150 Pages of Threats: Anthropic's September 2026 Report Names Zhipu, Xiaomi, ShinyHunters and a PLA Navy Weapons Pitch
Anthropic's most detailed threat intelligence report yet documents eight months of disrupted abuse: Chinese labs distilling billions of Claude exchanges, AI-orchestrated Russian espionage, an anti-torpedo weapons specification, and five potential bioweapon-use cases.
On September 10, 2026, Anthropic published “Detecting and countering misuse of AI,” its fourth and most detailed threat intelligence report to date — a document spanning nearly 150 pages and covering operations its Threat Intelligence team identified and disrupted between December 2025 and August 2026. It is the fullest public accounting yet of what malicious AI use actually looks like from inside a frontier lab, and almost none of it resembles the hypothetical risks that dominate safety debates.
The report covers seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation. The threat actors include suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals. One notable technical footnote: all of the misuse ran through Claude’s Haiku, Sonnet, and Opus tiers. None of it involved the Fable or Mythos-class models, with the single exception of one illicit distillation case — a data point Anthropic attributes to the stricter safeguards wrapped around its top cyber-capable models.
The cyber chapter: AI as orchestrator, not assistant
The most consequential shift the report documents is structural. In November 2025, Anthropic had described an operating model for autonomous attacks used by one suspected state-sponsored campaign. Nine months later, that operating model has “proliferated across every class of actors we investigated,” with public offensive agent frameworks like PentAGI reproducing the same scaffolding for anyone who downloads them. Sophisticated attacks no longer require sophisticated attackers — sophistication has stopped being a reliable signal of who is behind an operation.
GTG-20006, attributed to Russia’s Midnight Blizzard nexus, is the flagship case. A Russian-speaking operator using the handle “JackPoterz” ran AI-driven workflows that automated nearly the entire espionage cycle against Ukrainian and European government, defense, and diplomatic targets — more than 20 organizations in planning or live operations. The toolkit included Windows implants (PowerChrome, WUEngine, Shadow C2), an Android surveillance RAT, and an iOS exploit chain. When security products detected the malware, AI agents autonomously modified and rebuilt it until it went clean — inverting, in Anthropic’s words, the cost equation back onto defenders, who can no longer rely on shipping a new signature to slow an adversary down. The actor stole a complete proprietary SDK for a military drone vision system and spent days reverse-engineering it, hijacked hotel guest WiFi through three compromised hospitality vendors via DNS hijacking, and took over WhatsApp accounts with headless browsers. A separate intrusion into a North African government technology authority yielded more than 300,000 national identity records and the commercial registry data of over half a million companies.
GTG-50014, a ShinyHunters-linked cluster, shows the same pattern in pure criminal form. One French-speaking operator ran a credential-harvesting pipeline across 10 AWS workers that mass-downloaded 1.8 million distinct Android APKs, decompiled them, and scanned for hardcoded secrets — verified findings streamed in real time into Telegram groups organized by secret type. Affiliates breached a technology provider and exfiltrated over a terabyte including millions of payment card records, accessed airline systems holding tens of millions of passenger records, and claimed the ability to control EV charging current in customers’ homes. One supply-chain breach of a SaaS vendor reached roughly 200 downstream customer organizations and dumped over 2,100 Azure AD token sets across 40 tenants in about 34 hours. In one case, escalation from a single stolen developer token to full administrative control of a cloud environment took roughly three hours — with AI agents doing nearly all of the work. The report calls this “vibe hacking”: operators direct AI toward general goals and defer the specifics of each environment to the model.
GTG-10007, Chinese-speaking operators likely based in Changsha, ran what Anthropic describes as an autonomous exploit foundry — undergraduate students included. The group’s AI workflows decompiled appliance firmware, formed vulnerability hypotheses, wrote exploit code, tested it against lab copies, and iterated until success, yielding more than a dozen possible zero-day findings in a single month on one appliance family. Thirteen standing collection agents ran on a schedule to harvest content from public US military and government sites. Campaign memory persisted across sessions so each could resume mid-operation. Roughly fifty organizations were targeted.
