
Related Threat Actors: GTG-10007, Charcoal Typhoon, Salmon Typhoon, SweetSpecter, Keyhole Panda, Vixen Panda, APT41, Ravine Castle
Executive Summary
Competition between the United States and China for artificial intelligence supremacy is increasingly intersecting with the cyber threat landscape. Anthropic disrupted malicious campaigns using Claude for cyber operations, surveillance, weapons development, influence operations, fraud, biological misuse, and illicit model distillation between December 2025 and August 2026. Combined with previous reporting on PRC-linked and China-based threat actors adopting commercial AI, the findings reveal a broader progression. Frontier AI is becoming an operational capability for cyber and intelligence activity while simultaneously emerging as a strategic technology targeted for acquisition and replication.
Key Takeaways
- AI is moving from assistant to operator. Anthropic observed AI executing or coordinating vulnerability research, exploitation, credential harvesting, malware development, infrastructure management, and data exfiltration. Automated exploit foundries and multi-agent frameworks increasingly allow operations to continue with reduced human involvement.
- PRC-linked and China-based threat actors have steadily expanded their use of commercial AI. Since 2024, OpenAI and Google have documented actors using frontier models for reconnaissance, scripting, vulnerability research, phishing, post-compromise activity, C2 development, data exfiltration, and intelligence processing.
- China is closing the frontier-AI capability gap. Stanford University’s 2026 AI Index found that the performance gap between leading US and Chinese models has effectively closed. The United States maintains substantial advantages in private investment and notable-model production, while China leads in AI publication volume, citations, and patent grants.
- Frontier AI is becoming both an operational capability and a strategic target. Anthropic identified PRC-linked or China-based activity involving surveillance and military applications of Claude while separately attributing industrial-scale attempts to extract its capabilities to seven China-based AI laboratories.
Background
Anthropic’s September 2026 threat intelligence report documents malicious use of Claude observed between December 2025 and August 2026 across cyber operations, surveillance, influence operations, scams and fraud, biological misuse, conventional-weapons development, and illicit model distillation. Although threat actors have used generative AI for years, the report highlights an important change in how the technology is being integrated into malicious operations.
Earlier adoption largely centered on discrete tasks such as writing code, researching vulnerabilities, translating technical material, troubleshooting malware, and creating phishing content. Anthropic now reports actors building automated exploit foundries and autonomous workflows capable of conducting vulnerability and exploit research continuously. Other operations used AI across reconnaissance, exploitation, credential collection, infrastructure management, and data exfiltration.
The resulting change is as much economic as technical. Cyber operations have traditionally been constrained by access to skilled personnel, working exploits, infrastructure, and time. Agentic AI can reduce several of those constraints simultaneously by allowing one operator to delegate parallel technical tasks to automated systems. Humans can retain control over target selection and consequential decisions while AI increasingly performs the work required to execute those decisions.
Anthropic reports that some AI-assisted operations completed breaches within two to three hours and allowed individual operators to handle dozens of victims in parallel. The company also observed agent swarms, persistent campaign memory, and automated workflows capable of maintaining operational continuity across multiple tasks and targets. This capability is also diffusing beyond bespoke systems. Publicly available offensive-agent frameworks can provide scaffolding capable of automating portions of the cyber kill chain. As those frameworks mature, actors may require less custom engineering to assemble sophisticated AI-enabled workflows, potentially shortening the time between advanced experimentation and broader adoption.
AI-Enabled Cyber Operations Scale Across the Attack Lifecycle
One case in Anthropic’s report involved GTG-10007, a sustained espionage operation conducted by Chinese-speaking operators assessed as likely residing in Changsha, Hunan province. Anthropic identified two operators as undergraduate students studying in a School of Computer & Communication Engineering at a Chinese university. The company did not attribute GTG-10007 to the Chinese government.
The operation demonstrated how AI can support parallelized offensive activity. Actors developed skills and workflows that allowed AI systems to conduct vulnerability research and other offensive tasks on an ongoing basis. Rather than treating Claude as a chatbot consulted periodically by an operator, the actors incorporated it into infrastructure designed to perform repeatable operational functions.
