Anthropic has issued a warning that adversaries are no longer treating its Claude AI as a mere curiosity for sporadic misuse. According to the company, organized threat actors are systematically integrating large language models (LLMs) into core attack infrastructure—a shift Anthropic has formalized under a new adversary category it calls "Generative Threat Groups" (GTGs).

In a disclosure reported by The Hacker News on September 11, Anthropic detailed what it described as a pattern of misuse observed between December 2025 and August 2026. According to the company, threat actors are leveraging Claude for tasks including network intrusion, weapons development, disinformation creation, and mass surveillance. Anthropic characterized this as a transition from incidental or opportunistic abuse to the deliberate construction of AI-powered attack pipelines, where generative AI functions as a scalable, force-multiplying tool within adversary operations.

Anthropic's assessment categorizes GTGs into three broad groups: state-sponsored entities, financially motivated cybercriminals, and a growing commercial segment. This third category is particularly noteworthy. According to Anthropic's framing, it encompasses vendors that sell AI-powered offensive capabilities as a service—firms offering AI-augmented phishing kit generators, platforms providing automated exploit analysis, or spyware-as-a-service operations that use LLMs to process and analyze stolen data at scale. The company argued that this commercialization lowers the barrier to entry, enabling less-skilled actors to acquire sophisticated, AI-driven offensive tools without building them from scratch.

One case Anthropic highlighted involved a Russian state-sponsored group that reportedly used Claude to automate pivotal phases of its operations. According to the company's findings, the AI was employed to analyze exfiltrated data, generate convincing phishing lures, and identify vulnerabilities for exploitation—a workflow that Anthropic said dramatically compresses the attack lifecycle and enables rapid deployment of multi-stage campaigns.

This development moves the long-theoretical "dual-use" problem of advanced AI into a concrete, active state. The capabilities that make LLMs transformative for legitimate productivity—advanced reasoning, code fluency, and deep language comprehension—are precisely what make them potent offensive tools. Anthropic's disclosure underscores that this potential is not a speculative future risk but a current operational reality being exploited in the wild.

For cybersecurity practitioners, the disclosure demands a defensive paradigm shift. Threat models must now account for adversaries who use AI to enhance both reconnaissance and exploitation phases. At the same time, the dual-use nature of the technology opens defensive possibilities, including the use of LLMs for advanced phishing detection and anomaly analysis.

Practitioner Considerations

Anthropic's findings point to several immediate priorities for security teams:

  1. Internal AI Usage Auditing: Organizations deploying LLMs for internal productivity should implement governance controls, including monitoring for unauthorized use in developing attack tools or analyzing sensitive data.
  2. AI-Augmented Phishing Detection: Deploy defensive AI solutions capable of identifying the highly sophisticated, AI-generated phishing campaigns that GTGs can now produce at scale.
  3. Threat Model Updates: Revise threat models to explicitly incorporate "AI-augmented attacks" as a scenario, assessing how adversaries might use generative AI to accelerate or enhance specific attack vectors targeting your environment.

A Note on Source Context

Anthropic's disclosure is significant, but it is worth noting that the company operates in a market where shaping the narrative around AI safety and responsible deployment carries direct reputational and commercial value. This does not invalidate the threat the company describes—organized adversaries operationalizing generative AI is a concrete and observable phenomenon. However, practitioners should treat Anthropic's characterization of the landscape, including its GTG taxonomy, as one informed perspective from a party with vested interests in how AI governance frameworks develop. Corroboration from independent threat intelligence providers will be essential as this adversary category matures.


Anthropic 發出警告,指對手已不再將其 Claude AI 僅視為零星濫用的新奇工具。根據該公司所述,有組織的威脅行為者正系統性地將大型語言模型(LLMs)整合至核心攻擊基礎設施中——Anthropic 已將此轉變正式歸類為新的對手類別,稱為「生成式威脅組織」(Generative Threat Groups,簡稱 GTGs)。

在 9 月 11 日由 The Hacker News 報導的披露中,Anthropic 詳述了其於 2025 年 12 月至 2026 年 8 月間觀察到的濫用模式。該公司表示,威脅行為者正利用 Claude 執行多項任務,包括網絡入侵、武器開發、虛假資訊散播及大規模監控。Anthropic 將此特徵描述為從偶然或機會性濫用,過渡至蓄意建構 AI 驅動的攻擊流水線,令生成式 AI 在對手運作中發揮可擴展、具力量倍增效果的工具功能。

Anthropic 的評估將 GTGs 分為三大類別:國家支持實體、以牟利為動機的網絡犯罪分子,以及日益壯大的商業類別。第三類別尤為值得關注。根據 Anthropic 的框架,當中包括將 AI 驅動攻擊能力作為服務出售的供應商——提供 AI 增強式網絡釣魚工具套件的公司、提供自動化漏洞利用分析的平台,或利用 LLMs 大規模處理及分析被竊數據的間諜軟件即服務運營。該公司指出,此商業化降低了入行門檻,使技術較遜的行為者無需從零開始建構,即可獲取複雜的 AI 驅動攻擊工具。

Anthropic 特別提及的一宗案例涉及一個俄羅斯國家支持組織,據報該組織利用 Claude 自動化其行動的關鍵階段。根據公司研究結果,該 AI 被用於分析外洩數據、生成具說服力的網絡釣魚誘餌,以及識別可供利用的漏洞——Anthropic 指出,此工作流程大幅壓縮了攻擊週期,並實現多階段行動的快速部署。

此發展將先進 AI 長期以來停留在理論層面的「雙重用途」問題推向具體且活躍的狀態。令 LLMs 對合法生產力具變革意義的能力——高級推理、流暢代碼能力及深度語言理解——正是使其成為強大攻擊工具的關鍵。Anthropic 的披露強調,此潛力並非推測性的未來風險,而是當下活躍的運作現實,已於實戰中被利用。

對網絡安全從業員而言,此披露要求防禦範式必須轉變。威脅模型現須納入對手利用 AI 同時加強偵察與漏洞利用階段的情況。與此同時,技術本身的雙重用途特性亦為防禦帶來可能性,包括利用 LLMs 進行高級網絡釣魚偵測及異常分析。

從業員須知

Anthropic 的發現為安全團隊指出多項即時優先事項:

  1. 內部 AI 使用審計: 部署 LLMs 提升內部效率的組織應實施管控機制,包括監察及防止其被未經授權用於開發攻擊工具或分析敏感數據。
  2. AI 增強式網絡釣魚偵測: 部署具備辨識能力的防禦性 AI 方案,以應對現時 GTGs 能大規模製造的高度複雜 AI 生成式網絡釣魚行動。
  3. 威脅模型更新: 修訂威脅模型,明確納入「AI 增強式攻擊」情境,評估對手可能如何利用生成式 AI 加速或提升針對特定環境的攻擊向量。

關於消息來源的說明

Anthropic 的披露具重要意義,但須注意該公司營運於一個塑造 AI 安全及負責任部署敘事可帶來直接聲譽及商業價值的市場。這並不代表其所描述的威脅無效——有組織對手將生成式 AI 運作化實屬具體且可觀察的現象。然而,從業員應將 Anthropic 對態勢的描述,包括其 GTG 分類法,視為來自對 AI 治理框架發展具既得利益一方的知情觀點。隨著此類對手類別日趨成熟,獨立威脅情報提供者的佐證將不可或缺。

新聞來源 / Original News Source