01 / 16
OVERVIEW · 概览
Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity. In this report, we share case studies from those operations and describe how malicious use of Claude has evolved since our previous threat reports in March, August, and November 2025. In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate.
This report covers activity we disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Claude Haiku, Sonnet, and Opus models were used. None of the misuse cases involved the use of Claude Fable or Mythos-class models, with the exception of one illicit distillation case.
中文翻译
过去八个月里,我们的威胁情报团队识别并处置了一系列行动,其中威胁行为体试图利用 Claude 从事恶意活动。在本报告中,我们分享这些行动中的案例研究,并描述自我们 2025 年 3 月、8 月和 11 月的前几期威胁报告以来,Claude 被恶意使用的方式发生了怎样的演变。在每一起案例中,我们都处置了相关活动,用获取的经验加强自身防护措施,并在适当情况下与主管部门及行业伙伴共享情报。
本报告涵盖 2025 年 12 月至 2026 年 8 月间我们处置的活动,横跨七类危害:网络行动、影响力行动、监控、诈骗与欺诈、生物滥用、常规武器开发,以及蒸馏。过程中被使用的是 Claude Haiku、Sonnet 和 Opus 模型。除了一起非法蒸馏案例之外,没有任何滥用案例涉及 Claude Fable 或 Mythos 级模型。
02 / 16
OVERVIEW · 概览
The cases we share here aren't typical misuse, but rather examples of the most notable and novel threat activity we've identified to date. We're publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society's defenders act to make them safer.
The threat actors covered in this report include suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals. The cases range from a network of fake dating apps designed to defraud users to surveillance systems built to identify and monitor dissidents.
中文翻译
我们在此分享的案例并非典型滥用,而是我们迄今识别出的最具代表性和最新颖的威胁活动样本。我们公开这项工作,是因为我们认为有责任披露对我们服务的恶意滥用。随着模型能力不断增强,其风险也会上升——除非 AI 开发者与社会的防御者采取行动,让它们变得更安全。
本报告涉及的威胁行为体包括:疑似国家支持的组织、以经济利益为动机的犯罪者、商业间谍软件供应商、国家宣传机构,以及有政治动机的个人。案例范围从用于诈骗用户的虚假交友应用网络,到为识别和监视异见者而搭建的监控系统。
03 / 16
CYBER OPERATIONS · 网络行动
Cyber operations: From assistant to orchestrator
Over the past six months, our Threat Intelligence team identified and disrupted a series of cyber operations in which threat actors used Claude. The actors included suspected state-sponsored groups, financially motivated criminals, and politically motivated individuals.
Throughout these case studies, the report will reference Generative Threat Groups (GTGs). These are Anthropic's internal designators for actors observed to be abusing AI. The report also attempts to measure uplift, a term we use to describe the AI capability boost, or how much more harm was caused with AI versus without AI.
Many commentators focus on the risk of AI developing exploits at scale. While this is a danger, the risk from AI adoption is more pronounced across the cyber kill chain, where adversaries can operate faster, across a broader and deeper surface area, with fewer resources.
中文翻译
网络行动:从"助手"到"编排者"
过去六个月里,我们的威胁情报团队识别并处置了一系列威胁行为体使用 Claude 的网络行动。这些行为体包括疑似国家支持的组织、以经济利益为动机的犯罪者,以及有政治动机的个人。
在以下案例研究中,报告会引用"生成式威胁组织"(Generative Threat Groups,GTG)——这是 Anthropic 对被观察到滥用 AI 的行为体所使用的内部编号。报告还试图衡量"能力增益"(uplift),即我们用来描述 AI 所带来能力提升的术语,或者说"有 AI 相比没有 AI 多造成了多少危害"。我们从速度、规模和深度三个维度审视这种增益。
许多评论者关注的是"AI 能规模化开发漏洞利用"这一风险。这确实是一种危险,但采用 AI 所带来的风险,在网络杀伤链(cyber kill chain)的各个环节更为突出——攻击者可以以更快的速度、在更广更深的攻击面上、用更少的资源开展行动。
04 / 16
CYBER OPERATIONS · 趋势
Sophisticated attacks no longer require sophisticated attackers
The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators. In the case studies we report below, a hacktivist using stolen API keys, disparate financially motivated individuals, and a state espionage operator each sustained multi-victim campaigns that, even just a year ago, would have required many skilled operators and specialist knowledge.
