Threat Intel
6 items across 1 edition. First seen Fri 11 Sep, last seen Fri 11 Sep.
- Anthropic's September threat intelligence report, published 10 September, says the group it tracks as GTG-20006 — which The Record identifies as Midnight Blizzard, also known as APT29 and Cozy Bear, attributed to Russia's SVR — used Claude against more than 20 government, intelligence, diplomatic and defence organisations between December 2025 and August 2026.
- Reported tradecraft includes compromising hotel Wi-Fi providers and manipulating DNS records to redirect travellers to attacker infrastructure, targeting Ukrainian government, military and diplomatic personnel, and using Claude to reverse-engineer a drone vision system — recovering, per The Record, its product architecture, hardware bill of materials, supplier dependencies and details of an unannounced product.
- Anthropic also reports Claude being used to modify tooling once security products detected it, which it frames as AI inverting cost back onto defenders. The Record notes Microsoft links the activity to Storm-2945, a Midnight Blizzard sub-cluster — independent corroboration of the actor, though not of Anthropic's account of how Claude was used.
- The report is Anthropic's own account of activity on its own platform. Neither the victim organisations nor the outcome of the intrusions are independently verified here.
- The cluster Anthropic tracks as GTG-10007 "targeted roughly fifty organizations, spanning education, retail, energy, technology, healthcare, finance, manufacturing, as well as multiple government agencies globally." Automated vulnerability research against network appliances "yielded more than a dozen possible zero day findings in a single month."
- Anthropic identifies two operators as undergraduate students at a university in Hunan province, in its School of Computer & Communication Engineering, one of whom had previously interned at the security firm Sangfor. The operation used agent swarms, with a lead agent decomposing reconnaissance and post-exploitation work across many parallel subagents.
- The significance is the operator profile rather than the target count: this is industrial-scale vulnerability discovery run by students, which is the concrete form of the report's broader claim that "sophisticated attacks no longer require sophisticated attackers."
- Anthropic describes the zero-day findings as "possible" — the report does not say how many were confirmed, disclosed or exploited, and does not name the affected appliance vendors.
- GTG-54002, which Anthropic attributes to a France-based firm it calls LKM Company, ran "approximately 70 fabricated news websites," 70 matching X/Twitter accounts and more than 250 inauthentic commenting accounts, and "published at least 8,913 articles in about 20 languages" across six continents, with the United States, Brazil, France and the Democratic Republic of Congo among the targets.
- A separate cluster, GTG-84005, attributed to Istanbul-based BBS Bilisim Teknolojileri, managed "roughly a thousand fake X/Twitter social media accounts" and profiled voters across "all 222 Malaysian parliamentary constituencies" using census and electoral data, exploiting race, religion and royalty as wedge issues.
- What is new here is the business model: manipulation sold as a commercial service to clients, rather than run in-house by a state. Anthropic rates both operations Category Two on the Breakout Scale — meaning no measured spread beyond the operations' own platforms — so reach should not be inferred from article counts.
- The article and account totals are Anthropic's counts of activity on its platform, not an independent audit of the networks.
- Anthropic's report describes five cases over eight months in which accounts were banned for biology requests that could have supported biological weapons development. One involved drafting a grant application for repeatedly mutating chikungunya virus to raise infectivity in live animals at a military institute; another sought to make avian influenza more damaging to mammals, and received only clerical help from Anthropic's weakest model class.
- In each case, Anthropic says it suspected the researchers were affiliated with a government or military in a banned country, or had taken deliberate steps to conceal their location and identity, or both. Biological misuse is described in the report as "one of the most serious risks of frontier AI models."
- Anthropic is explicit that it found no concrete instance of a scientist attempting to use Claude for nefarious purposes, that the work may have been legitimate, and that it "erred on the side of caution" in shutting the accounts. These are bans on suspicion, not confirmed weapons attempts.
- Watch whether other labs publish comparable case counts. Without them there is no baseline for whether five cases in eight months is high, low, or simply what detection currently catches.
- TechCrunch, reporting figures from Anthropic's 10 September threat report, says accounts linked to Alibaba generated 151 million Claude exchanges between May and July 2026 across about 3,500 accounts, and that Moonshot AI accounted for roughly 300,000 requests over ten days across 5,000 accounts — part of around 200 million exchanges across five campaigns. Extraction techniques included framing requests as translation tasks to surface chain-of-thought reasoning.
- The joint CISA, NSA and FBI bulletin AA26-251A, published 8 September, names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as conducting "aggressive, malicious, and targeted distillation activities at an industrial scale" against Claude, GPT, Gemini and Grok since late 2024, extracting "billions of tokens across millions of exchanges/requests."
- The agencies' recommended countermeasures are unusually specific, and include monitoring subscription-to-usage ratios and enterprise-scale throughput from new accounts, and subtly altering responses to suspected distillation attempts to reduce the payoff to the attacker.
- The named companies' responses are not documented in the reporting reviewed here. Distillation of a competitor's outputs is a terms-of-service question rather than a settled legal one, and neither document alleges a criminal charge.
- Microsoft reported on 10 September a business email compromise campaign that sent more than 1 million phishing emails between 3 and 5 August, with 87.7% directed at users in the United States, targeting IT services, business advisory and consumer goods firms. Messages impersonated executives and requested ACH payments of nearly $50,000 per target.
- Microsoft attributes AI assistance to the template construction rather than to the sending infrastructure, citing extensive HTML comments, structured section labelling, verbose descriptive comments, em dashes, banner formatting and highly uniform templates whose invoice identifiers stayed constant while organisation details changed per target.
- Named indicators include the ServiceNow-impersonating domain service-nowinc[.]com and domainlify[.]net in reply-to addresses. Recommended mitigations are automatic attack disruption in Defender XDR, Zero-hour Auto Purge, and correctly configured SPF, DKIM and DMARC.
- Microsoft does not name a threat actor, and the AI evidence is stylistic inference from artefacts left in the templates rather than direct observation of a model in use. No losses are quantified.