Anthropic Claude misuse analysis of multi-agent reconnaissance, exploitation, and exfiltration
Technical Analysis
Summary
Hide ▲
Show ▼
AI-assisted abuse around Claude has shifted from simple prompting into multi-agent automation, increasing the speed and scale of reconnaissance, exploitation, and data exfiltration across multiple threat groups. The activity spans state-backed operators, financially motivated criminals, commercial spyware vendors, propaganda networks, and politically motivated individuals. The result is a broader operational surface for credential theft, surveillance, and intrusion support.
Related Happenings
Ghostjacking AI hijacking attack using trusted logs and alerts
Technical Analysis
H score30
First: 10.08.2026 15:59
Last: 10.08.2026 15:59
Sources 1
About this happening:
Researchers demonstrated Ghostjacking, an AI hijacking technique that turns trusted logs, alerts, and agent inputs into a command channel for agentic tools, creating risk...
Ghostjacking AI hijacking attack using trusted logs and alerts
Technical AnalysisAbout this happening: Researchers demonstrated Ghostjacking, an AI hijacking technique that turns trusted logs, alerts, and agent inputs into a command channel for agentic tools, creating risk...
Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime
Threat Actor Meta
H score36
First: 20.07.2026 12:07
Last: 20.07.2026 12:07
Sources 1
About this happening:
Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-as...
Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime
Threat Actor MetaAbout this happening: Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-as...
Shadow-Aether-040 AI-augmented campaign against Mexican government entities
Campaign
H score41
First: 13.05.2026 16:00
Last: 13.05.2026 16:00
Sources 1
About this happening:
The Shadow-Aether-040 campaign used AI agents and custom tooling to compromise six government entities in Mexico, increasing the risk of follow-on intrusion and data...
Shadow-Aether-040 AI-augmented campaign against Mexican government entities
CampaignAbout this happening: The Shadow-Aether-040 campaign used AI agents and custom tooling to compromise six government entities in Mexico, increasing the risk of follow-on intrusion and data...
Google GTIG analysis of adversary AI use for exploit development and attack orchestration
Technical Analysis
H score33
First: 11.05.2026 16:00
Last: 11.05.2026 16:00
Sources 1
About this happening:
Google Threat Intelligence Group (GTIG) reported that threat actors are moving from prompt-based AI use to multi-agent frameworks that coordinate attack tasks with min...
Google GTIG analysis of adversary AI use for exploit development and attack orchestration
Technical AnalysisAbout this happening: Google Threat Intelligence Group (GTIG) reported that threat actors are moving from prompt-based AI use to multi-agent frameworks that coordinate attack tasks with min...
CL-UNK-1068 years-long espionage campaign targeting Asian organizations
Campaign
H score38
First: 09.03.2026 09:21
Last: 09.03.2026 09:21
Sources 1
About this happening:
A Chinese threat actor is linked to a years-long espionage campaign against high-value organizations in South, Southeast, and East Asia, creating persistent risk for c...
CL-UNK-1068 years-long espionage campaign targeting Asian organizations
CampaignAbout this happening: A Chinese threat actor is linked to a years-long espionage campaign against high-value organizations in South, Southeast, and East Asia, creating persistent risk for c...
Timeline
-
11.09.2026 17:29 2 articles · 2h ago
Anthropic warns Claude models are being used for cyber attacks and mass surveillance
Initial DisclosureAnthropic warned that Claude models were being used by cybercriminals and state-sponsored hackers for cyber attacks, weapons design, propaganda, and mass surveillance, and said the use of AI had gone beyond simple chatbot prompting into multi-agent frameworks executing reconnaissance, exploitation, credential harvesting, and data exfiltration.
Show sources
- Claude Used to Automate Exploitation and Data Theft Across Multiple Victims — thehackernews.com — 11.09.2026 17:29
- Claude Used to Automate Exploitation and Data Theft Across Multiple Victims — thehackernews.com — 11.09.2026 17:29