For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation. Every layer of offensive operations has been uplifted by AI, from reconnaissance and tool development to data processing and exploitation. Publicly available offensive agent frameworks, like PentAGI, reproduce much of the same scaffolding for anyone who downloads them. This scaffolding effectively automates each step of the cyber kill chain.
中文翻译
高水平攻击不再需要高水平的攻击者
AI 模型所具备的网络安全技能,意味着 AI 已经抹平了此前把"资源雄厚的国家支持行动"与"个人操作者"区分开来的劳力与工具差距。在下方我们报告的案例研究中,一名使用窃取 API 密钥的黑客活动者、若干彼此分散的经济动机犯罪者,以及一名国家间谍操作者,各自都维持了多受害者的攻击行动——而这些行动即便在一年前,也需要众多熟练操作者和专业知识才能完成。
对威胁情报调查人员而言,"技术水平高低"已经不再是判断幕后主体的可靠信号。进攻性行动的每一层——从侦察、工具开发,到数据处理与漏洞利用——都被 AI 提升了。公开可得的进攻型代理框架(例如 PentAGI)把大部分同样的脚手架复刻出来,供任何人下载。这套脚手架实际上自动化了网络杀伤链的每一步。
05 / 16
CYBER OPERATIONS · 个案 GTG-20006
GTG-20006: Russian espionage
Historically, cyber espionage actors have followed a pattern of developing and deploying custom toolkits designed to evade detections. Actors would use these tools until defenders identified and built signatures to detect and block them, and there would then begin a new cycle of evasion and detection. Robust defenses and detections therefore created increased costs for adversaries. Now, however, the adoption of AI threatens to quickly and easily subvert defenders' ability to impose costs on adversaries via static detections alone.
GTG-20006 is an actor who has increased their speed by automating their operations using AI. Our attribution is consistent with public reporting linking the actor to Midnight Blizzard.
The actor also used AI to monitor how well their tools evaded detections from known security defenses. If their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections.
中文翻译
GTG-20006:俄罗斯间谍活动
历史上,网络间谍行为体一直遵循这样一套模式:开发并部署用于规避检测的定制工具集,一直使用到防御方识别并构建特征签名将其检测、拦截为止,随后又开始新一轮的规避与检测博弈。因此,强健的防御和检测会推高对手的成本。然而如今,AI 的采用有可能迅速而轻易地瓦解防御方"仅靠静态检测就向对手施加成本"的能力。
GTG-20006 是一个通过用 AI 自动化其行动来提升速度的行为体。我们的归因,与将该行为体关联到 Midnight Blizzard 的公开报道相一致。
该行为体还用 AI 来监控其工具规避已知安全防御的效果。如果其用于监控的 AI 代理发现,所部署的任一恶意软件被某款安全产品检测到,这些代理便会着手自动化地修改并重建该恶意软件,以规避现有的检测。
06 / 16
INFLUENCE OPERATIONS · 影响力行动
Influence operations are neither new nor unique to the internet. An established community of journalists, researchers, and government agencies has studied these tactics, exposed them, and built the frameworks we use to understand them.
However, while a social media site usually sees an operation once its content is already circulating, we may see it on Claude while the operation is still being built. Actors use AI to plan their campaign, choose their targets, and write the material. Those types of tasks produce signals that our systems are trained to detect, which often lets us disrupt an operation before it gets off the ground.
Our visibility into these operations ends once it's live. To verify our findings and understand what happened after content left our platform, we rely on open-source research, cross-platform industry data, and public reporting.
