
Fake HBO Max ads on Reddit pushed a ClickFix lure that could install info-stealing malware.
A new Anthropic threat intelligence report says Claude was misused over eight months for espionage, malware iteration, surveillance platforms, weapons software and unauthorized model distillation by Chinese AI labs.


Anthropic’s threat intelligence report covers December 2025 through August 2026 and groups misuse into cyber operations, influence operations, surveillance, fraud, biological misuse, conventional weapons and unauthorized model distillation. The report says Haiku, Sonnet and Opus were the most affected Claude models, while newer Fable and Mythos models appeared in only a single distillation case. The central takeaway for readers is that AI misuse is no longer limited to simple prompt abuse: models are being inserted into operational workflows where speed, scale and automation matter.
The report’s cyber chapter argues that sophisticated attacks no longer require sophisticated attackers, because reconnaissance, exploitation and tool-building can be handed off to models running in parallel. Anthropic describes a Russian-speaking espionage actor that used AI agents to test malware against security products, then rewrite and recompile it when antivirus tools detected it. The practical implication for defenders is clear: static signatures and slow update cycles become less effective when attackers can iterate at machine speed.
Anthropic identifies multiple Chinese AI labs in unauthorized distillation or request-routing campaigns, including Alibaba’s Qwen team, DeepSeek, Moonshot AI, Xiaomi, Zhipu, SenseTime and MiniMax. The largest campaign attributed to Alibaba’s Qwen lab totaled more than 151 million exchanges between May and July 2026, according to the report. Anthropic also says some labs relayed their own users’ requests to Claude, creating cases where sensitive material such as surveillance data, public security work and personal information passed through the system.
The report says Claude was used in conventional weapons-related cases, including missile guidance software, an autonomous FPV kamikaze drone swarm and electronic warfare modules. In surveillance, Anthropic describes a Mali project called “Lakana 360” that used Claude as a primary engineering workforce for a platform monitoring roughly 25 million SIM cards across all three national mobile carriers. The biology section is more self-critical: Anthropic says classifiers struggle in dual-use science because legitimate and harmful intent can be nearly impossible to distinguish, and the company points to stricter safeguards and verified-user access as responses.

Fake HBO Max ads on Reddit pushed a ClickFix lure that could install info-stealing malware.
Top AI figures are backing a frontier AI slowdown, while critics warn about regulation, transparency, and open-source risks.

Anthropic’s CEO wants auditors, shared safety standards, and global agreements before AI self-improvement accelerates further.

Nvidia may invest up to $10 billion in Anthropic’s planned IPO.