Anthropic observed similar automation elsewhere in the cyber portion of the report. One actor developed an AI-assisted workflow that could automatically rebuild and redeploy tooling when security products detected it. The operation used disposable hosting alongside phishing, ClickFix, and DNS hijacking, while AI-enabled workflows researched and registered domains, configured hosting, sent phishing material, and monitored command-and-control (C2) infrastructure. That operation targeted more than 20 organizations, including government ministries, defense and intelligence organizations, embassies and diplomatic missions, think tanks, and defense-industrial companies. Targeting was concentrated in Ukraine and Europe but extended to the Middle East and government maritime organizations in Asia.
Ukraine and its drone supply chain emerged as recurring targets. Anthropic observed scanning against email and remote-access systems belonging to more than two dozen Ukrainian government organizations, bulk export of mailboxes belonging to at least two drone-component manufacturers, and targeting of a military drone manufacturer. In one intrusion, actors stole the complete proprietary software development kit for a drone vision system and subsequently used AI to reverse-engineer its architecture, hardware bill of materials, supplier dependencies, and information concerning an unannounced product. The activity illustrates that AI’s role does not end when access to a victim is obtained. Models can assist with processing and exploiting stolen information, allowing attackers to move more quickly from collection to usable intelligence.
The potential defensive impact is significant. Automated adaptation reduces the value of the time traditionally gained when defenders identify a malicious payload or piece of infrastructure. If an AI-enabled workflow can modify tooling, redeploy infrastructure, and resume an operation quickly following detection, defenders face an adversary whose iteration cycle increasingly approaches machine speed.
China’s Growing Role in the AI Threat Landscape
The expansion of AI-enabled cyber operations is occurring alongside China’s rapid advancement in frontier-model development. Stanford University’s 2026 AI Index concluded that the performance gap between leading US and Chinese models has effectively closed. US and Chinese models have traded positions near the top of performance rankings since early 2025, and as of March 2026 the leading US model held an advantage of only 2.7% over the leading Chinese model.
The United States continues to hold significant structural advantages. US-based institutions produced 59 notable AI models in 2025 compared with 35 from China, while US private AI investment reached approximately $285.9 billion compared with $12.4 billion in China. Stanford cautions that private-investment comparisons likely understate total Chinese AI spending because government guidance funds are not fully represented in those figures.
China nevertheless leads several important measures of AI research output, including publication volume, citations, and patent grants. The result is not a simple picture of Chinese technological dominance or American decline, but an increasingly competitive environment in which the United States retains major advantages in capital and notable-model production while Chinese developers have rapidly approached frontier performance parity.
This technological competition is developing alongside an established pattern of PRC-linked and China-based threat actors adopting commercial AI services for cyber and intelligence operations. Reporting from multiple major AI providers shows that this adoption has progressed considerably since the first publicly disclosed cases.
China’s rapid AI expansion also aligns with Beijing’s current national development strategy. China’s 15th Five-Year Plan for 2026–2030 identifies artificial intelligence as a strategic frontier technology and calls for breakthroughs in foundational AI theory and core technologies, continued advancement of model architectures and algorithms, and development of multimodal AI, autonomous agents, embodied AI, and swarm intelligence while exploring pathways toward artificial general intelligence (AGI). The plan also expands the country’s “AI Plus” initiative, pairing investment in computing power, algorithms, and data infrastructure with broader AI adoption across industry and government. China’s narrowing performance gap with US frontier models, therefore, coincides with an explicit national policy to accelerate both domestic AI capabilities and their deployment across the economy.