中文翻译
影响力行动既不是新事物,也不是互联网独有的产物。一个由记者、研究人员和政府机构构成的成熟群体,长期研究这些手法、揭露它们,并建立了我们用来理解它们的框架。
然而,社交媒体平台通常是在内容已经开始传播之后才看到某个行动,而我们可能在行动仍在搭建阶段时就通过 Claude 观察到它。行为体用 AI 来策划行动、选择目标、撰写材料。这类任务会产生我们系统被训练去检测的信号,这往往让我们能够在行动真正展开之前就将其处置。
一旦行动进入实际传播,我们对它的可见性就结束了。为了核实我们的发现、并理解内容离开我们平台之后发生了什么,我们依赖开源研究、跨平台的行业数据以及公开报道。
07 / 16
INFLUENCE OPERATIONS · 衡量与趋势
How we measure reach: To accurately evaluate the impact of each influence operation, we apply the Breakout Scale, a six-category framework widely accepted by industry researchers. The scale categorizes impact based on cross-platform migration and reach. Category One represents content that is confined to a single community on a single platform, while Categories Two through Six measure increasingly higher levels of public exposure and distribution.
Trends in influence operations
• Influence sold as a service. ... commercial actors hired by entities (political, government, et cetera) produce content for whoever wishes to pay. This gives plausible deniability to the ultimate commissioners of the influence operations, and puts this capability within reach of actors who can't or do not want to build it themselves.
• AI as a newsdesk. In several cases, Claude was slotted into a human-edited pipeline that was already up and running, playing the role of a sub-editor or content creator. This allowed low-resourced actors to run influence operations at a scale well beyond what they could accomplish alone.
中文翻译
我们如何衡量触达:为准确评估每一次影响力行动的影响,我们采用"突围量表"(Breakout Scale)——一个被行业研究者广泛接受的六类框架。该量表依据跨平台迁移与触达范围来划分影响程度。第一类指局限于单一平台、单一社群的内容;第二至第六类则衡量逐级升高的公众曝光与传播水平。
影响力行动的趋势
• 影响力被当作服务出售。……由实体(政治、政府等)雇佣的商业行为体,为任何愿意付费者生产内容。这为影响力行动的最终委托方提供了"合理推诿"的空间,也使得这一能力触手可及——即使那些自身无力或不愿自行搭建该能力的行动者也能使用。
• AI 作为"新闻编辑部"。在若干案例中,Claude 被嵌入到一个本已运转、由人编辑的流程中,扮演副编辑或内容创作者的角色。这让资源匮乏的行为体,得以以远超其自身能力的规模开展影响力行动。
08 / 16
SURVEILLANCE · 监控
AI-enabled surveillance operations
Between January and July of this year, we identified and disrupted a set of operations in which state-aligned actors, state-linked contractors, and commercial spyware vendors used Claude to build, run, and otherwise facilitate surveillance operations. These cases include threat actors from China, Iran, and West Africa, as well as the commercial "surveillance-for-hire" market, and range from operations carried out by a single individual to entire teams.
First, AI is now being used in place of an engineering workforce. A single consultant working for Malian national security authorities used Claude to engineer a mass-interception platform capable of surveilling communications on all of the country's mobile operators and generating dossiers on targets. In this case, Claude was not used to analyze the surveillance dossiers but to design the underlying software that enabled the intelligence gathering.
中文翻译
AI 赋能的监控行动
今年 1 月至 7 月间,我们识别并处置了一系列行动,其中与国家立场一致的行为体、与国家有关联的承包商,以及商业间谍软件供应商,使用 Claude 搭建、运行或以其他方式推动监控行动。这些案例包括来自中国、伊朗和西非的威胁行为体,以及商业化的"监控外包"市场;规模从由个人单独实施,到由整个团队实施不等。
第一,AI 如今正被用来替代一支工程队伍。一名为马里国家安全部门工作的顾问,独自使用 Claude 设计出一个大规模监听平台,能够监控该国所有移动运营商的通信,并生成针对目标的档案。在此案例中,Claude 并非用于分析监控档案,而是用于设计支撑这套情报搜集的底层软件。
09 / 16
SURVEILLANCE · 趋势二、三
Second, AI is being used not only to build tools but to ingest data in bulk to identify targets. In one case, an actor uploaded batches of social media posts and directed Claude to produce structured records that outlined targets' locations, demographic data, and political leanings, along with confidence scores. Similarly, an Iranian unit used Claude to analyze hundreds of thousands of social media posts and selected 39 opposition accounts to monitor.
