Last week, Anthropic published its most detailed Threat Intelligence Report to date. Covering activity from December 2025 through August 2026, it is the clearest public accounting we have of how real adversaries are using AI right now. Not in some theoretical future state, but today.
The headline finding: sophisticated cyber attacks no longer require sophisticated attackers. AI has collapsed the labour and tooling gap that used to separate well-resourced state-sponsored operations from individual operators. Anyone with stolen API keys and a few hours can now sustain multi-victim campaigns that, even a year ago, would have required a team of skilled operators and specialist knowledge.
Russian Espionage: The Autonomous Kill Chain
The report tracks a Russian state-nexus espionage group, designated GTG-20006 and linked to Midnight Blizzard. Their tradecraft is a window into where offensive cyber is headed.
GTG-20006 built a custom toolkit comprising two families of Windows implants, a mobile exploitation kit, a credential stealer targeting browser password stores, a phishing platform designed to mimic government organisations, and an administrative console for managing compromised accounts. Every single tool was managed and re-tooled as needed through AI-assisted workflows.
Here is the part that kept me awake. The actor used AI to monitor how well their tools evaded detection from security products. When their AI agents identified that any deployed malware was detected, the agents would autonomously modify and rebuild the malware to evade those detections. The agents would keep iterating until the malware was undetected. At that point, the tools were staged for live operations from disposable hosting servers.
This is not a human saying “we got burned, let’s recompile with a different packer”. This is an autonomous loop: detect, rebuild, redeploy, all at machine speed, with no human in the decision loop. Traditional detection-based defences cannot keep up with that pace.
From Assistant to Orchestrator
Anthropic notes that the role of AI in cyber operations has shifted from being an assistant to being an orchestrator. In the majority of operations described in the report, AI was used via direct execution or orchestration, not just simple question-and-response from a chatbot. Multi-agent frameworks handled reconnaissance, exploitation and data exfiltration. Humans remained in the loop only for setting targets and reviewing exfiltrated data.
This operational model, which Anthropic first documented in November 2025, has now proliferated across every class of actor the threat intelligence team investigated. Publicly available offensive agent frameworks like PentAGI reproduce much of the same scaffolding for anyone who downloads them. The barrier to entry is now effectively zero.
The Proliferation Problem
The report covers activity across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation. In every category, AI adoption is accelerating the threat landscape.
One case study that stands out is GTG-50020, which targeted the AI supply chain itself, creating fraudulent resellers offering discounted Claude access while silently proxying user traffic to a different model and harvesting credentials. This is the AI equivalent of a watering-hole attack, and it targets the very ecosystem that is supposed to be securing these systems.
What This Means for Defenders
Anthropic’s findings align with what we have been tracking all year. The IBM Cost of a Data Breach 2026 report found that one in four malicious breaches is now AI-enabled, costing companies an average of $6 million. The CrowdStrike 2026 Global Threat Report documented an 89% increase in attacks by AI-enabled adversaries.
The implication for defenders is uncomfortable but unavoidable. If your detection strategy relies on signature-based tools or static rules, you are already fighting the last war. An adversary using AI can modify their tools faster than you can write new signatures. The only viable response is to invest in behaviour-based detection, AI-powered defence tools, and zero-trust architectures that assume every agent, human or AI, is potentially hostile until proven otherwise.
Anthropic’s report also highlights that none of the malicious activity involved Claude Fable or Mythos-class models, which have stronger safeguards. That is small comfort. If the attackers cannot get what they want from the locked-down frontier models, they will use the open-weight ones instead, and there is little stopping them.
The Bottom Line
This report should be required reading for every CISO, security architect, and board member. It is not speculative. It is not theoretical. It is a documented account of what adversaries are doing with AI today, backed by eight months of operational intelligence.
If you take one thing from Anthropic’s findings, let it be this: AI-augmented cyber operations are no longer a future risk. They are the present reality, and they are accelerating faster than most organisations are prepared for.
The cybersecurity skills of AI models means that AI has collapsed the labour and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators. Anthropic Threat Intelligence, September 2026

