersecuritydive+1anthropicState-linked hackers and cybercriminal organizations are moving beyond simple AI experimentation and building autonomous, agentic systems capable of scanning targets, exploiting vulnerabilities, and exfiltrating data with minimal human oversight, according to a pair of threat intelligence reports released this week by Google Alphabet Inc. and Anthropic.
Google Threat Intelligence Group's Q3 2026 AI Threat Tracker, published on September 8, documents a shift from basic prompting to operationalized multi-agent AI frameworks across a range of adversaries. "At this point, we can assume that all threat actors are using AI in some capacity, and their operations have benefited," said John Hultquist, GTIG's chief analyst.cybersecuritydive+1
The Google report details several campaigns where AI was woven into the full attack life cycle. A China-nexus espionage group built an AI-assisted exploitation pipeline using a tool called CC Switch to operate multiple large language models — including Claude, Gemini, and Codex — to create custom exploit scripts and spear-phishing lures. A separate China-nexus group tracked as Basin Castle queried LLMs to profile high-value targets and write custom malware, while an Iran-nexus group tracked as Calanque Ion used generative AI for reconnaissance, social engineering, and software reverse-engineering.cybersecuritydive
Google also warned of coordinated model-distillation campaigns, with some exceeding 100 million prompts, targeting its AI models in an attempt to extract reasoning capabilities and chain-of-thought processes.cybersecuritydive
Anthropic's own threat intelligence report, released on September 10, offered a complementary and more granular view. The company disclosed that it identified and disrupted operations by suspected state-sponsored groups, financially motivated criminals, and hacktivists who misused Claude between December 2025 and August 2026.anthropic+1
Among the most detailed cases was GTG-20006, an actor Anthropic linked to Russia's Midnight Blizzard, which used Claude to automate phishing infrastructure, malware retooling, and data exfiltration targeting Ukrainian government and military drone technology providers. The actor's AI-driven workflow could autonomously rebuild detected malware until it evaded security products. Anthropic also disrupted affiliates of the ShinyHunters collective, one of whom mass-downloaded 1.8 million Android APKs to harvest hardcoded credentials and used stolen AI API keys to power further intrusions.anthropic
Microsoft added to the week's disclosures with a September 10 blog post documenting campaigns that impersonate AI brands — including ChatGPT, Copilot, DeepSeek, and Claude — to deliver phishing kits and malware, with one ChatGPT-themed campaign sending up to 100,000 emails in a single day.microsoft
The collective findings point to a structural shift. Anthropic concluded that AI "has inverted the cost back onto defenders," enabling adversaries to bypass detections faster than security teams can deploy them. As Hultquist warned, the challenge will deepen "as it is applied agentically, creating a scaled, faster adversary".anthropic+1