Third, AI is being fully integrated into states' security bureaucracy. One PRC state security bureau used Claude to produce an internal manual on how to use AI in surveillance operations, suggesting that AI models are being deeply integrated into the daily work of state actors.
中文翻译
第二,AI 不仅被用于搭建工具,也被用于批量摄取数据以识别目标。在其中一个案例里,某行为体上传了成批的社交媒体帖子,并指示 Claude 产出结构化记录,勾勒出目标的位置、人口统计数据和政治倾向,并附带置信度评分。类似地,一个伊朗单位用 Claude 分析了数十万条社交媒体帖子,并挑选出 39 个反对派账号加以监控。
第三,AI 正被全面整合进国家的安全官僚体系。中国某国家安全局使用 Claude 制作了一份关于如何在监控行动中使用 AI 的内部手册,这表明 AI 模型正被深度嵌入国家行为体的日常工作。
10 / 16
CONVENTIONAL WEAPONS · 常规武器
Conventional weapons — Detecting and countering the use of Claude in conventional weapons activity
Since publishing our last threat report in November 2025, we have identified new categories of threat actors misusing Claude in violation of our Usage Policy and terms of service. One of these is the use of Claude to develop software for conventional weapons, including firearms, missiles, armed drones, bombs, and other munitions, as well as the targeting and control systems that operate them.
Over the past year, our threat intelligence teams have investigated and disrupted multiple threat actors who used Claude to develop software for weapons design and development, or to support the intelligence gathering and procurement that weapons programs depend on. In this report, we share details on six of these cases: three in China, two in Russia, and one in Yemen.
中文翻译
常规武器——侦测与反制 Claude 在常规武器活动中的使用
自 2025 年 11 月发布上一期威胁报告以来,我们识别出新的威胁行为体类别:它们违反我们的使用政策和服务条款,滥用 Claude。其中之一,就是用 Claude 为常规武器开发软件,包括枪械、导弹、武装无人机、炸弹及其他弹药,以及用于操作这些武器的瞄准与控制系统。
过去一年,我们的威胁情报团队调查并处置了多个威胁行为体,它们用 Claude 为武器设计与开发编写软件,或用来支持武器项目所依赖的情报搜集与采购。本报告分享了其中六起案例的细节:三起在中国、两起在俄罗斯、一起在也门。
11 / 16
CONVENTIONAL WEAPONS · 个案 GTG-17001
GTG-17001: Disrupting a China-based operation using Claude to draft a fire control specification and acquisition documents for undersea warfare
We identified a China-based threat actor who used Claude to advance three parallel tracks of work on an anti-torpedo weapons system:
• First, the actor used Claude to draft a Chinese-language specification for an anti-torpedo fire control system (the core logic that aims and times an anti-torpedo weapon's response). The document was written to win approval from a Chinese defense manufacturer, which would move the work on to technical certification and operational testing.
• Second, the actor used Claude to produce a Chinese-language technical proposal of more than 200 pages, accompanied by an executive briefing deck.
We assess the actor was associated with a Chinese defense industry manufacturer aiming to produce a weapons specification and acquisition proposal for the People's Liberation Army Navy. ... We cannot attribute the activity to a specific entity or actor.
