Back Home

AI 安全/威脅情報

Anthropic Reveals Attackers Use Agents to Continuously Rewrite Malware, Letting One Person Target Dozens in Parallel

Anthropic’s new threat report shows that several types of attackers have upgraded Claude from a coding assistant into a schedulable attack-orchestration layer with persistent memory. Some workflows automatically modify, rebuild, and redeploy malware after detection, although humans still largely control target selection and the review of stolen data.

البرمجية: كلود لقطة الشاشة: أنون · Public domain · Image source
zh-Hant

Anthropic released a [threat intelligence report](https://www.anthropic.com/threat-intelligence-report-september-2026) on September 10 covering activities disrupted between December 2025 and August 2026. Rather than merely asking a model to write phishing emails or scripts, attackers in the new cases built persistent agentic workflows: multiple agents divide up reconnaissance, vulnerability testing, infrastructure provisioning, intrusion, data processing, and exfiltration, while preserving targets, credentials, and progress for subsequent sessions.

Anthropic said GTG‑20006, whose characteristics are consistent with Russian state-sponsored activity, uses agents to monitor whether security products block its tools. Once detected, the workflow automatically modifies, rebuilds, and redeploys the malware until it evades existing detection. Scheduled jobs also refresh stolen access tokens and collect data from cloud storage. Another group, GTG‑10007, uses parallel agents for intrusions, reconnaissance against foreign governments, reverse engineering of cybersecurity products, and vulnerability research. The report concludes that some intrusions were completed within two to three hours, while a single operator could handle dozens of victims simultaneously.

This means defenders can no longer treat tooling complexity as a direct attribution signal for state-sponsored actors, nor can they rely solely on static malware signatures to raise adversaries’ costs. More effective observables will shift toward infrastructure shared by agents, automated registration and update behavior, anomalous API token rotation, and consistent task trajectories across targets. Some cases also have external corroborating evidence: [*Le Monde*](https://www.lemonde.fr/en/politics/article/2026/09/11/anthropic-reveals-hacker-used-claude-to-target-french-far-right-organizations_6757429_5.html) reported that another attacker using Claude compromised at least 14 of 42 tracked targets and exfiltrated approximately 12–26 GB of data.

However, Anthropic did not publish enough raw records to fully reconstruct each workflow, and its classifications, attributions, and claims of AI-enabled “uplift” rely primarily on the platform’s telemetry. The report also explicitly states that humans still choose targets, determine monetization strategies, and inspect exfiltrated data. Greater autonomy changes cost and scale, but it should not be equated directly with the severity of harm or with fully autonomous attacks.

Sources

  1. Detecting and countering misuse of AI: September 2026
  2. Anthropic reveals hacker used Claude to target French far-right organizations