Anthropic reported detecting and disrupting malicious use of Claude between December 2025 and August 2026, including a China-linked religious-affairs intelligence operation identified as GTG-14020. Reporting linked the activity to an alleged platform called BABEL (Global Faith Monitoring), which collected multilingual online material on communities connected to China and generated structured Chinese-language dossiers. Its reported targets included Catholic, Tibetan Buddhist, Falun Gong, Taiwanese Christian, Uyghur, Tibetan exile, Inner Mongolian, Korean, and Japanese Christian communities.
BABEL allegedly combined the MiniClaw AI-agent framework with Claude, Codex, and DeepSeek models, using infrastructure on two VPS instances outside China to automate collection and analysis. Anthropic said malicious actors increasingly used agentic AI workflows to lower the time, labor, and expertise needed for espionage, intrusion, influence, and large-scale data collection; it banned involved accounts, strengthened safeguards, and shared relevant intelligence with authorities, affected organizations, industry partners, and researchers.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
Anthropic published its “Detecting and countering misuse of AI: September 2026” report, covering malicious activity it said it detected and disrupted from December 2025 through August 2026. It reported banning associated accounts, strengthening safeguards, and sharing relevant intelligence with authorities, affected parties, industry partners, and researchers where appropriate.
The reported BABEL target set included Uyghur dissidents, Tibetan exile-government members, Inner Mongolian independence movements, and Korean and Japanese Christian communities, categorized through themes such as separatism, terrorism, national unity, and social stability. Reporting linked the activity to Anthropic's GTG-14020, described as a China-based religious-affairs intelligence operation targeting Catholic, Tibetan Buddhist, Falun Gong, and Taiwanese Christian communities.
Researchers reported obtaining backend access to BABEL, an alleged China-linked Global Faith Monitoring system that collects intelligence on religious and independence-oriented communities connected to China. The reported platform used MiniClaw and Claude, Codex, and DeepSeek models to scrape multilingual material and generate structured Chinese-language dossiers through infrastructure on two VPS instances outside China.
GTG-50029 exploited a previously undocumented WordPress re-installation race condition to create rogue administrator accounts at European political parties, media organizations, think tanks, and associated SaaS providers. The actor accessed at least 14 of 42 tracked targets and exfiltrated an estimated 12 to 26 GB of data.
GTG-50021 operated a fraudulent AI-reseller service that installed credential-harvesting tooling, stole Anthropic credentials, and resold access. Separately, GTG-50020 used prompt injection against an AI vendor's evaluation sandbox to steal production API keys and used stolen customer keys in further intrusion attempts.
GTG-10007 ran an autonomous vulnerability-research program against endpoint-security products and network and security appliances. The operation identified multiple previously unknown vulnerabilities and developed working exploits in laboratory environments.
GTG-10007, a Chinese-speaking group likely operating from Changsha, Hunan, used Claude for intrusion attempts, foreign-government reconnaissance, exploit research, malware development, and intelligence collection. The group targeted roughly 50 organizations and compromised an education-technology company, a retail company, and a Southeast Asian government agency.
Anthropic identified financially motivated clusters suspected to be ShinyHunters affiliates using AI to accelerate scanning, exploitation, cloud compromise, data theft, resale, and extortion. One affiliate scanned 1.8 million Android APKs for hardcoded secrets, while a supply-chain intrusion affected roughly 200 downstream customers and extracted more than 2,100 Azure AD token sets across over 40 tenants.
GTG-20006 compromised at least three hotel guest-Wi-Fi vendors, modified DNS records to redirect users to ClickFix-style malware delivery, and used compromised WhatsApp accounts to export Russian- and Ukrainian-language conversations. The group also targeted at least two former high-level Ukrainian officials through WhatsApp account takeover.
A Russian state-nexus group assessed as consistent with Midnight Blizzard targeted more than 20 organizations, including Ukrainian and European government, defense, diplomatic, and drone-sector entities. The group used Claude-assisted workflows for reconnaissance, phishing, malware development, command-and-control, and data exfiltration, including theft of identity and commercial-registry records from a North African government technology authority.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.