|
||
Anthropic says malicious actors are increasingly using AI not merely to assist cyberattacks, but to orchestrate substantial parts of them—including reconnaissance, exploitation, credential theft, data exfiltration and rebuilding malware when defenses detect it.
The company’s September threat intelligence report, based on activity it disrupted between December 2025 and August 2026, describes operations involving suspected state-backed groups, financially motivated criminals and politically motivated attackers. Anthropic says a majority of the cyber operations it examined involved AI directly executing or orchestrating attack steps, although humans generally continued to choose targets and review results.
The attacks themselves were largely familiar; their economics were changing. Anthropic found actors automating work that previously required teams of skilled operators, including scanning Internet-facing systems, developing exploits, processing stolen data and managing multiple victims in parallel. Some breaches progressed from initial access to extensive data theft within two or three hours, according to the report. Anthropic cautions that the cases are selected examples of notable or novel misuse rather than a representative sample of malicious AI activity.
One case, which Anthropic links to reporting on the Russia-aligned Midnight Blizzard espionage operation, used AI-driven workflows spanning infrastructure acquisition, phishing, persistence and exfiltration. The system also monitored whether security products detected deployed malware and automatically modified and rebuilt affected components until they evaded detection.
DNS infrastructure was part of the attack path. Anthropic says the actor compromised at least three hospitality technology providers and altered DNS records so hotel guest traffic was redirected through attacker-controlled services. Those redirects were used to stage malware delivery and collect information about travelers, with Ukrainian officials and drone-industry personnel among the targets. Microsoft independently documented related activity in July under the name CaptiveCrunch, reporting manipulation of DNS and HTTP traffic on captive-portal networks in several countries and attributing the campaign to a Midnight Blizzard sub-cluster.
AI credentials are themselves becoming attack targets. Anthropic describes criminal groups harvesting exposed API keys and session tokens from code repositories, mobile applications, containers and customer environments, then using those credentials as resale inventory, attack compute and cover for subsequent operations. In one case, an attacker compromised an AI vendor’s evaluation environment, stole production API keys and used the resulting access while probing roughly 30 AI companies over about four days. Anthropic says its own systems were not compromised.
The report also describes autonomous vulnerability-research workflows, including “agent swarms” that operated in parallel and retained campaign state between sessions. Anthropic’s broader conclusion is that attacker sophistication is becoming a less reliable indicator of resources or state backing as AI lowers the labor and expertise required to conduct sustained cyber operations.
Sponsored byVerisign
Sponsored byVerisign
Sponsored byIPv4.Global
Sponsored byDNIB.com
Sponsored byCSC
Sponsored byWhoisXML API
Sponsored byRadix