Logo
FrontierNews.ai

Claude Code Becomes Unwitting Tool in State-Sponsored Espionage and Malware Development

Anthropic disclosed that Claude Code and related tools have become targets for state-sponsored actors seeking to extract sensitive data, rebuild malware, and train competing AI models without user knowledge. In separate threat campaigns, Chinese companies rerouted millions of customer requests to Claude while Russian hackers used the AI system to automatically modify malware and evade security defenses, according to reports published in early September 2026.

How Are Attackers Exploiting Claude Code and Related Tools?

The exploitation methods vary by threat actor, but all share a common goal: leveraging Claude's capabilities while hiding the activity from end users. Here are the primary attack vectors researchers identified:

  • Request Rerouting: Chinese companies including Moonshot AI and DeepSeek intercepted customer requests meant for their own models and secretly forwarded them to Claude Opus instead, then displayed Claude's responses to users who believed they were using the original service.
  • Credential Extraction: Attackers routed requests containing live credentials for government systems, military databases, and corporate infrastructure through Claude, allowing them to harvest sensitive authentication data without user awareness.
  • Malware Automation: Russian state-sponsored hackers used Claude to build an AI-driven workflow that automatically detects when their malware is discovered by security products, then rebuilds and redeploys modified versions to evade static defenses.
  • Model Distillation: Both Chinese and Russian actors captured Claude's responses and internal reasoning to train their own competing AI models, effectively stealing Anthropic's intellectual property at scale.

What Scale of Data Theft Are We Talking About?

The numbers are staggering. Moonshot AI alone relayed nearly 300,000 customer requests to Claude in a single ten-day period, with the vast majority targeting Claude Opus, Anthropic's most capable model. Between May and July 2026, Anthropic counted more than 23 million exchanges attributable to Moonshot's distillation attacks. DeepSeek conducted a similar campaign, with over 12.1 million exchanges routed to Claude Opus over just 14 days in July 2026.

Even more alarming, Alibaba ran what Anthropic describes as "the largest distillation attack we have ever measured," with more than 151 million exchanges between May and July 2026. The requests intercepted by these actors included sensitive information across multiple languages and countries, including names, email addresses, company data, and other personally identifiable information from hundreds of end users in at least a dozen languages.

What Sensitive Information Was Exposed Through Claude Code?

The specific data captured reveals the scope of the breach. In one case documented by Anthropic, a user believed to be affiliated with China's military loaded CCTV surveillance footage from hundreds of cameras in Chengdu into what they thought was the Kimi AI system, asking whether a tracked individual was behaving abnormally. The footage included video from cameras outside People's Liberation Army facilities and institutes affiliated with state-owned enterprises. The user had no way of knowing their request was being forwarded to Claude.

An engineer at a major Chinese state-owned enterprise used Kimi to build an internal system and inadvertently exposed internal code and live credentials from multiple major Chinese technology companies. Similarly, an employee of a Chinese technology company used what they believed was DeepSeek to analyze internal documentation, including full specifications, organizational structure, and strategic objectives of a flagship AI program, which was then relayed to Claude without the company's knowledge.

Russian government data also flowed through these compromised channels. DeepSeek relayed requests from an IT operator working with data from a Russian government agency associated with the country's Ministry of Defence, including live credentials for a Russian government database.

How Are Russian Hackers Using Claude for Malware Development?

Beyond data theft, Russian state-sponsored actors have weaponized Claude Code for offensive cyber operations. Anthropic attributed a campaign to a threat group it calls GTG-20006, which aligns with broader reporting linking the cluster to Midnight Blizzard, also known as APT29 and Cozy Bear. This group developed an AI-driven process to automatically rebuild and redeploy their toolkit if it was detected by security products, thereby undermining defenders' ability to block the malware through traditional signature-based detection.

"The actor used AI to monitor how well their tools evaded detections from known security defenses. If their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections," Anthropic explained.