Distillation at industrial scale
The report’s illicit distillation section names seven China-based labs that ran covert capability-extraction campaigns against Claude since Anthropic’s first disclosure in February. Three are detailed:
- Zhipu (Z.ai), tracked as GTG-16006, rotated through 273 fraudulent accounts over ten days in June to extract chain-of-thought reasoning traces from Claude Opus 4.8 — 770,609 exchanges through the CoT-extraction cleaner, and over 3 million attributed exchanges across 17 days. Ahead of GLM-5.3’s release, Zhipu reportedly built capture-the-flag challenges from public vulnerability datasets and distilled the cyber capabilities of a leading US frontier model, with Claude Opus 4.6 used primarily to grade the responses. Notably, Zhipu first tried Fable — and gave up after its cyber safeguards degraded the attacks, switching to weaker-guarded targets.
- Xiaomi, GTG-16008, replayed more than 400,000 saved user conversations from its MiMo models through Claude across 1,500-plus accounts via proxy services. Anthropic assesses Xiaomi may have launched MiMo-V2-Pro’s free trial with the intent of harvesting international developer sessions for SFT and RL data — the bulk of the distillation began just as the trial ended. The relayed traffic included sensitive personal data from hundreds of Xiaomi users.
- DeepSeek, in a pattern the report calls “relay” abuse, rerouted its own users’ requests to Claude without their knowledge — including engineers building a police case-management tool for a Chinese Public Security Bureau, and an IT operator whose relayed requests exposed live credentials for a Russian defense ministry database. Over 14 days in July 2026, Anthropic observed more than 12.1 million exchanges attributable to DeepSeek.
Weapons, biology, and surveillance
The conventional weapons section may be the most startling single case. Anthropic identified a China-based actor using Claude to advance three parallel tracks of an anti-torpedo weapons system for the People’s Liberation Army Navy: a fire control system specification written to win approval from a Chinese defense manufacturer, a 200-plus-page technical proposal with executive briefing deck, and benchmarking against specific US anti-torpedo and anti-submarine programs. The actor posed as a US defense-sector OEM.
The biological misuse chapter opens with a candid admission: Anthropic states it can no longer assure that current models are “well below the threshold” where they could meaningfully assist dangerous biological research, which is why Fable 5 shipped with stronger dual-use restrictions. The report presents five case studies it describes as the first public evidence from any private company of potential bioweapon-relevant misuse of its platform — including a reseller platform serving virologists on a state-sponsored chikungunya gain-of-function grant, a researcher who spent weeks planning avian influenza mammalian-adaptation experiments (confined by classifiers to the weakest models), an Opus 5-drafted orthopoxvirus immune-evasion grant application completed in about an hour, a venom peptide atlas aimed at paralytic targets, and computationally redesigned toxins for a national program with agents kept deliberately vague in progress reports.
The surveillance chapter documents a single consultant engineering a national mobile-interception platform for Malian security authorities, a PRC religious affairs unit reduced from many analyst teams to a single office producing thousands of AI-assisted investigations per month, a PRC-aligned actor with no Arabic skills running a multiday infiltration operation against Uyghur targets in Syria — with Claude drafting outreach in regional dialect and role-playing a quality check — and an Israeli-Singaporean commercial vendor building a social-media profiling platform for Iranian and Persian Gulf users.
Why this report matters
Three things distinguish it from prior lab transparency efforts. First, scale: this is primary-source evidence, gathered from inside the abused platform, spanning seven harm areas over eight months. Second, the uplift framing: Anthropic explicitly measures how much faster, broader, and deeper actors became with AI — and concludes the effect is strongest not at exploit-writing but across the entire kill chain. Third, the policy context: the report landed two days after the NSA/CISA/FBI joint advisory formally accusing six Chinese AI firms of industrial-scale distillation, and it supplies the vendor-side evidentiary base for that government posture — including the detail that when one lab hit Fable’s safeguards, it simply shopped for weaker-guarded models elsewhere.
The quiet headline is the last one. Every case in the report was discovered by Anthropic’s own investigators, after the fact. The report’s implicit argument is that frontier labs now sit on non-public visibility into weapons proliferation, biosecurity, and state espionage — and that publishing it is becoming a responsibility, not a courtesy.
Sources are listed in the frontmatter of this post.
Sources
- [1] https://www.anthropic.com/threat-intelligence-report-september-2026
- [2] https://www.usatoday.com/story/tech/2026/09/10/anthropic-stops-potential-bioweapons-research-report-says/91694786007/
- [3] https://technode.global/2026/09/11/anthropic-ai-orchestrated-cyberattacks-model-distillation/
- [4] https://explainx.ai/blog/anthropic-threat-intelligence-report-september-2026