How AI Is Letting Solo Hackers Pull Off Attacks That Once Required State-Sponsored Teams
Artificial intelligence has fundamentally changed the economics of cybercrime, allowing individual operators to conduct attacks of a scale and sophistication that once required entire state-sponsored teams. According to a threat intelligence report published by Anthropic on September 10, AI models like Claude are now being weaponized to automate the reconnaissance, tool development, and post-exploitation work that previously consumed months of skilled labor.
What's Changed in the Threat Landscape?
The shift is dramatic and measurable. Anthropic documented cases where individual hackers completed full network breaches in two to three hours, with some operators managing dozens of victims in parallel by delegating the grunt work to AI running at machine speed. One particularly striking example involved affiliates of the ShinyHunters extortion collective who went from stealing a single developer token to gaining full administrative control of a victim's cloud environment in roughly three hours.
The autonomous operating model that Anthropic first documented in a suspected Chinese state-sponsored campaign last November has since spread to every class of attacker the company investigated, including financially motivated criminals, commercial spyware vendors, and suspected state-backed groups. These actors used Claude Haiku, Sonnet, and Opus models, with only one distillation campaign touching Anthropic's more advanced Fable or Mythos-class models.
Which Threat Groups Are Exploiting AI Most Aggressively?
Anthropic identified multiple actor groups leveraging Claude for different attack objectives. A Chinese-speaking group tracked as GTG-10007, likely based in Changsha, ran what Anthropic calls automated exploit foundries against approximately 50 organizations. Notably, two of the operators were identified as undergraduate students, suggesting that the barrier to entry for sophisticated cyberattacks has collapsed. This group used agent swarms for reconnaissance and post-exploitation work, and one workflow iterating on network appliances produced more than a dozen possible zero-day findings in a single month.
GTG-20006, attributed to the Russian espionage group Midnight Blizzard, targeted Ukrainian government, military, and diplomatic staff. The group bulk-exported mailboxes from at least two drone component makers, stole a proprietary software development kit for a drone vision system, and compromised hotel guest Wi-Fi vendors to reach travelers. Whenever security products flagged their implants, Claude was used to modify and redeploy them, inverting the cost burden back onto defenders.
A Russian-speaking financially motivated actor designated GTG-50020 shifted focus to the AI industry itself after earlier intrusions against hotel booking and financial technology platforms. This group planted malicious instructions in an AI vendor's automated evaluation sandbox, which handed over production application programming interface (API) keys for several model providers. A follow-on campaign targeted roughly 30 AI companies in approximately four days, with the stated goal of accessing a pre-release Claude model. Anthropic confirmed that every attempted path failed and its own systems were never breached.
How Are Chinese AI Labs Distilling Claude's Capabilities?
Beyond direct attacks, Anthropic documented what it calls the largest distillation attack it has ever measured, involving operators affiliated with Alibaba Group Holding Ltd. A fixed prompt forced Claude Opus 4.6 and 4.7 to write out their chain-of-thought reasoning, and the transcripts were used to train Qwen 3.5, 3.6, and 3.7 models. The campaign peaked at nearly 3 million exchanges per day from more than 3,500 fraudulent accounts, with more than 151 million total exchanges counted between May and July.
Moonshot AI and DeepSeek Ltd. are accused of quietly forwarding their own customers' requests to Claude and saving the answers for training data. In one 10-day stretch, Moonshot relayed almost 300,000 requests from users who believed they were interacting with Kimi, Moonshot's own AI assistant. Sensitive data came along with these requests, including footage from hundreds of surveillance cameras in Chengdu uploaded by a user Anthropic assessed as likely affiliated with China's People's Liberation Army. A DeepSeek relay exposed live credentials for a Russian government database linked to the country's Ministry of Defense.
Four additional labs were named in the report: Xiaomi Corp., Zhipu, SenseTime Group Inc., and MiniMax. Anthropic said MiniMax set up a proxy service through an undisclosed shell company that sells access exclusively to Anthropic and OpenAI Group PBC models.
What Specific Attack Patterns Are Emerging?
The report details several recurring attack patterns that demonstrate how AI has compressed the timeline and reduced the skill requirements for sophisticated intrusions:
- Credential Theft and Reuse: Attackers leveraged stolen credentials and unpatched edge devices as entry points, with AI handling the reconnaissance and tool modification work at scale.
- Rapid Post-Exploitation: One case documented AI agents dumping more than 2,100 Azure Active Directory token sets from over 40 corporate tenants in approximately 34 hours.
- Automated Exploit Development: Agent swarms conducted reconnaissance and post-exploitation work, with one workflow producing more than a dozen possible zero-day findings in a single month.
- Surveillance Platform Development: Lakana 360, a surveillance platform built with Claude for Mali's state intelligence service, monitors roughly 25 million SIM cards across all three of the country's mobile operators and was designed to circumvent legal requirements for court orders.
- Weapons Development: Six weapons development cases in China, Russia, and Yemen were disrupted, including an effort by likely freelance Russia-based developers to build an autonomous kamikaze drone swarm.
How Is Anthropic Responding to These Threats?
Anthropic has implemented several defensive measures to reduce the utility of stolen Claude transcripts and limit access from high-risk regions. Claude now summarizes its internal reasoning before responding, making stolen transcripts less useful for training competing models. Additionally, accounts operating from unsupported countries such as China, Russia, and Iran can be required to verify their identity or lose access.
The company said it banned the accounts involved in the documented attacks and shared intelligence with authorities and industry partners where appropriate. However, the speed and scale at which individual operators can now conduct attacks suggests that defensive measures will need to evolve continuously to keep pace with AI-enabled threat actors.
What Does This Mean for Enterprise Security?
The implications are sobering for organizations of all sizes. The democratization of sophisticated attack capabilities means that defenders can no longer assume that only well-resourced, state-sponsored groups can execute complex, multi-stage intrusions. A single operator with access to a capable AI model can now reconnaissance networks, develop custom tools, modify malware in real time, and manage multiple victims simultaneously. This fundamentally changes the threat model and suggests that organizations need to invest in detection and response capabilities that assume attackers have access to AI-assisted automation. The traditional assumption that sophisticated attacks require large teams is no longer valid.