3 key takeaways from the new Anthropic threat intelligence report on AI misuse in cyber and influence operations

1: AI Lowers the Technical Barrier for Cyber Attacks

Generative AI tools have collapsed the labor and tooling gap, allowing low-skill threat actors (such as individual hacktivists and opportunistic cybercriminals) to execute advanced, multi-stage cyber campaigns that previously required the resources of well-resourced, state-sponsored groups.

2: The AI Supply Chain is a Primary Target

Malicious groups are targeting the technology companies and systems that power AI. They steal things like API keys, developer access tokens, and connections to AI agents from businesses. They then use that stolen access to pay for their own computing power while making it harder to track what they are doing.

3: Scaling and Laundering Influence Operations

State-backed and commercial influence-as-a-service actors use AI extensively as an automated “newsdesk” and administrative engine. This enables them to generate multi-language fake news sites, automate synthetic persona networks, and launder state narratives to make them appear as independent local reporting.

Here’s what Iran was doing with Claude:

1) Propaganda: Writing content, disguising posts as independent news sources, and spreading them across X, Instagram, and TikTok — run by actors working within or on behalf of Iranian state propaganda institutions.

2) Targeting U.S. naval forces: One Iran-nexus actor used Claude to develop targeting recommendations against U.S. naval forces in the region.

3) Domestic mass surveillance: The same account designed software for a mass-surveillance platform for Iranian state systems.

4) Spyware: Creating a malicious Firefox extension built to harvest user identities from social networks.

The bigger pattern: Anthropic describes Claude being used “in place of an engineering workforce” — AI as a force multiplier, letting small teams build capabilities that used to require serious resources.

Anthropic banned the accounts and took down the relay networks, but never disclosed how long these campaigns ran before detection.

The propaganda content was already live, reaching real people.

For the surveillance and targeting work, there’s no public word on whether any of it was ever deployed.

Timeframe: December 2025-August 2026

Scope: cyber operations, influence operations, surveillance, scams & fraud, biological misuse, conventional weapons development, distillation (a form of intellectual property theft — cloning an AI model)

Pages

Archive

Alert: The content on this site is frequently migrated. If you land on a broken link, please visit the Annual Diaries.