中文翻译
GTG-17001:处置一起中国境内行动——利用 Claude 起草水下作战的火控规格与采购文件
我们识别出一个中国境内的威胁行为体,它利用 Claude 推进一个反鱼雷武器系统的三条并行工作线:
• 第一,该行为体用 Claude 起草了一份中文的"反鱼雷火控系统"规格书(即用于瞄准、并为反鱼雷武器响应计时的核心逻辑)。这份文件的目的是获得某中国国防制造商的批准,从而将该项目推进到技术认证与作战测试阶段。
• 第二,该行为体用 Claude 制作了一份 200 多页的中文技术方案,并配有一份高管汇报演示文稿。
我们评估,该行为体与一家中国国防工业企业有关联,其目标是面向中国人民解放军海军产出武器规格与采购方案。……我们无法将这一活动归因到某个具体实体或行为体。
12 / 16
BIOLOGICAL MISUSE · 生物滥用
Biological misuse is one of the most serious risks of frontier AI models. It has long been a concern that AI models might one day reach the level of capability where they can help to make existing pathogens more dangerous—or create entirely new ones. Without the correct safeguards, such capabilities could have catastrophic consequences.
Results from evaluations of older models (for example Claude Opus 4 and Claude Sonnet 4.5, from 2025) clearly showed that these models were well below the threshold where they could meaningfully assist a sophisticated user in carrying out dangerous biological research. ... But for today's models—which are capable of assisting in a range of complex scientific research tasks—the evidence is no longer certain, and we cannot make that same assurance.
中文翻译
生物滥用是前沿 AI 模型最严重的风险之一。长期以来一直有人担心,AI 模型或许有朝一日会达到某种能力水平,能够帮助把现有病原体变得更具危险性——甚至创造出全新的病原体。若缺乏正确的防护措施,这类能力可能带来灾难性后果。
对较早模型(例如 2025 年的 Claude Opus 4 与 Claude Sonnet 4.5)的评估结果清楚显示,这些模型远低于"能够实质性协助一名老练用户开展危险生物学研究"的门槛。……但对今天的模型——它们能够协助一系列复杂的科研任务——证据已不再确定,我们无法再作出同样的保证。
13 / 16
BIOLOGICAL MISUSE · 五起案例
Here, we present five case studies of actors using our models in ways that could support biological weapons development. ... In the first example, a reseller platform evaded regional blocks to serve virologists working on a state-sponsored grant to pursue chikungunya gain-of-function work. In the second, a researcher in an unsupported region spent weeks planning avian influenza mammalian-adaptation experiments with Claude, but classifiers confined the work to our weakest models. ... And in the final case study, a researcher computationally redesigned toxins for a national program, asking Claude to keep the agents' identities deliberately vague in progress reports.
We are withholding the names of research institutions, the countries wherein the activity took place, and the specific biological agents or research techniques involved. The individuals implicated in these case studies are working scientists. We do not assert that they intended harm, and identifying them or their labs could expose them to harm.
中文翻译
在此,我们呈现五起案例研究,涉及行为体以可能支持生物武器研发的方式使用我们的模型。……在第一个例子中,一个转售平台绕过了区域封锁,为正在从事一项国家资助的基孔肯雅病毒(chikungunya)功能增益研究的病毒学家提供服务。在第二个例子中,一名身处不受支持地区的研究者,用 Claude 花了数周时间筹划禽流感哺乳动物适应实验,但分类器将该工作限制在我们能力最弱的模型上。……在最后一个案例中,一名研究者为一个国家项目用计算方式重新设计了毒素,并要求 Claude 在进展报告中刻意模糊这些制剂的身份。
我们隐去了研究机构的名称、活动发生所在的国家,以及所涉及的具体生物制剂或研究技术。这些案例中涉及的个人是在职科学家。我们并不断言他们意图造成伤害,而识别他们或其实验室,可能使他们遭受伤害。
14 / 16
SCAMS AND FRAUD · 诈骗与欺诈
GTG-15001: Deceptive dating app network
GTG-15001 reflects the reach and the limitations of existing AI models for fraud and scam activity. A China-based app studio used Claude to both build a network of over 20 dating apps and power the AI personas used to converse with users—despite advertising their service as fully human. Over a two-week window in April 2026, we discovered more than 4,700 distinct AI personas that engaged in conversations with at least 25,000 unique individuals.