PRC-Linked Threat Actors Expand Their Use of AI
OpenAI and Microsoft provided some of the earliest public evidence of Chinese state-affiliated actors experimenting with commercial large language models in February 2024. Charcoal Typhoon used OpenAI services to research companies and cybersecurity tools, debug code, generate scripts, and produce material likely intended for phishing campaigns. Salmon Typhoon used the models to translate technical papers, research intelligence agencies and regional threat actors, assist with coding, and investigate techniques for concealing processes on compromised systems. At the time, these activities largely resembled productivity augmentation. AI helped operators research, translate, troubleshoot, and write relatively basic code, but there was little public evidence that it had fundamentally changed their operational capabilities.
That boundary subsequently expanded. In October 2024, OpenAI disclosed activity associated with SweetSpecter, which it described as a suspected China-based adversary. The actor used OpenAI models for vulnerability research, scripting, debugging, and other support for offensive cyber activity. SweetSpecter also targeted OpenAI employees with spear-phishing messages carrying SugarGh0st RAT, illustrating that an American frontier-AI provider could simultaneously serve as a source of useful capabilities and a target for China-based cyber operators.
By June 2025, OpenAI had identified activity associated with infrastructure linked to Keyhole Panda/APT5 and Vixen Panda/APT15. Operators used ChatGPT for open-source research, reconnaissance, script modification, Linux troubleshooting, software development, and infrastructure configuration. Activity included modifying scripts, troubleshooting systems, automating web reconnaissance, and investigating methods involving authentication bypass and authorization-token capture.
Google observed adoption on a broader scale. Google Threat Intelligence Group reported that more than 20 PRC government-backed groups had attempted to use Gemini. Their activity included target reconnaissance, vulnerability research, scripting and development, technical research, and assistance with post-compromise tasks. Google noted that much of the activity resembled an IT administrator using AI to streamline or troubleshoot technical tasks, except that the same assistance could facilitate lateral movement, privilege escalation, data exfiltration, and detection evasion during malicious operations.
Subsequent reporting showed increasingly structured use. Google observed PRC-backed actors using Gemini for vulnerability analysis, software development, attack planning, and post-compromise support.
APT41, now tracked by Google as SPIRE CASTLE, used Gemini to assist with C++ and Golang development for multiple tools, including an actor-developed command-and-control framework.
By September 2026, Google Threat Intelligence Group described a broader transition from basic prompting toward agentic workflows and AI-enabled automation. RAVINE CASTLE, previously tracked as APT24 and COULEE, used Gemini across distinct operations spanning intelligence gathering, attack-capability development, and influence activity. Google observed the group researching foreign ministries and international organizations, supporting social-engineering efforts, and using AI to translate, summarize, and restructure exfiltrated information into finished intelligence reporting.
The progression is significant. Public reporting shows PRC-linked threat actors moving from using AI predominantly for research, translation, and scripting toward employing it for vulnerability analysis, post-compromise operations, software and infrastructure development, intelligence exploitation, and increasingly automated workflows.
Just as importantly, the activity is not dependent on one provider. Documented PRC-linked or China-based use spans OpenAI models, Google Gemini, and Anthropic Claude. Commercial frontier AI is increasingly functioning as another component of the adversary toolchain.
PRC-Linked Surveillance and Transnational Repression
Anthropic’s September report extends the pattern beyond conventional cyber espionage. The company disrupted China-based activity associated with municipal public and state-security organizations using Claude to support surveillance, intelligence collection, and what the PRC security apparatus calls “stability maintenance.” Targets included domestic petitioners and human-rights defenders, Hong Kong pro-democracy figures, organizers of Tiananmen Square commemorations, Uyghur advocacy organizations, overseas dissidents, and Western human rights institutions. Anthropic reported that the most serious activity included directing Claude to produce pre-operational venue intelligence concerning overseas protests.
One municipal cyber police unit used Claude Code and custom skills to operate a sentiment-monitoring pipeline, query a government surveillance database, and generate daily reporting concerning politically sensitive activity. Anthropic linked associated activity to individuals or organizations aligned with PRC municipal security services, including the tracking of prominent overseas dissidents.
