Anthropic said it disrupted five suspected efforts to use its Claude AI models for biological research with potential weapons applications between November 2025 and September 2026. The activity included work related to enhancing or evading immunity in chikungunya, avian influenza, and orthopoxviruses, plus attempts to optimize or redesign toxins and venoms under claimed therapeutic-research rationales. Anthropic assessed that some activity was linked to state-sponsored actors.
The users allegedly hid their origins through anonymized accounts, private email, VPS infrastructure, U.S. proxy traffic, gray-market resellers, and zero-data-retention services to bypass regional controls. Anthropic terminated the accounts and access, hardened safeguards, disrupted relay networks, and shared relevant findings with other AI labs and government authorities. The company also reported blocking an Iran-nexus actor that used Claude to analyze public data and develop targeting recommendations against U.S. naval forces in the region.
Track how attackers are adapting to this technology.
11 events from the most recent confirmed update back to the earliest known activity.
Anthropic reported that a China-based defense and military-industrial researcher used Claude to develop roughly 16 electronic-warfare and suppression-of-enemy-air-defenses modules. The work modeled radars, missile sites, command posts, and communications nodes, including a default scenario with 12 targets in Taiwan; Anthropic said metadata linked the actor to PRC research institutions including the PLA Academy of Military Sciences.
Anthropic's September 2026 misuse report reportedly described a Russia-based non-state group using Claude Code to develop an autonomous kamikaze-drone swarm and train a vision classifier on scraped Ukrainian combat footage. It also reportedly identified a China-based actor using Claude to draft a Chinese-language specification for an anti-torpedo fire-control system.
Anthropic reportedly tracked a northern Yemen-based cell designated GTG-87001 that used Claude Code across three guided-rocket and missile programs, including software for flight control, position estimation, firmware builds, and simulations. The group allegedly concealed weapons intent and divided tasks across sessions; Anthropic found no evidence that it fielded an operational weapon.
Anthropic alleged that seven China-based laboratories, including Moonshot and DeepSeek, attempted to replicate its technology through model distillation. It said it had detected increasingly sophisticated efforts to bypass defenses and extract capabilities from U.S. frontier AI models.
Anthropic identified and disrupted an Iran-nexus actor that used Claude to analyze publicly accessible data and develop targeting recommendations concerning U.S. naval forces in the region, alongside influence and surveillance activity. Anthropic banned the account, developed detections intended to reduce recurrence, and shared threat intelligence with government authorities.
Anthropic published its 154-page “Detecting and Countering Misuse of AI” report covering five Claude-use cases between November 2025 and September 2026 that it assessed as potentially supporting biological-weapons-related research. It reported banning implicated accounts, disrupting regional-block evasion infrastructure, sharing findings with AI labs and government authorities, and strengthening safeguards.
A purported theoretical scientist used Claude to redesign toxins under a national public research program, involving a bacterial toxin subunit and a hemorrhagic-fever-virus protein identified by WHO as particularly dangerous. The user attempted to obscure the topic with vague descriptions, and Anthropic terminated the associated access for terms-of-service violations.
A user mapped venom-toxin peptides across animal families and created a program to optimize toxic characteristics, while claiming the work was for therapeutic molecules. Anthropic concluded the output could enable harmful compounds and determined it was being used in a state-sponsored program in an unsupported region.
An account sought assistance with a grant application involving orthopoxviruses, including smallpox and Mpox, discussing containment facilities, live-virus experimentation, and research intended to evade immunity. Anthropic linked the activity to a reseller service, a randomly generated email account, U.S.-tunneled access, and a banned account farm.
A non-U.S. researcher used a random username, private email service, and VPS access while seeking information on avian influenza adaptation to mammals and non-respiratory disease. Anthropic assessed that the research could reveal mechanisms relevant to increasing human-to-human transmissibility.
Anthropic identified a case in which users sought Claude's help with a grant application involving chikungunya-virus modifications, including increasing mutation potential and virulence. Anthropic assessed that the purported civilian work was intended to proceed at a military facility and banned the associated accounts, sharing information with government authorities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
8 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcetechrepublic.com
Open sourcemachinesociety.ai
Open sourcearstechnica.com
Open sourcebloomberg.com
Open sourcesocradar.io
Open sourcetomshardware.com
Open sourcefoxbusiness.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.