Anthropic reported that PRC-linked and China-based operators used Claude between December 2025 and August 2026 in increasingly agentic workflows supporting reconnaissance, vulnerability research, exploitation, credential collection, infrastructure management, exfiltration, and intelligence analysis. Activity included Chinese-speaking operators tracked as GTG-10007, China-aligned surveillance operations, and alleged military research involving anti-torpedo and electronic-warfare systems. Anthropic also alleged that seven China-based AI laboratories—including Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime, and MiniMax—performed unauthorized industrial-scale distillation of Claude.
OpenAI separately disrupted accounts associated with China-linked Charcoal Typhoon, Salmon Typhoon, and SweetSpecter, as well as Iranian, North Korean, and Russian state-affiliated actors. The groups used AI primarily for open-source research, translation, scripting, troubleshooting, phishing content, and research into stealth techniques; SweetSpecter also targeted OpenAI staff in a May 2024 spear-phishing attempt carrying SugarGh0st RAT, though the emails were blocked. OpenAI assessed that the observed use did not provide attackers novel capabilities beyond public tools, while warning that enterprise users should consider whether AI routing services could expose sensitive prompts or credentials to third-party model providers.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
Anthropic reported that a China-based actor associated with a defense-industry manufacturer used Claude to support development of an anti-torpedo weapons system for a PLA Navy acquisition proposal. It also identified a military-industrial researcher using Claude to develop roughly 16 electronic-warfare and suppression-of-enemy-air-defenses software modules configured around targets in Taiwan.
Anthropic identified a China-based, PRC government-aligned religious-affairs intelligence operation that used Claude to create Chinese-language dossiers on religious figures and organizations. It also reported a PRC-aligned operation targeting Uyghurs in Syria that processed more than 100 WhatsApp groups and dozens of Telegram channels to identify recruitment targets and improve deceptive Arabic-language messages.
Anthropic said it disrupted activity associated with municipal public-security and state-security organizations that used Claude for surveillance and intelligence collection against dissidents, human-rights defenders, Uyghur advocates, and overseas protests. One municipal cyber-police unit reportedly used Claude Code to operate sentiment monitoring, query a government surveillance database, and produce daily reports.
Anthropic described an operation using disposable hosting, phishing, ClickFix, DNS hijacking, automated domain registration, and C2 monitoring against more than 20 organizations, including ministries, defense and intelligence entities, embassies, and defense-industrial firms. The activity included scanning systems of more than two dozen Ukrainian government organizations and stealing a drone vision system's proprietary SDK from one victim.
Anthropic reported that Chinese-speaking operators, likely located in Changsha, Hunan, conducted the sustained GTG-10007 espionage operation using Claude; two operators were identified as undergraduates at a Chinese university. Anthropic did not attribute the operation to the Chinese government.
Anthropic reported malicious Claude use from December 2025 through August 2026 for cyber operations, surveillance, influence activity, fraud, weapons-related work, biological misuse, and illicit model distillation. It assessed that AI-assisted operations supported vulnerability research, exploitation, credential collection, malware development, infrastructure management, exfiltration, and intelligence processing.
Anthropic attributed its largest alleged Claude-distillation campaign to Alibaba, reporting more than 151 million exchanges between May and July 2026 and a peak of nearly three million exchanges per day.
Anthropic reported that, since February 2026, it had detected and disrupted alleged illicit industrial-scale Claude-distillation campaigns from seven China-based AI laboratories.
OpenAI reported that infrastructure linked to Keyhole Panda/APT5 and Vixen Panda/APT15 used ChatGPT for reconnaissance, script modification, Linux troubleshooting, software development, and infrastructure configuration.
OpenAI publicly disclosed that it identified and banned ChatGPT accounts likely linked to SweetSpecter after finding them used for vulnerability research, scripting, and social-engineering support. It described this as the first public identification of the group targeting a U.S.-based AI company.
SweetSpecter sent phishing emails posing as ChatGPT-user support requests to OpenAI employees, attaching a ZIP archive containing an LNK file designed to deploy SugarGh0st RAT. OpenAI said its controls blocked the messages from corporate inboxes and no successful compromise was described.
OpenAI and Microsoft reported terminating accounts associated with five state-affiliated actors, including China-linked Charcoal Typhoon and Salmon Typhoon. The actors had used OpenAI services for research, translation, basic coding, troubleshooting, and in some cases phishing- or evasion-related content.
OpenAI stated that the suspected China-based adversary SweetSpecter emerged in 2023; prior reporting had focused on its activity against political entities in the Middle East, Africa, and Asia.
Google Threat Intelligence Group reported that more than 20 PRC government-backed groups attempted to use Gemini for reconnaissance, vulnerability research, scripting, development, technical research, and post-compromise work. It specifically described APT41/SPIRE CASTLE and RAVINE CASTLE using Gemini for tool development, intelligence gathering, social engineering, and processing exfiltrated information.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
blog.polyswarm.io
Open sourceopenai.com
Open sourceopenai.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.