The studio also recruited real people and mixed them into the same match feed as the bots. These people were primarily included for authenticity checks (live video calls and social media follows) to decrease skepticism by the scam's victims.
中文翻译
GTG-15001:虚假交友应用网络
GTG-15001 既体现了现有 AI 模型在欺诈与诈骗活动中的触达范围,也暴露了其局限。一家中国境内的应用工作室用 Claude 既搭建了一个包含 20 多款交友应用的网络,又驱动用于与用户对话的 AI 人设——尽管其对外的宣传是"完全由真人服务"。在 2026 年 4 月为期两周的窗口内,我们发现 4,700 多个不同的 AI 人设,与至少 25,000 名不同的个人进行了对话。
该工作室还招募真人,把他们与机器人混入同一个匹配信息流中。这些人主要被用于通过真实性核验(实时视频通话、关注社交媒体账号),以降低诈骗受害者的疑虑。
15 / 16
ILLICIT DISTILLATION · 非法蒸馏
Since we published our first disclosure in February, we have identified and disrupted additional distillation attacks against Claude from seven labs based in China.
What is illicit distillation?
Distillation itself is a legitimate training method. Researchers use a larger, more capable "teacher" model to generate responses to a set of inputs, then use those exchanges to train a smaller "student" model to mimic the teacher. Distillation is commonly used because it reduces the resources needed to achieve more advanced capabilities.
We define illicit distillation as an industrial-scale, covert campaign to extract a model's capabilities and replicate them in another model without authorization. Illicit distillation is typically enabled by fraud: sophisticated networks of fake accounts created with stolen credit cards, login credentials, and API keys.
中文翻译
自我们于 2 月首次披露以来,我们又识别并处置了来自七家中国实验室、针对 Claude 的更多蒸馏攻击。
什么是非法蒸馏?
蒸馏本身是一种合法的训练方法。研究者用一个更大、能力更强的"教师"模型对一组输入生成回答,再用这些交互去训练一个更小的"学生"模型来模仿教师。蒸馏之所以被普遍使用,是因为它能降低达到更高级能力所需的资源。
我们把非法蒸馏定义为:一场工业规模的、隐蔽的行动——在未经授权的情况下提取某个模型的能力,并将其复制到另一个模型中。非法蒸馏通常依靠欺诈来实现:用盗取的信用卡、登录凭证和 API 密钥,搭建起复杂精密的虚假账号网络。
16 / 16
ILLICIT DISTILLATION · 个案与隐私
Operators affiliated with Alibaba ran the largest distillation attack we have ever [measured]. ... Alibaba's illicit distillation campaign peaked at nearly 3 million exchanges per day ... Scale of distillation attacks attributable to Alibaba between May and July 2026: over 151 million.
Additionally, these findings raise concerns about the misuse of user data by PRC AI labs. DeepSeek, Xiaomi, and Moonshot fed conversations between their own models and users into Claude. These labs then used Claude's responses as training data with which to distill Claude's capabilities. Some of these exchanges included sensitive information ... These practices are likely inconsistent with privacy laws and the labs' own terms of service.
中文翻译
与阿里巴巴有关联的操作者,实施了迄今我们测得的最大规模的蒸馏攻击。……阿里巴巴的非法蒸馏行动峰值接近每天 300 万次交互……2026 年 5 月至 7 月间可归因于阿里巴巴的蒸馏攻击规模:超过 1.51 亿次(交互)。
此外,这些发现引发了对中国 AI 实验室滥用用户数据的担忧。DeepSeek、小米和月之暗面(Moonshot)把各自模型与用户之间的对话送入 Claude,随后将 Claude 的回复用作训练数据,以蒸馏 Claude 的能力。其中一些交互包含敏感信息……这些做法很可能违反隐私法律,以及这些实验室自身的服务条款。