An official threat intelligence report published by Anthropic AI security researchers reveals that state-backed entities and criminal organizations in Russia and China are deploying AI to automate multi-stage cyberattacks. Over an eight-month monitoring window, the safety team disrupted malicious activity targeting its Claude platform, which spanned illicit model capabilities extraction by Chinese tech firms, state-sponsored cyber espionage campaigns linked to Russia, and weapons development software operations across several countries.
According to Jacob Klein, head of threat intelligence at Anthropic AI security operations, significant model advancements over the past year have heightened operational risks. Rather than using artificial intelligence merely to generate simple code snippets or text, sophisticated operators are leveraging multi-agent systems that autonomously execute complex, end-to-end technical workflows.
Model Distillation Attacks and Data Extraction by Chinese Firms
Anthropic AI security analysis identified attempts by seven China-based organizations to illicitly extract capability data from Claude to augment their own native models. Tech conglomerate Alibaba conducted the largest “illicit distillation” scheme, routing more than 151 million unauthorized exchanges through over 3,500 fraudulent accounts between May and July 2026 to enhance its Qwen model series.
Additionally, Chinese AI developers Moonshot and DeepSeek circumvented standard training methodologies by routing live customer chat queries through Claude in real time. This allowed the firms to harvest Claude’s generated outputs as training data to refine their own platforms, exposing sensitive user information in the process. Misuse was also detected from consumer technology firm Xiaomi.

Russian State Cyber Espionage and Automated Defense Evasion
The Anthropic AI security findings documented malicious operations executed by Midnight Blizzard, a threat actor tied by U.S. officials to Russia’s Foreign Intelligence Service (SVR). The group utilized Anthropic’s systems across multiple stages of offensive cyber operations targeting Ukrainian government, military, and diplomatic entities.
To bypass endpoint protection, Midnight Blizzard deployed Claude to build automated monitoring systems. These tools detected when malicious payloads were flagged by security software and autonomously rewritten until the code evaded detection systems. Separately, Anthropic disrupted activity tied to the ShinyHunters cybercrime syndicate, alongside actors attempting to write software for conventional weapons, missile targeting systems, and military procurement in China, Russia, and Yemen.

