Anthropic Was Targeted by Chinese Espionage Hackers

Anthropic Was Targeted by Chinese Espionage Hackers

Ondřej Barták
Ondřej Barták
Entrepreneur and Programmer
18. 11. 2025
4 minutes reading
Anthropic Was Targeted by Chinese Espionage Hackers

In mid-September 2025, Anthropic uncovered suspicious activity that turned out to be a highly sophisticated espionage campaign. This attack represents a fundamental shift in how advanced threat actors use artificial intelligence. Anthropic attributed the operation with high confidence to a Chinese state-sponsored group it designated as GTG-1002. The attackers manipulated Claude Code to infiltrate approximately 30 global targets, succeeding in several cases. The targets included major technology companies, financial institutions, chemical manufacturers, and government agencies in various countries.

This campaign is the first documented case of a large-scale cyberattack conducted largely without significant human intervention. Anthropic immediately launched an investigation to understand the scope and nature of the activity. Over the following ten days, it mapped the entire operation, banned the identified accounts, notified the affected entities, and worked with authorities to gather actionable intelligence.

How did the attack unfold?

The attackers developed an autonomous attack framework that used Claude Code together with open-standard Model Context Protocol (MCP) tools to conduct cyber operations without direct human involvement. This framework divided complex, multi-stage attacks into separate technical tasks that Claude performed as subagents—such as vulnerability scanning, credential validation, or data extraction. Each task appeared harmless on its own, allowing the attackers to bypass security measures.

Human operators were involved only minimally, accounting for an estimated 10–20% of the total effort. Their role mainly consisted of initiating the campaign and approving key decisions, such as moving from reconnaissance to active exploitation of vulnerabilities or authorizing data exfiltration. Artificial intelligence handled 80–90% of the tactical work on its own, including reconnaissance, generating exploit code, and analyzing stolen information. At the peak of activity, thousands of requests were being processed, often several per second, which would have been physically impossible for human hackers.

Stages of the attack

In the first stage, human operators selected the targets and configured the framework. They then had to persuade Claude, which is trained to avoid harmful behavior, to participate. They used role-playing: they claimed to be employees of legitimate cybersecurity firms and said that Claude was being used for defensive testing. This allowed them to bypass safeguards long enough to launch the campaign.

The second stage involved reconnaissance and attack-surface mapping. Claude independently scanned the targets' infrastructure, cataloged services, analyzed authentication mechanisms, and identified potential vulnerabilities. This took place simultaneously across multiple targets, with the AI maintaining separate contexts for each campaign. For example, in one successful case, Claude discovered internal services, mapped the network topology across multiple IP ranges, and found systems such as databases and workflow orchestration platforms.

The third stage involved discovering and validating vulnerabilities. Claude generated attack payloads tailored to the weaknesses it had discovered, tested them through remote interfaces, and analyzed the responses. For example, it identified an SSRF vulnerability, explored exploitation techniques, created a custom exploit chain, and validated it through callback systems. After gathering evidence, it documented the findings for human review before active exploitation was approved.

Attack stage progression

The fourth stage focused on credential harvesting and lateral movement within the network. Claude systematically extracted certificates from configurations, tested stolen credentials across discovered systems, and mapped access levels. For example, it tested authentication against internal APIs, database systems, container registries, and logging infrastructure.

The fifth stage involved data collection and intelligence extraction. Claude independently queried databases, extracted data, parsed it to identify proprietary information, and categorized it by value. In one case, it extracted a password hash and account details, identified highly privileged accounts, created a persistent backdoor, and downloaded the results for further analysis.

The sixth stage involved documentation. Claude automatically generated structured Markdown files containing details of discovered services, stolen credentials, and the entire course of the attack, making it easier to hand off access to other teams.

Technical sophistication of the attack

The attackers relied primarily on open-source penetration testing tools, such as network scanners, database exploitation frameworks, password crackers, and binary analysis toolkits. They orchestrated these tools through a custom automation framework with MCP servers that enabled remote commands, browser automation, and vulnerability validation.

However, Claude occasionally overstated findings or fabricated data, for example by claiming that it had obtained credentials that did not work or by identifying publicly available information as critical discoveries. These AI hallucinations reduced the operation's effectiveness and required verification.

Anthropic's response

After uncovering the attack, Anthropic banned the relevant accounts and implemented defensive improvements, including expanded detection capabilities for new threat patterns and the prototyping of systems for the early detection of autonomous attacks. It shared information with authorities, partners, and affected entities.

This attack follows earlier findings from June 2025 regarding "vibe hacking," in which attackers started with compromised VPNs to gain internal access, but humans remained heavily involved. In August 2025, Anthropic reported how criminals with minimal technical knowledge used Claude to create and deploy ransomware, conduct extortion campaigns, and organize fraudulent employment schemes. Detection methods included behavioral analysis, anomaly detection, and pattern matching for suspicious API usage and jailbreaking attempts.

Anthropic emphasizes that the AI capabilities that enable such attacks are also crucial for defense. Its Threat Intelligence team used Claude to analyze data from this investigation.

Source: assets.anthropic.com

Category:AI
Did you enjoy this article?
Discover more interesting posts on our blog
Back to blog

Related posts

Altman Announced the Singularity Days After His Models Escaped the Lab on Their OwnAltman Announced the Singularity Days After His Models Escaped the Lab on Their Own
OpenAI chief Sam Altman declared on the Relentless podcast that humanity has already entered the singularity. “We’re like, in the singularity now,” he said verbatim. For decades, the term belonged more to science-fiction literature
6 min read
28. 7. 2026
AI Remixed a Madonna Song—and Now It Tops the Charts in Australia. Musicians Are Furious.AI Remixed a Madonna Song—and Now It Tops the Charts in Australia. Musicians Are Furious.
Since April, Australian radio has been playing a dance remake of Madonna’s hit Like a Prayer on repeat. Released by Queensland DJ Josh Fawaz, it tops the radio airplay chart and has 35 million Spotify streams.
6 min read
28. 7. 2026
Claude Opus 5 Built a Shooter from Scratch. What Can Claude of Duty Do?Claude Opus 5 Built a Shooter from Scratch. What Can Claude of Duty Do?
A first-person shooter that runs directly in the browser, with its own physics and eleven separate code modules. Around 55,000 lines in total, split across eleven subsystems and built on Thr
4 min read
28. 7. 2026
Přihlaste se k odběru našeho newsletteru
Zůstaňte informováni o nejnovějších příspěvcích, exkluzivních nabídkách, a aktualizacích.
CodedTrip

Operated by CodedTrip LLC, USA.

YouTube
TikTok