Anthropic Threat Intelligence Report, September 2026

The malware toolkit developed with Claude's assistance includes multiple components: two Windows-based implants, a mobile exploitation kit, a credential stealing tool targeting browser password stores, a phishing platform designed to mimic government organizations, and an administrative console for managing compromised accounts. The threat actor also used AI workflows to register domains, set up hosting infrastructure for phishing emails, deliver messages, and monitor command-and-control channels for successful compromises.

Which Organizations and Countries Have Been Targeted?

The attacks span multiple continents and target critical infrastructure. More than 20 distinct organizations were singled out during reconnaissance and live operations, including government ministries, defense and intelligence bodies, embassies, diplomatic missions, think tanks, and defense-industrial companies, primarily in Ukraine and Europe. The attacks also extended to the Middle East and maritime-related government agencies in Asia.

In one particularly brazen operation, GTG-20006 compromised at least three hospitality vendors operating hotel guest Wi-Fi networks. The hackers used compromised admin credentials to modify DNS records, redirecting hotel guests' traffic to servers controlled by the threat actor. Guests connecting to the hotel Wi-Fi had their traffic, device identifiers, and IP addresses sent to the attackers' infrastructure. Victims were then served ClickFix-style lures to deliver Windows, Android, and iOS malware tailored to their devices.

The threat actor also targeted surveillance platforms, discovering authorization flaws in camera streaming service application interfaces to enumerate users and harvest tokens granting access to victims' live camera streams. In North Africa, GTG-20006 leveraged stolen VPN credentials to hijack a central account server and exfiltrate an entire credential database containing over 300,000 national identity records and commercial registry data for more than half a million companies.

How Did Attackers Bypass Anthropic's Security Controls?

Anthropic had implemented safeguards to prevent unauthorized model distillation, including a feature that returns a reference to Claude's internal reasoning, which Anthropic calls a "thinking signature." However, both Moonshot and DeepSeek circumvented this control using what Anthropic terms a "cross-session replay attack". The attackers saved the signature, started a new session, and got Claude to convert it back into the full reasoning trace, effectively recovering the protected information.

To access Claude Code and related services, the Chinese actors created networks of fraudulent accounts. Moonshot reached Claude through a proxy network of 5,380 fraudulent accounts, most of which appeared to be based in Singapore and Japan, allowing them to evade Anthropic's geographic restrictions. Anthropic had barred companies more than 50 percent owned by businesses headquartered in China from its services since September 2025, but the proxy network allowed Moonshot to circumvent this policy.

What Actions Is Anthropic Taking to Prevent Future Attacks?

In response to these campaigns, Anthropic has strengthened its defenses and detection capabilities. Rather than banning proxy accounts one at a time, Anthropic now attempts to attribute their activity to specific organizations and has strengthened classifiers designed to detect adversarial extraction. Claude now summarizes its internal reasoning before responding, which Anthropic says makes stolen transcripts less useful for training another model.

Accounts showing signs of abuse, such as unauthorized resale of Claude or operation from unsupported countries including China, Russia, and Iran, can now be required to verify their identity and are banned if they fail to do so. Anthropic has also identified and disrupted distillation attacks from seven labs based in China, which it names as Alibaba, Moonshot, DeepSeek, Zhipu (branded Z.ai outside China), Xiaomi, SenseTime, and MiniMax.

The broader cybersecurity community has also mobilized. On September 8, 2026, the US National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI issued a joint advisory naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as China-based AI companies running industrial-scale distillation campaigns against US AI companies. However, China's Ministry of Commerce responded by calling the accusations groundless and without legal basis.

The implications extend beyond immediate security concerns. Anthropic warned that a model distilled from a frontier model can help achieve dangerous capabilities, including in the biological and cyber domains, even when the harvested exchanges contain little about those subjects. "The robust safeguards that prevent Claude from being misused by bad actors do not transfer when our models are distilled by an unauthorized lab," Anthropic stated. As AI tools become more powerful and more widely deployed, the stakes for securing them against state-sponsored exploitation continue to rise.

Anthropic
" }