Anthropic said on Thursday that it had disrupted several allegedly malicious uses of its Claude artificial intelligence models over the past eight months, including a suspected Russia-linked cyber-espionage campaign and efforts by Chinese technology companies to extract and replicate Claude’s capabilities.
In its latest Threat Intelligence report, Anthropic warned that cybercriminals and state-backed hackers were increasingly using artificial intelligence not simply to assist with individual tasks, but to orchestrate and execute substantial portions of cyberattacks. Human operators, the company said, were increasingly acting as overseers rather than carrying out attacks themselves.
“The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing” tasks, Anthropic said.
The company said it had disrupted activity involving seven China-based laboratories during the period covered by its report. Among those named were technology giant Alibaba, Moonshot, DeepSeek and Xiaomi.
Anthropic described an operation attributed to Alibaba as the largest “illicit distillation” attack it had observed. The company alleged that operators linked to Alibaba sought to extract capabilities from Claude and use the resulting data to improve Alibaba’s Qwen models. Alibaba did not immediately respond to a request for comment.
According to Anthropic, it observed more than 151 million exchanges that it attributed to Alibaba between May and July 2026. Activity peaked at almost three million exchanges a day and involved more than 3,500 accounts that Anthropic described as fraudulent.
Distillation is a technique in which outputs from larger and more expensive AI models are used to train smaller models, potentially reducing the cost and effort required to develop new AI systems.
Anthropic also accused Moonshot, the company behind the Kimi chatbot, and DeepSeek of using Claude in a different way. Rather than submitting large numbers of conventional queries, operators allegedly routed live customer conversations through Claude and used its responses as training data. Some of those conversations, Anthropic said, contained sensitive information.
The report also identified a suspected Russian-linked cyber-espionage operation. A hacking group whose methods were consistent with the Russia-based threat actor known as Midnight Blizzard allegedly targeted Ukrainian government, military and diplomatic organisations through phishing, hotel Wi-Fi hijacking and WhatsApp account takeovers.
Anthropic said artificial intelligence was used at almost every stage of the operation. The group allegedly developed a system capable of detecting when its malware had been identified by security systems and automatically rewriting the code until it could evade detection.
The US government has previously linked Midnight Blizzard, a tracking name coined by Microsoft, to Russia’s SVR foreign intelligence service. The Russian Embassy in Washington did not immediately respond to a request for comment.
Anthropic said its investigation had also uncovered what it described as “new categories of threat actors” misusing Claude. These included operators using the platform to develop software for conventional weapons, including firearms, missiles, armed drones, bombs and other munitions, as well as systems used to target and control them.
The report detailed cases in China, Russia and Yemen in which Claude was allegedly used to develop software associated with weapons design and development, or to support intelligence gathering and procurement linked to weapons programmes.
The company also said it had detected and disrupted activity associated with affiliates of the ShinyHunters cybercrime collective, which Anthropic described as one of the most prolific cybercrime enterprises involved in recent attacks against major corporations.
Jacob Klein, Anthropic’s head of threat intelligence, said the growing capabilities of AI models were creating new risks because systems were becoming increasingly capable of performing specialised technical tasks.
“A year ago, let’s say you wanted to optimize a drone or optimize the software on a missile, the models just wouldn’t be as good at that task as they are now,” he said.
Anthropic’s findings point to a widening gap between the original conception of generative AI as a tool for assisting human users and its emerging role in automated cyber operations. As models become capable of coordinating multiple tasks with limited human intervention, the company argues, the potential for their misuse is expanding alongside their capabilities.

