Anthropic on Thursday said it had disrupted several alleged malicious uses of its Claude models over the past eight months, including a suspected Russia-linked cyber espionage campaign and efforts by Chinese AI firms it accused of trying to extract and replicate Claude's capabilities.

Cybercriminals and state-backed hackers were increasingly using AI not just to assist with tasks but to orchestrate and execute large portions of cyberattacks, Anthropic said in its latest Threat Intelligence report, adding that humans were often overseers rather than hands-on operators in the campaigns.

"A majority of the operations ... were enabled by AI via direct execution or orchestration. The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing" tasks, Anthropic said.

Anthropic said it had disrupted what it described as attacks from seven China-based labs during that period. Among the labs Anthropic named were tech giant Alibaba 9988, BABA, Moonshot, DeepSeek and Xiaomi.

Operators it linked to Alibaba ran what Anthropic called the largest "illicit distillation" attack, allegedly aimed at extracting capabilities of Claude models and using them to improve the Chinese tech firm's Qwen models, the company said.

Anthropic, an AI safety and research company, has dedicated teams to rigorously stress-test their models for potential risks and to design protective safeguards, but these defenses often remain fragile.
Anthropic, an AI safety and research company, has dedicated teams to rigorously stress-test their models for potential risks and to design protective safeguards, but these defenses often remain fragile. (credit: SHUTTERSTOCK)

Millions of exchanges observed with Alibaba between May, July

Anthropic said it observed more than 151 million exchanges it attributed to Alibaba between May and July 2026, peaking at nearly 3 million per day from more than 3,500 accounts it described as fraudulent.

Distillation refers to the process of training smaller AI models using output from larger, more expensive models in a bid to lower the costs of training a new AI tool.

Rather than running bulk queries, Kimi chatbot creator Moonshot and DeepSeek allegedly routed live customer conversations, which sometimes included sensitive information, through Claude and used its responses as training data, Anthropic alleged.

A hacking group whose tradecraft was consistent with Russia-based threat actor Midnight Blizzard allegedly ran phishing, hotel Wi-Fi hijacking and WhatsApp-takeover operations against Ukrainian government, military and diplomatic targets, using AI at nearly every stage, Anthropic said.

The group allegedly used AI to build a system that automatically detected when its malware was flagged by security defenses and rewrote the code until it evaded detection again.