The Maivia Gazette

Verified AI news, every morning

Security

Anthropic threat report: Russian spies automated malware evasion, and Chinese labs ran 200 million distillation exchanges

The eight-month report spans seven harm areas, from a Midnight Blizzard espionage campaign against 20-plus organizations to drone-swarm and virus research, and names Alibaba, Moonshot AI, and DeepSeek in distillation campaigns.

Editorial illustration about Anthropic threat report: Russian spies automated malware evasion, and Chinese labs ran 200 million distillation exchanges.
AI-generated illustration, not event photography.

Evidence: Independent reports. Security stories run only with a named disclosure or independent reporting behind them.

Anthropic published a threat intelligence report on Thursday covering misuse of Claude it says it identified and disrupted between December 2025 and August 2026. The report spans cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Claude Haiku, Sonnet, and Opus models were involved; no case used Fable or Mythos-class models except one distillation case. The headline cyber case matches the Russian state-linked group Midnight Blizzard, which used Claude to check whether its malware evaded security products and had agents automatically rewrite, rebuild, and redeploy tools until they went undetected. The group targeted more than 20 organizations, including Ukrainian and European ministries, defense and intelligence bodies, embassies, and think tanks. CyberScoop says the report also describes an exploit foundry run by Chinese undergraduates and breaches tied to ShinyHunters, and concludes that AI has erased the skill gap between state hackers and lone criminals. SecurityWeek notes criminal groups increasingly targeted AI vendors' own infrastructure, including an attempt to steal a pre-release Claude model. The Register highlights attempts to build kamikaze drone swarms and a more dangerous mosquito-borne virus. On distillation, Anthropic observed nearly 200 million exchanges across five campaigns that tricked Claude into revealing its hidden chain of thought to train smaller models. Those findings follow this week's US advisory accusing six Chinese firms of industrial-scale distillation. A companion Frontier Red Team paper introduces evaluations for intelligence targeting and weapons development and describes new classifiers to block such use.

Sources

  1. CyberScoopAI lets small actors run state-level hacking campaigns, Anthropic report findsPublished · fetched
  2. SecurityWeekAnthropic Says Russian Hackers Used Claude AI to Automate Malware EvasionPublished · fetched
  3. theregisterLatest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons researchPublished · fetched
  4. TechCrunchAnthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek | TechCrunchPublished · fetched
  5. anthropic.comCountering misuse of AI: September 2026 / AnthropicPublished · fetched
  6. anthropic.comMeasuring AI capabilities in intelligence targeting and conventional weaponsPublished · fetched

Also in this edition