Anthropic separately identified what it assessed as a China-based, PRC government-aligned religious-affairs intelligence operation in which Claude effectively replaced portions of a staffed analyst team. A single operator used the model across concurrent workstreams to ingest multilingual source material and generate standardized Chinese-language dossiers on religious figures and organizations. The company also uncovered a PRC-aligned effort targeting Uyghurs in Syria. An actor without Arabic-language skills used Claude to process information from more than 100 WhatsApp groups and dozens of Telegram channels, identify individuals potentially vulnerable to recruitment, and improve deceptive Arabic-language messaging.
These operations demonstrate another form of AI-driven labor compression. AI can substitute not only for portions of a software-engineering workforce but for portions of the analyst workforce required to translate, triage, profile, and report on large volumes of intelligence information.
Military and Electronic-Warfare Applications
Anthropic identified six cases involving the use of Claude for conventional-weapons development, procurement, or intelligence collection, including three China-based cases. In one case, a China-based actor used Claude to advance work on an anti-torpedo weapons system. Claude helped draft a fire-control specification, produce an extensive technical proposal, benchmark the proposed system against US anti-torpedo and anti-submarine programs, and assist with portions of the fire-control software and testing process. Anthropic assessed that the actor was associated with a Chinese defense-industry manufacturer seeking to develop a weapons specification and acquisition proposal for the People’s Liberation Army Navy, but could not attribute the activity to a specific entity or actor.
A separate China-based defense and military-industrial researcher used Claude to develop approximately 16 software modules for electronic warfare and suppression of enemy air defenses, iterating through 12 versions of the system. The software analyzed radar systems, surface-to-air missile sites, command posts, and communications nodes. It also modeled detection and jamming effectiveness, prioritized targets, and allocated jammer sorties across multi-day campaigns.
During development, the actor changed the simulation’s default scenario to 12 targets in Taiwan. Those targets included a command bunker, early-warning radar, Patriot and Tien Kung air-defense batteries, major air bases, and a regional combatant-command headquarters. Anthropic assessed the actor as a China-based defense and military industrial researcher and identified links to PRC research institutions, including the PLA Academy of Military Sciences.
A third China-based actor used Claude to collect intelligence concerning advanced directed-energy weapons and their supply chains. The actor researched high-power microwave systems, attempted to identify suppliers and components, and generated Chinese-language intelligence products. Anthropic assessed that the activity demonstrated state-grade intelligence tradecraft.
These cases are consistent with independent evidence that Chinese military interest in American frontier AI extends beyond Anthropic’s visibility. A July 2026 Reuters investigation reviewed more than 80 Chinese academic papers and patents, many associated with People’s Liberation Army institutions, and found researchers describing the use of US AI models or distillation techniques for military and security applications including surveillance, cyber warfare, drones, and tactical decision-making.
The significance is broader than whether a frontier model directly designs a weapon. General-purpose AI can accelerate the software development, intelligence analysis, supply-chain research, technical documentation, testing, and procurement work surrounding military programs.
Frontier AI Becomes a Target
China’s use of frontier AI is only one side of the competition. Anthropic also reports that the underlying capabilities of American frontier models have themselves become targets. Since February 2026, Anthropic says it has detected and disrupted additional distillation attacks from seven AI laboratories based in China. The company characterizes the activity as illicit distillation: industrial-scale, covert extraction and replication of model capabilities without authorization, often facilitated through fraudulent accounts and other methods designed to circumvent access controls. Model distillation itself is a legitimate and widely used machine-learning technique in which outputs or capabilities from a more capable model are used to improve another model. The security issue identified by Anthropic is therefore not distillation as a technical practice, but the alleged covert and unauthorized extraction of proprietary frontier-model capabilities.
According to Anthropic, the campaigns targeted valuable capabilities including advanced reasoning, coding and data analysis, agentic tool use, software engineering, and long-horizon task execution. The company argues that illicit distillation can allow competing developers to reproduce portions of those capabilities at a fraction of the time, compute, and cost required to develop them independently.
