Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Anthropic released the report Countering misuse of AI: September 2026 on September 10, documenting ten months of observed malicious activity from December 2025 through August 2026. The finding shaking the industry is not the presence of a new APT group, but its absence: individual actors, students, and criminal affiliates conducted offensive campaigns of sophistication and scale previously reserved for state actors. The mechanism is a closed loop of autonomous evasion, in which AI agents modify, recompile, and redeploy malware without significant human intervention. This shifts the cost of adaptation from the offensive side to the defensive side, inverting the asymmetry that has structured twenty years of cybersecurity.
- GTG-20006, a campaign attributed to Midnight Blizzard, targeted more than 20 government, defense, and intelligence organizations in Ukraine, Europe, the Middle East, and Asia
- Two Chinese university students produced more than a dozen potential zero-days in a single month using "agent swarms" with persistent campaign memory
- ShinyHunters affiliates exfiltrated 2,100 Azure access tokens across more than 40 corporate tenants in roughly 34 hours, with AI performing "almost all the work"
- A single hacktivist conducted a multi-victim campaign against European political parties using stolen API keys, an operation that a year earlier would have required "many skilled operators and specialized knowledge"
The Closed Loop That Subverts Signature Detection
The most destabilizing technical element in the report is the autonomous workflow documented in GTG-20006, the operation attributed to Midnight Blizzard. When security products detected a malware sample, AI agents autonomously initiated the modification and reconstruction process to evade existing detections. The system identified detection triggers, altered the code, recompiled, and redeployed artifacts on disposable hosting. The entire cycle required minimal human intervention, according to Anthropic's documentation and reporting by CyberScoop and The Record.
The consequence is a structural reversal. Traditionally, the defender imposed costs on the attacker by forcing them to manually rewrite tools after each detection. With the AI closed loop, adaptation latency compresses from days or weeks to hours. As The Record reports, citing the report: "AI has flipped the cost onto defenders. Previously, defenders could slow an attacker's operational tempo through deployment of a new detection. Now, at least in theory, capable adversaries can 'close the loop,' bypassing traditional security detections faster than defenders can develop and deploy them."
The Scale of "Uplift": From Students to Criminal Cartels
Anthropic introduces the term "uplift" to describe the amplification of offensive capabilities obtained through AI. The report presents three cases illustrating the spectrum of this phenomenon. The two Chinese university students ran an automated "exploit foundry," sustaining prolonged research against a major security product. In a single month, the "agent swarms" produced more than a dozen potential zero-days, with campaign memory enabling subsequent iterations without context reconstruction.
In the ShinyHunters operation, affiliates of the criminal group exfiltrated more than 2,100 Azure access tokens belonging to more than 40 corporate tenants in roughly 34 hours. According to CyberScoop, citing the report, AI "did almost all the work." The Record adds an operational detail: the transition from stolen developer token to full cloud environment control took approximately three hours. Finally, a single hacktivist conducted a multi-victim campaign against European political parties using stolen API keys, demonstrating that "a hacktivist with stolen API keys, scattered criminals, and a state espionage operator each conducted campaigns that a year ago would have required many skilled operators and specialized knowledge," as CyberScoop reports citing Anthropic.
GTG-20006: When the Novice State Operates Like the Nation-State
The most detailed campaign in the report, GTG-20006, shows how AI amplifies even already sophisticated actors. The group targeted more than 20 government, defense, and intelligence organizations in Ukraine, Europe, the Middle East, and Asia. Techniques included theft of a complete SDK for a drone vision system, with Claude used for reverse-engineering an unannounced product architecture. GTG-20006 compromised hotel Wi-Fi vendors for DNS hijacking and used headless browsers for WhatsApp account takeover.
Exfiltration included 300,000 national identity records and registry data for more than 500,000 companies from a North African government agency. Attribution to Midnight Blizzard — also known as BlueBravo, APT29, and Cozy Bear — was confirmed by three convergent sources: CyberScoop, The Record, and the Anthropic report itself, which declares consistency with existing "public reporting."
"For threat intelligence investigators, sophistication has ceased to be a reliable signal of who is behind an operation" — Anthropic report, September 2026
The Transparency Paradox: Voluntary Disclosure Versus Opaque Market
The report introduces a governance contradiction. We know about these attacks because Anthropic found and stopped them, then shared the findings. David Agranovich, formerly of the NSC, Meta, and Google, commented to The Record: "Similar to the commercial spyware industry before it — AI is lowering the barrier to entry for cyber operations and delivering what were state-level capabilities to actors who could never have built them." Agranovich added a warning about media framing: "Some press coverage will frame this report as 'Claude was used to [do something bad]' without noting that the only reason we know is because Anthropic dug and disrupted. If we don't incentivize (or require) companies to share this information, they will stop doing it."
This highlights a structural flaw. Anthropic's disclosure is the exception, not the rule. Without a mandatory regulatory framework, competing AI systems — including the seven Chinese labs documented in the report for distillation attacks, with Alibaba reaching nearly 3 million exchanges per day through more than 3,500 fraudulent accounts — have no analogous incentive for transparency.
Why It Matters
The report does not specify how many misuse cases went undetected or undisrupted by Anthropic, explicitly acknowledging the selection of the "most notable" cases. The dossier does not document specific remedial measures for GTG-20006 victims, nor does it quantify the concrete impact of the documented exfiltrations. It does not emerge whether the autonomous evasion techniques have bypassed production detection systems or only attacker-controlled test environments. The identity of the two Chinese university students is not disclosed, and no infrastructure overlaps linking the GTG-20006 actor to other groups beyond Midnight Blizzard emerge at present. The "intelligence shared with authorities" cited by the report does not specify which authorities or jurisdictions are involved.
What the report documents with certainty is sufficient to redefine the threat model. When sophistication ceases to indicate provenance, the risk perimeter expands to every organization with sensitive data, not only those of geopolitical interest. Static detection, a pillar of enterprise cybersecurity, loses effectiveness against adversaries who autonomously reconstruct their own tools. The transition to dynamic behavioral defenses becomes not an advanced strategy, but an operational necessity.
The offensive AI market is replicating the commercial spyware trajectory: democratization of capabilities in opacity, with the ecosystem discovering the threat architecture only when an operator chooses transparency.
Sources
- https://cyberscoop.com/anthropic-report-ai-enabled-cyber-attacks/
- https://therecord.media/anthropic-russia-hackers-claude
- https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html
- https://www.securityweek.com/in-other-news-injecteave-attack-sim-swapper-sentenced-glasswing-findings-review/
- https://www.anthropic.com/threat-intelligence-report-september-2026
- https://www.cisa.gov/news-events/news/cisa-releases-updated-insider-threat-guide-new-insights-mitigate-physical-and-cyber-threats
- https://podcast.securityweek.com/
Information has been verified against cited sources and updated at time of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.