i
DATAIST
News · 2026-09-11

Anthropic ties Claude to missile guidance code and seven Chinese labs

@neuronium_ai @neuronium_ai

A cell in northern Yemen used Claude Code in place of human developers to write guidance, navigation and control software for three missile programs, one of them multistage with a calculated range above 2,000 km. That is the first time Anthropic has described its own model being used to build weapons, and it appears in an eight-month threat intelligence report that also documents an autonomous kamikaze drone swarm, a surveillance platform built to cover 25 million SIM cards in Mali, and seven Chinese labs pulling capability out of Claude through networks of fraudulent accounts.

Cover: Anthropic ties Claude to missile guidance code and seven Chinese labs

A cell in northern Yemen used Claude Code in place of human developers to write guidance, navigation and control software for three missile programs, one of them multistage with a calculated range above 2,000 km. That is the first time Anthropic has described its own model being used to build weapons, and it appears in an eight-month threat intelligence report that also documents an autonomous kamikaze drone swarm, a surveillance platform built to cover 25 million SIM cards in Mali, and seven Chinese labs pulling capability out of Claude through networks of fraudulent accounts.

The report sorts misuse into seven categories: cyber operations, influence operations, surveillance, fraud, dangerous biological applications, conventional weapons and unauthorised model distillation. Haiku, Sonnet and Opus turn up most often across the incidents. The newer Fable and Mythos appear in exactly one case, a distillation cluster. Anthropic says it deliberately concentrated on novel abuse patterns rather than the ordinary ones.

The weapons section is the one with no precedent. In the Yemen case, designated GTG-87001, the operators ran several Claude instances in parallel and split the work across sessions so that no single session held the full picture of what was being built. One test launch is thought to have failed; within hours the group was back asking Claude to work out why. Compartmentalisation of that kind is an operational discipline borrowed from human intelligence work, applied here to a vendor's safety layer.

A second cluster, GTG-27005, is probably the work of Russian contract developers. They built a swarm of autonomous FPV kamikaze drones carrying a small language model onboard, with camera guidance in the terminal phase. The platform was designed to engage targets autonomously: the onboard model could pick out objects of class "human" and trigger detonation with no operator in the loop. According to Anthropic, the image classifier was trained on captured combat footage from Ukraine. A Chinese cluster, GTG-17002, covered roughly 16 modules for electronic warfare and suppression of enemy air defences; midway through the project the default simulation scenario was changed to twelve targets in Taiwan.

The cyber findings are less cinematic and probably more consequential. The techniques in play are the familiar ones — stolen credentials, unpatched devices, SQL injection, phishing. What has changed is who performs them: reconnaissance, exploitation and tool-building are now handed to models running in parallel at machine speed. Anthropic's conclusion is that complex attacks no longer require complex attackers, and that sophistication has stopped being a reliable signal for attribution. Autonomy also lowers the attacker's cost base, which makes targets worth hitting that previously were not worth the hours.

GTG-20006, a Russian-speaking espionage group, closed the loop entirely. AI agents checked whether security products detected the malware they had deployed; when an antivirus flagged it, the agents rewrote and recompiled the code themselves until it passed again. The defensive implication is blunt: shipping new detection signatures stops slowing an attacker who iterates faster than the signatures ship. More than 20 organisations were hit, including government ministries, intelligence services, embassies and defence contractors, mostly in Ukraine and Europe. The drone supply chain came up repeatedly — one haul included a complete proprietary SDK for a drone computer-vision system. Access sometimes came sideways: the attackers compromised hotel guest Wi-Fi providers and infected guests' devices from there, a method Microsoft named CaptiveCrunch in July 2026.

Clusters Anthropic associates with ShinyHunters, grouped as GTG-50014, went after credentials at industrial scale. One operator downloaded 1.8 million Android applications, decompiled them and searched for secrets hardcoded into the source. Anthropic calls the pattern vibe hacking: a human states a general objective, the model explores the environment and keeps iterating until the objective is met. One of the hackers said he was collecting bounties on HackerOne while extorting two companies at the same time.

