Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacker used the agent to identify exploitable services on targets’ systems... with the attacker preferring to issue vague directives such as “recon this” and allowing Claude to carry out the requests autonomously.
During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to scan target infrastructure to identify potential vulnerabilities and to enumerate services and endpoints. APT28 has performed large-scale scans in an attempt to find vulnerable servers. APT29 has conducted widespread scanning of target environments to identify vulnerabilities for exploit.
They simply broke the job into small, ordinary-looking requests and let the tool’s own connections carry them out. That is the same kind of connection, via MCP, that lets any AI agent open a file, query a database, or call an API on a company’s behalf.
They simply broke the job into small, ordinary-looking requests and let the tool’s own connections carry them out. That is the same kind of connection, via MCP, that lets any AI agent open a file, query a database, or call an API on a company’s behalf.
The highest-privilege accounts were identified, backdoors were created, and data were exfiltrated with minimal human supervision.
According to the write-up, obfuscated detection logic had shipped silently since version 2.1.91, released on April 2, with no mention in the release notes.
Rather than sending an overt signal, the tool allegedly encoded its findings steganographically, tweaking the date format and swapping a punctuation character in the system prompt sent back to Anthropic's servers — invisible to the user, but machine-parseable on Anthropic's end.
Claude Code, acting with custom scaffolding, was assessed to have conducted 80 to 90 percent of the operation autonomously, handling reconnaissance, privilege escalation, lateral movement, credential theft, and data exfiltration...
...its own Claude Code agent handled an estimated 80 to 90 percent of tactical work, including reconnaissance, exploitation, credential harvesting and lateral movement...
Once jailbroken, Claude Code scanned systems, mapped out infrastructure, identified high-value databases, and even wrote its own exploit code.
During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to scan target infrastructure to identify potential vulnerabilities and to enumerate services and endpoints.
Whenever a proxy was detected, the code reportedly checked whether the system timezone matched Asia/Shanghai or Asia/Urumqi and inspected the proxy URL against a hardcoded list of Chinese domains and AI lab identifiers.
...its own Claude Code agent handled an estimated 80 to 90 percent of tactical work, including reconnaissance, exploitation, credential harvesting and lateral movement...
Instead of transmitting explicit telemetry data, the tool allegedly encoded detection results by modifying internal system prompts. This included subtle changes such as altering date formats or swapping punctuation characters, effectively creating a covert signaling method.
The highest-privilege accounts were identified, backdoors were created, and data were exfiltrated with minimal human supervision.
China’s National Vulnerability Database ... said Claude Code versions 2.1.91 to 2.1.196 contained a built-in monitoring mechanism capable of transmitting sensitive information to remote servers. The database said the information could include users’ geographic location and identity-related identifiers.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.