Anthropic Reveals How It Stopped ‘Kamikaze Drone’ Swarms, Biological Weapons And More
Anthropic unveiled its latest report detailing how it stopped bad actors from using its Claude artificial intelligence (AI) models for malicious activity.
Sean Moran · Sep 10, 2026 · 5 min read

Anthropic unveiled its latest report detailing how it stopped bad actors from using its Claude artificial intelligence (AI) models for malicious activity.
Cases ranged from fake dating apps designed for fraud to surveillance systems meant to track dissidents, according to Anthropic’s Threat Intelligence Report. The report states that bad actors include “suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals.”
Anthropic emphasized that bad actors used Claude Haiku, Sonnet and Opus for malicious purposes and that its frontier models, Fable and Mythos, were not involved, save for one instance of trying to steal AI model data through a process known as “distillation.”
The report follows as an Anthropic researcher recently quit, saying that AI could potentially kill everyone by the end of the decade.
The AI company said it banned a group of Chinese accounts linked to Chinese state security organs used Anthropic’s AI to support “stability maintenance,” which is the Chinese Communist Party’s term for suppressing dissent. Anthropic identified another actor it believes is associated with a municipal cyber police unit that used Claude to run a domestic surveillance system, which identified 10 Chinese citizens as targets.
Many targets of this surveillance ranged from pro-democracy figures in Hong Kong, those that sought organize Tiananmen Square massacre commemorations, as well as advocates for Uyghurs and Western human rights groups.
Hong Kong remains a special administrative region (SAR) of China after the United Kingdom handed control over to the country in 1997. However, over the years, the Chinese mainland government cemented more control over Hong Kong’s somewhat-autonomous status, limiting freedom of expression and the press, according to the Council on Foreign Relations.
The Chinese Embassy in Washington, D.C., did not immediately respond to a DCNF request for comment.
Anthropic said it also disrupted plots using AI to conduct research to develop biological weapons. It stated that it could not determine if this research was for a nefarious or legitimate purpose.
“You are not seeing someone in a comic book kind of way say, ‘Hey, I want to build a biological weapon to kill everybody,’” Jacob Klein, the head of threat intelligence at Anthropic, told The New York Times.
The Anthropic report detailed how it believes sophisticated attacks no longer require sophisticated attackers.
GTG-20006 is an actor whose actions and targeting are consistent with Russian state-nexus espionage, per the report. GTG-20006 targeted government ministries, defense and intelligence groups, embassies, think tanks and defense industrial companies. The actor often targeted Ukrainian and military drone technology providers and supply chains. It remains unclear if GTG-20006 is a hacking collective, individual, or group.
The purported Russian operation used AI to compromise hotel guest WiFi, to which the bad actors then sent malware to hack targets’ laptops and phones.
Anthropic said it identified a “likely freelance Russia-based” threat actor that sought to build a “kamikaze drone swarm.” The AI lab believes the bad actors used Claude Code to test the code meant to design the drone swarm and likely had associations with the Russian Academy of Sciences and not a Russian state entity.
The Russian Embassy in Washington, D.C., did not immediately respond to a DCNF request for comment.
In another instance, the threat intelligence team spotted a Chinese bad actor that sought to build software meant to help detect, jam, or potentially deceive an opponent’s radar and communications systems.
The report accuses several Chinese labs, including Alibaba, Moonshot AI, DeepSeek, Z.ai, Xiami and MiniMax of distillation, which Anthropic defines as an “industrial-scale, covert campaign to extract a model’s capabilities and replicate them in another model without authorization.” It argues that illicit distillation often occurs through fraud, fake accounts, stolen credit cards and login credentials.
Anthropic said it discovered that Moonshot AI, which produces the Kimi family of AI models, “silently forwarded customer requests to Claude, instead of processing them using Kimi.”
Moonshot AI in July unveiled Kimi K3, an AI model that threatened America’s predominance in the global AI race. The AI model experienced so much demand that it initially had to pause new subscriptions. However, the Trump administration accused Moonshot AI of illicit distillation, using American AI models to train the Chinese AI model.
The Chinese Embassy in Washington, D.C., at the time referred the DCNF to Foreign Ministry Spokesperson Lin Jian’s statement on the topic.
“The development of AI in China comes from greater self-reliance and strength in science and technology, and is fueled by China’s vision of extensive consultation and joint contribution for shared benefit,” the spokesperson said in July. “All countries should take a people-centered approach and develop AI for the positive and for good to ensure the open and inclusive development of AI for good and for all so as to better contribute to social progress and the common welfare of the international community. China opposes politicizing and instrumentalizing trade and tech issues. Such actions will only stifle global AI advances and serve no one’s interests.”
Anthropic said it hopes the report gives governments and civil society a better understanding of the evolving nature of AI safety.
“Sophisticated and persistent threat actors continuously test our safeguards and try to circumvent the technical measures we use to detect and prevent misuse. We’ll continue to evolve our safeguards and coordinate with our partners to improve our ability to detect, disrupt, and prevent future misuse,” Anthropic wrote in its report.
“We hope that the findings in this report will help other developers recognize similar patterns on their own platforms, give governments and civil society a clearer view of how emerging threats take shape, and strengthen collective defenses,” the report added.
All content created by the Daily Caller News Foundation, an independent and nonpartisan newswire service, is available without charge to any legitimate news publisher that can provide a large audience. All republished articles must include our logo, our reporter’s byline and their DCNF affiliation. For any questions about our guidelines or partnering with us, please contact [email protected].
All content created by the Daily Caller News Foundation, an independent and nonpartisan newswire service, is available without charge to any legitimate news publisher that can provide a large audience. All republished articles must include our logo, our reporter’s byline and their DCNF affiliation. For any questions about our guidelines or partnering with us, please contact [email protected].
Get every new post by email
No spam, no account needed. Unsubscribe anytime.
Comments
Free account · your comment posts right after signup
