Anthropic has published a threat intelligence report documenting misuse of its own models. It covers the eight months from December 2025 to August 2026.
The documented cases fall under seven headings: cyber operations, influence operations, surveillance, fraud, biological misuse, conventional weapons and unauthorised model distillation.
Malware that rewrites itself
A Russian-speaking actor designated GTG-20006 deployed malware that used AI agents to rewrite its own code automatically whenever antivirus tools detected it.
More than 20 organisations were targeted, among them government entities and defence contractors. The focus fell particularly on Ukraine and on European drone supply chains.
That case carries the report's most striking technical detail: malware is no longer a fixed file but a process that changes shape as it is detected. Signature-based defence is exactly what struggles at that point.
The distillation campaign by Chinese labs
Seven Chinese AI laboratories are said to have run large-scale covert campaigns. The numbers tell the scale on their own.
| Actor | Method | Scale |
|---|---|---|
| Alibaba's Qwen team | More than 3,500 fraudulent accounts | peak of almost 3 million exchanges a day |
| DeepSeek | Routing its own customers' requests to Claude | over 12.1 million exchanges in 14 days |
| Moonshot AI | The same routing method | users believed they were on a Chinese model |
Among the requests arriving through DeepSeek were ones from users linked to the Chinese military analysing CCTV footage from Chengdu.
The second leg of the method is more uncomfortable. Moonshot AI and DeepSeek routed their own customers' requests to Claude while those users believed they were talking to a Chinese model. The misuse was aimed not only at the provider but at those services' own users.
Surveillance and weapons cases
The largest case under surveillance belongs to a Mali-based consultant. A system called "Lakana 360" monitored roughly 25 million SIM cards across the country's carriers, with voice identification and encryption detection.
Two cases are documented under conventional weapons: missile guidance systems, and autonomous FPV drone swarms carrying onboard targeting models trained on Ukrainian combat footage.
The biological risk side
The company said it stopped multiple attempts this year to use its models for research that could help develop biological weapons. Five examples were shared, in which actors circumvented controls and tried to obfuscate the purpose of their research.
Some cases involved users in nations Anthropic bars from accessing its models. The company also states why it is sharing them: to spark a conversation within the industry and with governments about how emerging biological risks should be countered.
The measures taken
In response Anthropic shipped Claude Fable 5 with stricter biosecurity safeguards. Fable 5.1 added a "preserved thinking" feature aimed at blocking account manipulation and distillation attacks.
The report's real value is that documents like it remain rare. Publishing numbers on how your own product is being abused is not an established habit in this industry, and this report leaves a baseline others can be measured against.