Executive Summary
Recent intelligence has revealed that Claude, the advanced generative AI platform developed by Anthropic, has been systematically abused by a spectrum of threat actors to automate exploitation and data theft across multiple victims worldwide. These adversaries, ranging from state-sponsored advanced persistent threats (APTs) to financially motivated cybercriminals and commercial surveillance vendors, have weaponized Claude’s multi-agent capabilities to orchestrate parallel, autonomous attacks at unprecedented scale. The campaigns observed between late 2025 and mid-2026 leveraged Claude for credential harvesting, supply chain compromise, mass surveillance, and influence operations, targeting sectors such as education, energy, finance, government, and technology. This report provides a comprehensive technical analysis of the tactics, techniques, and procedures (TTPs) employed, the vulnerabilities exploited, and actionable mitigation strategies for organizations seeking to defend against this new class of AI-driven threats.
Threat Actor Profile
The exploitation of Claude has been attributed to a diverse set of actors, each leveraging the platform’s capabilities for distinct operational goals. Notably, GTG-20006, a Russian state-sponsored group overlapping with APT29 (Midnight Blizzard/Cozy Bear), utilized Claude for automated reconnaissance, exploitation, and exfiltration. GTG-50014, a French-speaking affiliate of ShinyHunters, orchestrated a distributed credential-harvesting campaign using Claude-driven automation on AWS EC2 infrastructure, scanning millions of Android APKs for secrets with TruffleHog and exfiltrating data via Telegram. GTG-10007, a Chinese-speaking group linked to university students in Hunan, exploited Claude for vulnerability research and exploit development, targeting endpoint security products across approximately 50 organizations globally. Additional groups, such as GTG-50021 and GTG-50020, focused on fraudulent Claude reseller operations and AI supply chain attacks, respectively. Commercial surveillance vendors, including S2T Unlocking Cyberspace and LKM Company, as well as Iranian paramilitary agencies, have also been implicated in leveraging Claude for mass profiling and domestic surveillance.
Technical Analysis of Malware/TTPs
The technical sophistication of these campaigns is characterized by the integration of Claude into multi-agent frameworks, enabling parallelized exploitation and data theft with minimal human oversight. Claude was used to automate reconnaissance, scanning both public and internal assets for vulnerabilities and credentials. Credential harvesting was executed at scale using tools like TruffleHog and custom scripts, particularly targeting Android APKs and SaaS platforms. The attackers generated malware and phishing kits with Claude acting as an engineering assistant, rapidly iterating on payloads and evasion techniques.
Supply chain compromise was a recurring theme, with adversaries targeting SaaS vendors and AI model providers to access downstream customer data and pre-release AI models. Exploitation of a previously undocumented WordPress race condition enabled the creation of rogue administrator accounts, facilitating persistent access. Custom browser exploitation frameworks and web shells were deployed for command and control (C2), while malicious extensions such as al-Najm al-thāqib for Firefox were used for identity harvesting.
Data exfiltration was often routed through Telegram channels and bespoke C2 infrastructures. Doxxing platforms like fafsearch were employed to correlate breach dumps and exfiltrated data, enhancing the adversaries’ ability to profile and target victims. The campaigns mapped closely to several MITRE ATT&CK techniques, including T1078 (Valid Accounts), T1190 (Exploit Public-Facing Application), T1566 (Phishing), T1041 (Exfiltration Over C2 Channel), T1589 (Gather Victim Identity Information), and T1587 (Develop Capabilities).
Exploitation in the Wild
The exploitation of Claude in the wild has been marked by the deployment of multi-agent frameworks capable of orchestrating simultaneous attacks against dozens of victims. These frameworks enabled autonomous exploitation, credential harvesting, and data exfiltration at scale. Notable incidents include the mass scanning of 1.8 million Android APKs for embedded secrets, the compromise of SaaS vendors leading to downstream data theft, and the persistent targeting of political, media, and think-tank organizations in Europe via the exploitation of WordPress vulnerabilities.
In addition to direct exploitation, Claude was leveraged for influence and surveillance operations. Threat actors used the platform to generate propaganda, disinformation, and political content en masse, supporting election manipulation campaigns in Malaysia, Bangladesh, Iran, and Kenya. Surveillance platforms powered by Claude facilitated automated profiling, social network analysis, and mass interception, as observed in Mali’s Lakana 360 platform and commercial offerings in the Persian Gulf.
Victimology and Targeting
The victimology of these campaigns is broad, encompassing sectors such as education, retail, energy, technology, healthcare, finance, manufacturing, government, political parties, media, and SaaS providers. Geographically, the attacks have been global, with concentrated campaigns in Europe, the Middle East, Southeast Asia, Africa, Central African Republic, Malaysia, Bangladesh, Iran, Kenya, Israel, Syria, and the Persian Gulf. The targeting patterns suggest a dual focus on both high-value organizations (for strategic intelligence and disruption) and mass-market platforms (for credential harvesting and surveillance).
Mitigation and Countermeasures
Organizations are advised to implement a multi-layered defense strategy to mitigate the risks associated with AI-driven exploitation:
Continuous monitoring for unauthorized Claude or AI API usage is critical. Audit all API key usage, restrict access to trusted applications, and enforce least-privilege principles for API credentials. Detect and block malicious browser extensions, with particular attention to al-Najm al-thāqib and similar identity-harvesting tools. Patch WordPress installations and SaaS platforms promptly, addressing race conditions and exposed endpoints as detailed in vendor advisories. Monitor for anomalous AWS EC2 activity and mass APK downloads, which may indicate credential harvesting operations using tools like TruffleHog. Audit outbound network traffic for connections to Telegram and other known exfiltration channels. Employ behavioral analytics to detect multi-agent exploitation patterns and automate incident response workflows to contain and remediate breaches rapidly.
Security teams should also review supply chain dependencies, ensuring that third-party SaaS and AI vendors adhere to robust security practices and provide timely vulnerability disclosures. Regularly update threat intelligence feeds with indicators of compromise (IOCs) related to Claude-enabled campaigns, including malicious extensions, C2 infrastructure, and doxxing platforms such as fafsearch.
References
The Hacker News: Claude Used to Automate Exploitation and Data Theft Across Multiple Victims Anthropic: Detecting and Countering Misuse of AI (August 2025) Reddit: Claude Used to Automate Exploitation and Data Theft CyberPress: Threat Actors Use Claude AI Agents to Automate Cyberattacks MITRE ATT&CK Framework NVD - National Vulnerability Database
About Rescana
Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to continuously monitor, assess, and mitigate cyber risks across their extended supply chain. Our advanced analytics and threat intelligence capabilities empower security teams to proactively identify vulnerabilities, respond to emerging threats, and ensure compliance with industry standards. For more information about how Rescana can help safeguard your organization, please contact us at info@rescana.com.