Industrial-Scale Capability Extraction
Anthropic attributed the largest distillation campaign it has measured to operators affiliated with Alibaba. Between May and July 2026, the company observed more than 151 million exchanges associated with the campaign, with activity reaching nearly three million exchanges per day at peak.
According to Anthropic, operators used large pools of fraudulent accounts supported by proxy infrastructure, disposable identities, and payment mechanisms designed to evade controls. The operation targeted reasoning traces from Opus-class models as well as agentic tasks, software engineering, kernel development, and long-horizon reasoning. Anthropic alleges that the resulting material was used to support training of Alibaba’s Qwen models, while Claude was separately used to assist with reinforcement-learning environments and model-architecture research.
Anthropic attributed additional campaigns to Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime, and MiniMax. The company reported more than 23 million Moonshot-associated exchanges between May and July 2026, more than 12.1 million DeepSeek-associated exchanges during a 14-day period in July, and more than 3.4 million Zhipu-associated exchanges during a 17-day period in June and July. The scale of the alleged activity changes the character of model abuse. These are not isolated developers asking a competing model occasional technical questions; Anthropic describes infrastructure designed to systematically harvest model outputs at industrial scale.
Distillation Creates an Enterprise Data-Security Risk
Anthropic’s investigation also uncovered a potentially serious secondary issue: users may not always know which model is actually processing information submitted to an AI service. Anthropic reports that DeepSeek, Xiaomi, and Moonshot fed conversations involving their own users into Claude and used Claude-generated responses as part of efforts to distill its capabilities. According to Anthropic, some of those exchanges contained names, email addresses, corporate information, authentication credentials, internal documentation, and other sensitive information. The company also observed requests originating from users of third-party model-routing services commonly used in the United States and Europe.
In one case, Anthropic says an employee of a PRC technology company submitted sensitive internal documentation to what the employee believed was DeepSeek. The material was instead relayed to Claude and included specifications, organizational information, and strategic objectives related to a major AI program. Another DeepSeek-relayed session allegedly exposed active credentials associated with a Russian government database used by an organization connected to the Russian Ministry of Defense.
Anthropic also observed engineers developing a case-management system for a Chinese municipal Public Security Bureau submitting requests through DeepSeek that were subsequently relayed to Claude. Moonshot allegedly forwarded requests intended for its Kimi models to Claude while presenting Claude-generated responses to customers as Kimi output. Anthropic states that it does not know whether affected users were informed that their information was being sent to another model provider.
For enterprises, this turns model routing into a security and supply-chain question. An organization may assess the security practices of the AI provider it believes it is using while remaining unaware that sensitive prompts, source code, credentials, proprietary research, internal documentation, or security telemetry are being forwarded through additional models, resellers, or proxy infrastructure.
AI-Enabled Influence and Fraud Operations
China is central to the strategic story, but Anthropic’s broader findings show that AI-driven labor compression is not confined to state-linked cyber activity. Influence operators used Claude to build fake personas, create deceptive media properties, manage social-media infrastructure, and automate portions of campaign administration.
One Malaysia-focused operation managed more than 1,000 fake X accounts using account-warming logic, IP and cookie renewal, and adjustable artificial engagement infrastructure. Anthropic observed a request to generate one million artificial views in support of Malaysia’s sitting prime minister. The operation also used genuine census and electoral information to tailor political content across all 222 Malaysian parliamentary constituencies.
Financially motivated actors demonstrated a similar hybrid model. Anthropic identified fraudulent dating services operating with roughly three AI personas for every human worker. Claude generated approximately 2.36 million messages over a two-week period, while human gig workers handled activities AI could not convincingly perform, including video calls and social-media interactions.
This division of labor may be an important indicator of how AI-enabled fraud evolves. AI handles the inexpensive, high-volume portion of victim engagement while humans intervene only when physical or social proof is necessary. The result is not complete replacement of human operators, but a substantial increase in the number of victims each human can support.
