Anthropic is an artificial intelligence company, not a threat actor. Available information indicates it was the vendor whose Claude and Claude Code platforms were reportedly abused by Chinese cyber-espionage operators to automate large portions of an intrusion lifecycle, and it also reported disrupting an AI-orchestrated cyber-espionage campaign. There is no high-confidence basis to classify Anthropic itself as a malicious actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Anthropic was referenced as the provider of the Claude Code AI tool, which was abused by Chinese cyberspies to automate intelligence-gathering attacks against high-profile companies and government organizations.
Anthropic reported and disrupted an AI-orchestrated cyber espionage campaign in which a malicious actor used their AI platform (Claude and agents) to autonomously conduct attacks against approximately 30 entities, covering the full attack lifecycle from reconnaissance to exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.