In a concerning revelation, Anthropic has exposed several state-sponsored surveillance operations leveraging its artificial intelligence models to target dissidents and minorities. These campaigns, detected between January and, originated in ChinaIran and West Africa with a particular focus on diaspora communities, including Hong Kong pro-democracy activists.
The misuse of AI for surveillance is part of a broader trend where threat actors are exploiting advanced technologies to conduct various malicious activities. Over the past eight months, Anthropic’s Threat Intelligence team has identified and disrupted numerous operations where threat actors attempted to use AI for harmful purposes. This report highlights case studies from these operations and describes how the misuse of AI has evolved since previous reports in March, August, and.
AI-Augmented Cyber Operations: From Assistant to Orchestrator
Over the past six months, Anthropic’s Threat Intelligence team has identified and disrupted a series of cyber operations where threat actors used AI models. These actors included suspected state-sponsored groups, financially motivated criminals, and politically motivated individuals. The report references Generative Threat Groups (GTGs) which are Anthropic’s internal designators for actors observed abusing AI.
The report attempts to measure uplift a term describing the AI capability boost, or how much more harm was caused with AI versus without AI. This uplift is viewed through the lens of speed, scale, and depth, and attempts to determine how an actor’s adoption of AI meaningfully impacts these traits.
Sophisticated Attacks No Longer Require Sophisticated Attackers
The cybersecurity skills of AI models have collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators. In the case studies reported, a hacktivist using stolen API keys, disparate financially motivated individuals, and a state espionage operator each sustained multi-victim campaigns that, even just a year ago, would have required many skilled operators and specialist knowledge.
For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation. Every layer of offensive operations has been uplifted by AI, from reconnaissance and tool development to data processing and exploitation. An example of this uplift in capabilities is documented in case study GTG-50014.
AI’s Role in Cyber Operations Has Become Increasingly Autonomous
A majority of the operations described in the report were enabled by AI via direct execution or orchestration. The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration. Humans remained in the loop by setting the targets of attacks and reviewing exfiltration.
An example of this trend is GTG-20006, an actor who developed an AI-assisted workflow that automatically rebuilt and re-deployed their toolkit if it was detected by security products. This actor, attributed to the Russian state-nexus espionage group Midnight Blizzard targeted military intelligence, diplomatic, and defense organizations in Ukraine, Europe, and beyond.
Case Study: GTG-20006 – Russian Espionage
GTG-20006 employed a custom toolkit composed of two families of Windows-based implants, a mobile exploitation kit, a credential stealing tool, a phishing platform, and an administrative console. Each of these tools was managed and re-tooled as needed during the cyber operations through AI-assisted workflows.
The actor used AI to monitor how well their tools evaded detections from known security defenses. If their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections.
The actor also used AI to drive their phishing operations. They developed AI-driven workflows to research then register domains and then configure the hosting infrastructure used to send phishing emails. Additional workflows were developed to send the emails and monitor the C2 channels for successful compromises.
Our investigation identified more than 20 distinct organizations targeted in the actor’s operational planning, reconnaissance, and live operations. They included government ministries, defense and intelligence bodies, embassies and diplomatic missions, think tanks, and defense-industrial companies, concentrated in Ukraine and Europe but extending to the Middle East and maritime related government agencies in Asia.
The most commonly recurring targets were members of the Ukrainian government, military, and diplomatic staff. The actor scanned email services and remote access systems across more than two dozen Ukrainian government organizations.
A secondary recurring target for theft was drone supply chain technology. The actor bulk-exported the mailboxes of at least two drone component manufacturers, targeted a military drone maker, and stole a complete proprietary software development kit for a drone vision system.
The actor also compromised at least three hospitality vendors that operate hotel guest WiFi. They used compromised admin credentials to modify DNS records so that they pointed to services owned by the actor. Guests of hotels using the compromised vendors who connected to the hotel WiFi had their traffic, device identifier and IP address sent to the actor’s servers.
The actor also took over victims’ WhatsApp accounts, using a platform of headless browsers to link victim accounts as companion devices. In part by using the WPPConnect open-source WhatsApp automation library, the actor’s configuration suppressed read receipts so victims would not notice while it bulk-exported Russian and Ukrainian language conversations.
The actor also targeted surveillance platforms. They found authorization flaws in the application interface of camera streaming services, and from there they enumerated users and harvested tokens that granted them access to the victims’ live camera streams.
The same actor also conducted an intrusion of a North African government technology authority. They stole credentials to a VPN appliance, and used them to take over the organization’s central account server. This allowed them to exfiltrate its full credential database: more than 300,000 national identity records, and the commercial registry data of more than half a million companies operating in the country.
The actor continued to develop a cloud email espionage platform that in part used “Embassy Kit,” the actor’s framework for managing device code phishing, to operate a Microsoft 365 token theft campaign. This platform, which was used to target diplomatic and government personnel, resulted in the access and exfiltration of mail records from at least eight organizations including a national prosecutor office, a military education institute, and a regional intergovernmental organization.
Windows credential stealers were delivered via fake update-themed social engineering lures, alongside companion payloads with full remote access capabilities. These payloads were designed to freeze the victim machine’s security updates, meaning that new malware detection signatures published by security vendors would not be retrieved or run on the victim’s machine.
Anthropic has disrupted these activities, strengthened their AI safeguards based on what they learned, and shared intelligence with authorities and industry partners where appropriate. They hope that the findings in this report will help other developers recognize similar patterns on their own platforms, give governments and civil society a clearer view of how emerging threats take shape, and strengthen collective defenses.



