Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI Exploited in Cyber Attacks Across the Globe

AI Exploited in Cyber Attacks Across the Globe

Posted on September 11, 2026 By CWS

Anthropic, an AI research company, has issued a warning about the misuse of its AI models, known as Claude, by various malicious entities. Between December 2025 and August 2026, these models have been exploited in cyber attacks, weapons design, propaganda, and mass surveillance campaigns.

The entities, labeled as Generative Threat Groups (GTGs) by Anthropic, include state-sponsored actors, financially motivated criminals, commercial spyware vendors, and politically driven individuals. The AI company highlights how the advanced capabilities of AI models have bridged the gap between well-funded state operations and independent operators.

State-Sponsored Cyber Operations

Among the highlighted cases is a Russian-sponsored threat actor, GTG-20006, linked to Midnight Blizzard, which utilized AI to enhance their cyber capabilities. Other incidents involve GTG-50014, a French-speaking operator associated with the ShinyHunters collective, which executed credential-harvesting operations on a large scale.

A Chinese-based group, GTG-10007, reportedly used Claude for reconnaissance and intrusion attempts on foreign networks and developed exploits for security products. This group targeted various sectors globally, demonstrating the broad reach and impact of AI-assisted cyber campaigns.

Commercial and Financial Exploitation

GTG-50021, a Russian and Ukrainian-speaking group, ran a fraudulent operation reselling AI access while stealing credentials. Similarly, GTG-50020 targeted AI vendors to steal API keys, showcasing the financial motivations driving some of these operations.

Furthermore, GTG-50029 exploited vulnerabilities in European political organizations and media outlets, highlighting the wide-ranging targets of these threat actors. This group also developed a doxxing platform to cross-reference breached data.

Influence and Surveillance Campaigns

Anthropic has also identified numerous influence and surveillance campaigns utilizing Claude. These include GTG-04001, which engaged in information manipulation in the Central African Republic, and GTG-54002, linked to a commercial influence operation rewriting political content.

Other significant operations include GTG-54006 in Bangladesh, which promoted political narratives, and GTG-84006, which targeted Iranian audiences. These campaigns underline the potential of AI models to amplify influence operations at scale.

An alarming aspect is the misuse of AI in surveillance operations, such as GTG-30005, which developed intelligence-gathering capabilities targeting U.S. naval forces.

Conclusion

Anthropic’s findings reveal the extensive misuse of AI models in cyber operations worldwide. The company’s efforts to neutralize some of these threats highlight the ongoing challenges in ensuring the safe deployment of AI technologies. As AI continues to evolve, it is crucial for stakeholders to remain vigilant and implement necessary safeguards to prevent exploitation.

The Hacker News Tags:AI, Anthropic, Claude, cyber attacks, Cybersecurity, data theft, GTGs, influence operations, state-sponsored, Surveillance

Post navigation

Previous Post: Ukrainian Hacker Sentenced for Role in Conti Ransomware
Next Post: AI-Driven Exploits Target PaperCut Vulnerabilities

Related Posts

Vercel’s v0 AI Tool Weaponized by Cybercriminals to Rapidly Create Fake Login Pages at Scale Vercel’s v0 AI Tool Weaponized by Cybercriminals to Rapidly Create Fake Login Pages at Scale The Hacker News
Rise of AI-Powered Cyber Threats Shifts Security Landscape Rise of AI-Powered Cyber Threats Shifts Security Landscape The Hacker News
F5 Fixes Critical NGINX Vulnerabilities Allowing Code Execution F5 Fixes Critical NGINX Vulnerabilities Allowing Code Execution The Hacker News
Wiz Uncovers Critical Access Bypass Flaw in AI-Powered Vibe Coding Platform Base44 Wiz Uncovers Critical Access Bypass Flaw in AI-Powered Vibe Coding Platform Base44 The Hacker News
New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status The Hacker News
Microsoft Alerts on Active Exploitation of Defender Vulnerabilities Microsoft Alerts on Active Exploitation of Defender Vulnerabilities The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • KATARU IoT Malware: Linux Exploits and DDoS Tactics
  • GitLab Patch Targeted by Attackers Within 24 Hours
  • Russian Hackers Exploit AI to Revamp Undetected Malware
  • GuardBreaker Threatens AI Malware Analysis Security
  • AI-Driven Exploits Target PaperCut Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • KATARU IoT Malware: Linux Exploits and DDoS Tactics
  • GitLab Patch Targeted by Attackers Within 24 Hours
  • Russian Hackers Exploit AI to Revamp Undetected Malware
  • GuardBreaker Threatens AI Malware Analysis Security
  • AI-Driven Exploits Target PaperCut Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark