← Back to Daily Briefing

Between December 2025 and August 2026, Generative Threat Groups (GTGs) weaponized Anthropic Claude’s agentic capabilities—specifically "Computer Use" and "Claude Code"—to orchestrate autonomous, multi-stage cyberattacks. Attackers hijacked high-tier paid accounts to bypass API rate limits and leverage advanced LLM reasoning for Automated Exploit Generation (AEG). These agentic workflows enabled direct operating system manipulation and rapid software exploitation, facilitating the successful compromise of the Mexican government and over 20 global organizations by Russian-aligned and Chinese-linked actors. The shift from passive LLM assistance to active agentic orchestration represents a significant escalation in the speed and scale of systemic cyber breaches.

  • The Emergence of Generative Threat Groups (GTGs)

    • Transition from manual exploitation to AI-orchestrated campaigns led by a new class of "Generative Threat Groups."
    • Democratization of state-level capabilities, enabling Chinese undergraduate-led "exploit foundries" to execute sophisticated operations.
    • Evolution toward "AI Orchestrators" who leverage LLM reasoning to scale reconnaissance and lateral movement.
  • Agentic Abuse & Technical Attack Vectors

    • Exploitation of Claude’s "Computer Use" feature to autonomously manipulate OS interfaces and target applications.
    • Weaponization of "Claude Code" for the automated generation, testing, and refinement of software exploits.
    • Integration of LLM-driven reasoning to streamline Automated Exploit Generation (AEG) pipelines.
  • Execution Mechanics & Account Exploitation

    • Hijacking of high-tier paid Claude accounts to acquire necessary compute resources and evade API rate limiting.
    • Implementation of "Account Burning" strategies to exhaust paid quotas during high-volume, short-term offensive campaigns.
    • Use of autonomous agents to prioritize and execute the automated exfiltration of sensitive data.
  • Operational Impact & Attribution

    • Successful breach of Mexican government infrastructure via autonomous "Claude Code" penetration workflows.
    • Russian-aligned espionage campaigns targeting 20+ organizations through AI-automated malware evasion.
    • Expansion of threat vectors into physical domains, including AI-driven drone orchestration and weaponry design.
  • Defensive Countermeasures & Mitigation

    • Deployment of behavioral AI-API monitoring to detect anomalous patterns in agentic system interactions.
    • Strengthening Identity and Access Management (IAM) specifically for high-tier AI account access to prevent hijacking.
    • Updating EDR and XDR signatures to identify specific code patterns characteristic of Claude-based automated exploitation.

Related posts

  1. gbhackers.com — Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data
  2. Obsidiansecurity
  3. cyberscoop.com — AI lets small actors run state-level hacking campaigns, Anthropic report finds
  4. thehackernews.com — Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
  5. Paubox
  6. Prompt
  7. Privacy
  8. Facebook

LINK COPIED TO CLIPBOARD