Artificial intelligence (AI) is transforming malicious activity, shifting from being merely a tool for bad actors to becoming an integral part of operational machinery across various attack chains. This is the central finding of a recent threat intelligence report from Anthropic, covering activity identified and disrupted between December 2025 and August 2026. The report highlights AI's role in cyber operations, influence campaigns, surveillance, fraud, biological research, conventional weapons development, and attempts to extract capabilities from frontier AI models.
The report notes that AI is not necessarily introducing new attack techniques but is fundamentally altering the economics, speed, and scale of malicious operations. AI systems are now contributing across nearly the entire attack chain, from reconnaissance and tool development to exploitation, credential theft, data processing, and exfiltration. Anthropic observed instances where AI executed commands against victim networks, harvested credentials, and exfiltrated information. In more autonomous scenarios, multi-agent frameworks conducted reconnaissance, exploitation, and data theft against multiple targets simultaneously, sometimes for extended periods with minimal human intervention.
This operational shift means that sophisticated attacks no longer exclusively require sophisticated attackers. AI is narrowing the gap between well-funded state operations and smaller criminal groups by automating tasks that previously demanded multiple specialists, such as reconnaissance, exploitation, coding, and data analysis. While underlying attack methods like stolen credentials, exposed services, vulnerable edge devices, phishing, and SQL injection remain prevalent, AI significantly reduces the cost of orchestrating these at scale.
One clear example cited in the report involves a financially motivated operation that harvested credentials from software and online services. Attackers downloaded and analyzed 1.8 million Android application packages (APKs) to find hardcoded secrets, while simultaneously collecting GitHub-related credentials. This operation, attributed to a French-speaking operator using aliases such as MeowSHA, frkoo, and blazespider, utilized a distributed credential-harvesting pipeline across 10 AWS EC2 workers. This pipeline mass-downloaded, decompiled, and scanned Android APKs from various app stores using TruffleHog. Verified findings were routed in real time to a Telegram group, and a parallel GitHub email harvester fed a second stream of stolen GitHub Personal Access Tokens. These two credential pipelines supplied initial access for confirmed breaches linked to frkoo.
Anthropic confirmed that its Claude AI model was used by attackers to engineer and test tooling for such operations. The report details how stolen tokens were replayed against Microsoft services to access mailbox contents, including deleted messages, with techniques designed to mimic legitimate Microsoft client traffic. The significance lies not in AI inventing new attacks, but in its ability to automate existing processes, enabling smaller teams to conduct operations that previously required a much larger workforce.
Beyond cybercrime, the report also details the use of AI in surveillance. Anthropic identified nation-state actors and commercial surveillance operators using Claude to build systems for monitoring populations, profiling individuals, and analyzing social media activity. These cases involved actors linked to China, Iran, and West Africa, as well as the commercial "surveillance-for-hire" market. Anthropic's Usage Policy explicitly prohibits using Claude for non-consensual surveillance and profiling, or for violating civil liberties and human rights, and the threat actors in these cases attempted to circumvent controls designed to detect such misuse.






