Anthropic on September 10 published its September 2026 threat intelligence report, warning that adversaries have moved from asking chatbots for advice to letting AI models run large chunks of their attacks end to end — with a Russian state-nexus operator dubbed GTG-20006 as the case study.
GTG-20006: 130 Days, 27 Targets
Anthropic says GTG-20006 conducted a 130-day campaign in which 24 of 27 targeted institutions were successfully engaged, including Ukrainian ministries, Ukrainian and European defence bodies, drone supply-chain manufacturers and individuals connected to U.S. foreign policy. The company attributes the tradecraft as "consistent with" the Russian state group publicly tracked as Midnight Blizzard, with one operator using the handle "JackPoterz." Rather than treating Claude as a passive tool, GTG-20006 wired the model into custom workflows that automated development, infrastructure acquisition, phishing, persistence, command and control, and data exfiltration — and even auto-rebuilt and redeployed its toolkit whenever security products caught up.
AI Now Rebuilds Malware, Runs Drone Kill Software And Trades Prompts For Persistence
The broader report documents cases spanning seven harm domains, from biological weapons uplift attempts and industrial espionage to AI-generated "kamikaze drone" targeting software. Anthropic says it disrupted operations that repurposed model outputs to rebuild malware modules on the fly and to script influence-operation content at scale. The company also disclosed that Claude models are approaching the Critical cybersecurity capability threshold under its Responsible Scaling Policy, echoing OpenAI's Astra Critical designation for its next flagship model.
Defenders Get New Tools, But The Race Is Escalating
Alongside the report, Anthropic detailed changes it has made to alignment and security since it disclosed three real-world cybersecurity evaluation incidents in July, and it continues to ship a hardened Claude Fable 5 and Mythos 5.1 lineup. The disclosures land as Google's Gemini 3.8 Flash Cyber and OpenAI's Astra push frontier labs into an arms race with the actors they are trying to describe — with Anthropic's own investigations serving as the closest thing the field has to public case files.
Reporting based on coverage from Anthropic, TechNode Global and Cyber Kendra.
