Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research

3 hours ago 10

In the latest installment of "my AI model is more dangerous than yours," Anthropic on Thursday warned that cybercriminals and state-sponsored hackers alike are using its Claude models to automate cyberattacks, build kamikaze drone swarms, conduct mass surveillance operations, and try to develop an even more dangerous version of a deadly mosquito-borne virus.

The baddies have come a long way since November, when an earlier Anthropic report documented Chinese spies using Claude to automate digital intrusions and steal sensitive data at a handful of critical organizations. Now everyone from ShinyHunters to Russian freelancers is getting in on the illicit model usage.

This is not to say that Anthropic – nor any other frontier AI lab – plans to slow down its model development or testing initiatives, or take responsibility when its AI commits crimes. It does, however, “hope that the findings in this report will help other developers recognize similar patterns on their own platforms, give governments and civil society a clearer view of how emerging threats take shape, and strengthen collective defenses.”

The model maker’s latest very lengthy report on AI misuse covers activity Anthropic disrupted between December 2025 and August 2026 across seven “harm areas” where miscreants used – or attempted to use – Claude Haiku, Sonnet, and Opus models for evil. 

These span cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Anthropic also noted that its most powerful Claude Fable or Mythos-class models weren’t used, except in one distillation case.

Even without those most advanced systems, the case studies in the report highlight some pretty bad behavior.

Autonomous cyberattacks

For example, a Russian espionage crew that Anthropic tracks as GTG-20006 – the state-sponsored cyber espionage arm of Russia’s Foreign Intelligence Service (SVR), also known as Midnight Blizzard, APT29, or Cozy Bear – increased the speed of its attacks by using AI to automate the entire kill chain. Anthropic identified more than 20 organizations targeted in these attacks, including embassies, think tanks, defense-industrial companies, and government, defense, and intelligence agencies across Ukraine, Europe, the Middle East, Asia, and North Africa.

“We observed GTG-20006 operate through customized AI-driven workflows that automated much of their operations from development, infrastructure acquisition, phishing, persistence through command and control, to data exfiltration,” Anthropic said.

Meanwhile, “multiple clusters” linked to the data-theft-and-extortion gang ShinyHunters used Claude to scale their smash-and-grab operations. One affiliate that specializes in supply-chain attacks breached a software-as-a-service provider, and used that foothold to steal data from about 200 of the SaaS company’s customer organizations. 

“It then conducted a session-store dump containing over 2,100 Azure AD token sets spanning more than 40 corporate tenants in about 34 hours,” according to the report. “AI agents performed nearly all of the work.”

Biological misuse

Moving on to a serious health-and-safety risk that looks even scarier when given an AI boost: Anthropic’s report documents five cases of users in “unsupported regions” using Claude to support biological weapons development. 

In one, a scientist attempted to use Claude to help write a grant application for research related to chikungunya virus, a mosquito-borne virus that can cause severe disease and death. The research focused on the virus’ transmissibility and immune evasion properties, which Anthropic admits could be used to help develop better vaccines. 

Or “it could also be used to make the pathogen more dangerous,” the report authors said, noting that the military research institute where the research would be performed gave them “cause of concern.”

In May, Anthropic discovered a user outside the US using Claude in their research on adaptations of highly pathogenic avian influenza – bird flu.

“Unlike other influenza variants, H5 viruses (of which this avian virus is one) often show striking brain involvement in cats, foxes, ferrets, and some human cases,” the report says. “A pandemic variant with such properties would be especially concerning due to its potential to increase disease severity, confuse diagnosis, and hinder treatment.”

Weapons development

Since its November report, Anthropic has identified new categories for Claude misuse that violate its terms of service. One of these involves users outside the US using Claude to develop software for conventional weapons – firearms, missiles, armed drones, bombs, and other munitions, plus targeting and control systems that operate them. 

In its new report, the model maker shares details on six cases: three in China, two in Russia, and one in Yemen.

In Yemen, a weapons development program used Claude instead of human software engineers to develop guidance, navigation, and control (GNC) software that steers and stabilizes a flying vehicle. “Our safeguards blocked many of their requests, but not all of them,” Anthropic says. 

The same team used Claude to try to develop guided weapons. While Anthropic says it has no evidence that the actors produced an operational device, it says they did test-fire a guided rocket.

“We banned accounts associated with the actors and shared threat information with public- and private-sector partners to mitigate risks posed by the actors,” the report says. “Nevertheless, we have evidence that the actors had already built an offline simulation toolkit that does not rely on Claude or other engineering computing environments.”

In China, someone used Claude to draft a Chinese-language specification for an anti-torpedo fire control system, and then benchmark their system against specific US anti-torpedo and anti-submarine programs. Anthropic assesses that the user was associated with a Chinese defense industry manufacturer aiming to produce a weapons specification and acquisition proposal for the People's Liberation Army Navy.

According to the report:

The actor used Claude to write the acquisition proposal, refining it over many drafts. After each draft, the actor instructed Claude to role-play a hostile expert reviewer to critique the proposal, then used that feedback to sharpen the next version. In parallel, the actor used Claude to build pieces of the anti-torpedo weapons system’s fire control software and a test matrix to validate them.

Anthropic uncovered this during an internal investigation into suspected weapons development and banned the account.

In yet another case, Anthropic identified a likely Russian “freelance team” attempting to build a full-stack autonomous first-person-view (FPV) kamikaze drone swarm. They used Claude to write and test the code, building the drones’ core software system. Anthropic also banned these accounts. ®

Read Entire Article