Artificial intelligence is no longer just helping hackers write code or phishing emails. State-backed groups are using AI to carry out reconnaissance, build surveillance tools, target military infrastructure and automate parts of cyberattacks, according to Anthropic.The AI company, in its latest threat intelligence report, said it had identified multiple cases of suspected state-linked actors using Claude in operations between December 2025 and August 2026.One of the most detailed cases involved a suspected Russian state-nexus group that used Claude across a cyber espionage operation, from researching targets and setting up phishing infrastructure to stealing credentials, moving across networks and extracting data.The group targeted more than 20 organisations, including government, defence, intelligence and diplomatic bodies, Anthropic said.Also Read: Anthropic says it blocked misuse of its AI that could have supported biological weaponsBut what stood out was not just the use of AI to launch an attack. Claude was also used to help the attackers respond when their tools were detected.According to Anthropic, AI agents monitored security products for malware detections and, when a tool was flagged, modified and rebuilt the malware before redeploying it. This allowed the attackers to continuously adapt their operations rather than rely on a fixed set of tools.Iran-linked actors used AI to target military infrastructureAnthropic also identified an Iran-nexus operation involving reconnaissance of US military and naval-related targets.The actors used Claude to automate parts of the operation, including researching targets, developing tools and organising information gathered during reconnaissance.The case is part of a wider pattern Anthropic says it is seeing where AI is increasingly being used not just to support an individual step of an attack, but to connect several steps of an operation.AI is also becoming a surveillance toolThe misuse isn't limited to cyberattacks.Anthropic said it found state-linked actors using Claude for surveillance and intelligence work. In one case, a PRC-aligned actor used the model to support investigations and an intelligence recruitment operation targeting Uyghurs in Syria.The model was used to draft outreach, translate responses and help manage interactions, according to the report.In another case, Iranian security-linked units used Claude to build surveillance-related tools and analyse large amounts of social media data.Also Read: AI helps terror groups target women, children with propaganda, UN report warnsThe bigger concernThe bigger shift, according to Anthropic, is the amount of work AI can now take on during an operation.Rather than simply asking an AI model to write a piece of code or suggest a phishing email, attackers can use AI to coordinate multiple tasks, analyse information and make changes as an operation progresses.Humans are still involved. Anthropic said operators set targets and reviewed information obtained from attacks. But AI is increasingly handling the work in between.That could make sophisticated operations faster and cheaper to run — and potentially allow less-skilled actors to carry out attacks that would previously have required larger teams of specialists.For cybersecurity teams, the challenge is therefore no longer just defending against better malware or more convincing phishing attempts. It could increasingly mean defending against attackers who can use AI to change tactics almost as quickly as their systems are detected.
State-backed hackers are using Claude for espionage, surveillance and military operations: Anthropic
State-backed groups are now using artificial intelligence for cyber espionage and surveillance. Suspected Russian actors employed AI in a cyber espionage operation targeting over twenty organisations. Iranian actors utilised AI for reconnaissance and tool development against military infrastructure. AI is increasingly automating complex tasks, making operations faster and cheaper.
State-backed actors used Claude against 20+ government and military targets for reconnaissance, credential theft and adaptive malware. AI now orchestrates multi-step attacks, enabling faster, cheaper campaigns accessible to less-skilled attackers.












