Anthropic Disrupts AI Misuse by Chinese Labs, Russian Hackers Targeting Claude Models
Anthropic has disrupted multiple malicious campaigns exploiting its Claude AI models over the past eight months, including a suspected Russia-linked cyber espionage operation and efforts by seven China-based labs to extract proprietary capabilities. The San Francisco-based company detailed the takedowns in its latest Threat Intelligence report, highlighting how state-backed hackers and cybercriminals are now using AI not merely as a tool but as an orchestrator of complex attacks.
The report marks a significant escalation in the AI security landscape, with Anthropic observing over 151 million exchanges attributed to Alibaba-linked operators between May and July 2026. These activities peaked at nearly 3 million daily interactions from more than 3,500 fraudulent accounts, representing what the company called the largest illicit distillation attack against its models.
How Chinese AI Labs Allegedly Exploited Claude Models
Anthropic accused several Chinese technology firms of attempting to extract and replicate Claude's capabilities through a process known as distillation, where smaller AI models are trained using outputs from larger, more expensive systems. The company named Alibaba, Moonshot, DeepSeek, and Xiaomi among the seven labs it disrupted.
According to Anthropic, Alibaba-linked operators sought to use Claude's outputs to improve the tech giant's Qwen models. Alibaba did not immediately respond to requests for comment. Meanwhile, Moonshot and DeepSeek allegedly routed live customer conversations, some containing sensitive information, through Claude and used the responses as training data for their own systems.
Russian Threat Actor Midnight Blizzard's AI-Driven Espionage
Anthropic identified a hacking group whose tradecraft matched that of Midnight Blizzard, a threat actor previously linked by the US government to Russia's SVR foreign intelligence service. The group allegedly used AI at nearly every stage of operations targeting Ukrainian government, military, and diplomatic sectors.
The reported tactics included phishing campaigns, hotel Wi-Fi hijacking, and WhatsApp-takeover operations. Notably, the group used AI to build an automated system that detected when its malware was flagged by security defenses and rewrote the code until it evaded detection again. The Russian Embassy in Washington did not respond to requests for comment.
New Categories of AI Misuse: Weapons Development and Cybercrime
Beyond state-sponsored espionage, Anthropic identified what it called new categories of threat actors misusing Claude. These included operators using the platform to develop software for conventional weapons such as firearms, missiles, armed drones, and bombs, as well as targeting and control systems. The report detailed incidents in China, Russia, and Yemen where Claude was used for weapons design, intelligence gathering, and procurement support.
The company also disrupted activity linked to affiliates of ShinyHunters, one of the most prolific cybercrime collectives in recent months, which has been connected to attacks on major corporations worldwide.
Why AI Models Pose Growing Security Risks
Jacob Klein, head of threat intelligence at Anthropic, explained that models have become significantly more capable over the past year, creating new risks.
A year ago, let's say you wanted to optimise a drone or optimise the software on a missile, the models just wouldn't be as good at that task as they are now,he said in an interview.
Anthropic emphasized that cybercriminals and state-backed hackers are increasingly using AI not just to assist with tasks but to orchestrate and execute large portions of cyberattacks. The company noted that humans often served as overseers rather than hands-on operators, with multi-agent frameworks executing complex tasks autonomously.
What This Means for Southeast Asia's Digital Economy
For ASEAN member states, the report underscores the dual-use nature of AI technologies as regional economies accelerate digital transformation. Singapore's model of AI governance, which emphasizes robust cybersecurity frameworks alongside innovation, offers a reference point for balancing technological advancement with security considerations.
The findings also highlight the importance of regional cooperation in addressing AI-enabled threats, particularly as Southeast Asia becomes an increasingly connected digital hub. Businesses operating in the region should consider AI supply chain risks and the potential for model extraction attacks when deploying AI solutions.
Frequently Asked Questions
What is AI model distillation and why does it matter?
Distillation is the process of training smaller AI models using outputs from larger, more expensive models to reduce training costs. When conducted without authorization, it becomes a form of intellectual property theft that can undermine competitive advantages in the AI sector.
How are state-backed hackers using AI in cyberattacks?
State-backed hackers are using AI to automate and orchestrate attacks, including phishing campaigns, malware development, and code rewriting to evade detection. AI systems can now execute multi-step operations with humans serving primarily as supervisors.
What should Southeast Asian businesses do about AI security risks?
Businesses should conduct thorough due diligence on AI vendors, implement robust monitoring systems, and stay informed about emerging threats. Regional cooperation and alignment with frameworks like Singapore's AI governance model can help mitigate risks.