Analyst Commentary
The emerging threat is not simply that adversaries have gained access to another powerful software tool. Frontier AI is beginning to change the economics, tempo, and scalability of malicious operations. Cyber operations have traditionally been constrained by the availability of skilled operators, infrastructure, working exploits, analysts, translators, malware developers, and time. AI directly pressures each of those constraints. An operator no longer needs to personally conduct every reconnaissance query, manually troubleshoot every tool, translate every stolen document, maintain every phishing server, or analyze every compromised environment. Increasingly capable agents can perform those functions concurrently while human operators concentrate on objectives and consequential decisions.
The progression visible across publicly documented PRC-linked activity is particularly instructive. In 2024, reported use of frontier models largely involved research, translation, basic scripting, and troubleshooting. By 2025, reporting included vulnerability research, reconnaissance automation, infrastructure configuration, authentication research, software development, and post-compromise assistance. By 2026, Google and Anthropic were documenting agentic workflows, automated vulnerability analysis, intelligence processing, autonomous offensive frameworks, and AI systems performing work traditionally distributed across teams of operators and analysts. The most consequential implications may extend beyond cyber operations. AI can act as a force multiplier, compressing the human expertise and labor required for intelligence analysis, surveillance engineering, electronic warfare, weapons development, and operational planning. These are areas where increased speed and scale can carry national-security consequences far beyond the compromise of an individual network.
China’s position in the global AI race makes this development strategically significant. Stanford’s data indicates that Chinese frontier-model performance is already near parity with leading US systems even while the United States retains major advantages in private investment and notable-model production. At the same time, documented PRC-linked or China-based actors are using foreign frontier models for cyber operations, surveillance, intelligence analysis, and military research, while Anthropic alleges that seven China-based AI laboratories have conducted industrial-scale efforts to extract capabilities from its models. This creates a potential feedback loop. More capable models can accelerate cyber operations, intelligence analysis, surveillance engineering, and military research. Those capabilities make the models themselves strategically valuable targets. Extracted capabilities may, in turn, contribute to increasingly capable domestic models that can support a broader range of operational workflows.
The enterprise implications extend beyond geopolitical competition. Anthropic’s findings concerning model routing demonstrate that organizations may not always know where information submitted to an AI assistant is ultimately processed. AI providers, aggregators, coding assistants, and routing services should increasingly be treated as components of the technology supply chain. Credentials, source code, security telemetry, proprietary research, internal documentation, and sensitive customer information can cross an unexpected trust boundary when one AI service invokes another.
For defenders, however, AI-enabled cyber operations still leave artifacts. An autonomous agent can write malware faster, rebuild detected tooling, rotate infrastructure, or operate against multiple targets simultaneously, but malicious payloads must still execute within victim environments. As AI increases the speed and volume at which adversaries can create and modify malicious code, relying on any single detection engine creates an increasingly consequential visibility gap. PolySwarm helps address that gap by crowdsourcing malware detection across a diverse marketplace of commercial and specialized security engines. Rather than depending on one vendor’s ability to recognize rapidly evolving or newly generated threats, defenders can compare verdicts from multiple independent detection sources and identify suspicious files that may evade individual products. This detection diversity becomes increasingly valuable as AI lowers the cost of producing malware variants. An adversary capable of automatically rebuilding a payload after detection can iterate faster than conventional signature-development cycles.
PolySwarm also allows analysts to investigate suspicious samples, compare engine verdicts, and pivot into associated malware intelligence as emerging threats appear across the ecosystem. In a threat environment where AI can increase adversary tempo, concurrency, and output while reducing the personnel required to sustain operations, defenders need detection and intelligence capable of keeping pace. AI may allow attackers to produce more malware, more variants, and more campaigns with fewer people. PolySwarm gives defenders the detection diversity and threat intelligence needed to meet that scale without betting their security on a single engine.
IOCs
PolySwarm has multiple samples associated with the activity described in Anthropic's report.
be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c
918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593
Don’t have a PolySwarm account? Go here to sign up for a free Community plan or subscribe.
Contact us at hivemind@polyswarm.io | Check out our blog | Subscribe to our reports.