The surveillance section centres on Mali, where a single consultant used Claude as the principal engineering resource for a platform called Lakana 360, intended to monitor roughly 25 million SIM cards across all three national mobile operators. It re-identified people by voice after they swapped SIMs, flagged users of encryption and VPNs, and tied individuals to the national biometric citizen registry. Suspending the account halted development and nothing else: the platform itself ran on local models hosted on the operator's own servers. Anthropic recorded comparable work by Iranian units, which claimed to have tracked and profiled 6,388 Iranians over a year.

Distillation is legal as a training technique; Anthropic's objection is to covert industrial-scale campaigns that extract a model's capabilities without permission, typically through networks of fake accounts backed by stolen bank cards and API keys, with traffic routed through relay stations. After the first disclosure in February, the company identified seven more Chinese labs doing it. The largest measured campaign, GTG-16005, is attributed to Alibaba's Qwen lab: a purpose-built prompt made Claude write out its reasoning chain in detail before answering, and the transcripts became fine-tuning data for Qwen 3.5, 3.6 and 3.7. Peak load reached nearly 3 million exchanges a day across more than 3,500 fraudulent accounts, and over 151 million exchanges passed through between May and July 2026, mostly agentic and coding work.

Several labs went further and routed their own paying customers' requests into Claude. Moonshot AI, as GTG-16002, passed almost 300,000 customer requests to Anthropic in ten days through 5,380 fraudulent accounts, with users believing they were talking to Kimi. DeepSeek, as GTG-16001, used marker strings to spot requests coming from tools like Claude Code, flagged those users and forwarded selected requests to Claude Opus — more than 12.1 million exchanges in 14 days. Xiaomi, as GTG-16008, saved the prompts and coding sessions of users on its own MiMo models and replayed those conversations through Claude to manufacture training data; Anthropic found no evidence that Claude's answers were shown to Xiaomi's users directly.

Zhipu, known outside China as Z.ai, ran more than 770,000 exchanges through 273 accounts in ten days, passing the traffic through a reasoning-chain scrubber that converts harvested chains of thought into training-ready data automatically. SenseTime, per the report, bought transcripts from intermediaries rather than collecting them, which means a broker market for this already exists. MiniMax stood up its own proxy network behind a front company — one that offered Anthropic and OpenAI models and no Chinese ones, including MiniMax's own.

The rerouted traffic carried more than coding tasks. Among the customer requests funnelled through DeepSeek was work by a user probably tied to the People's Liberation Army, who analysed archived surveillance footage on a single target and video from hundreds of cameras in Chengdu, some near PLA facilities. The same route delivered requests from an operator holding working credentials to a database linked to Russia's Ministry of Defence, and another project building a case-management system for a Chinese public security bureau that matched movement profiles against police records. Across Moonshot AI, DeepSeek and other labs, the redirected requests contained personal data — names, contact details and company information belonging to hundreds of people in at least twelve languages.

One line in the distillation section deserves more attention than the headline numbers. Zhipu, training GLM-5.3 on cyber tasks, first tried Anthropic's Fable model and dropped it once the cyber safeguards degraded output quality, then deliberately moved to models it judged less protected. That is safety functioning as a performance tax, with buyers pricing it and routing around it. Every lab that ships weaker guardrails collects the demand its more careful competitors shed — which is an argument for industry-wide floors and an argument that no single vendor's controls can hold, and the report makes neither.

This document is also doing two jobs and only owning up to one. The cyber, surveillance and weapons sections are threat intelligence in the ordinary sense: harm described, actors designated, defenders informed. The distillation section is a commercial grievance with a threat-intelligence spine. The injury is to Anthropic's margins and competitive position, the named parties are seven direct competitors, and the announced remedy — the saved thinking mechanism introduced in Fable 5.1, meant to stop new API accounts manipulating context — is a product feature. The conduct described is real and the accounts were fraudulent. But placing a list of competitors inside a document whose other chapters concern missile guidance and bioweapons lends it a severity the evidence in that chapter does not supply on its own.

The biology section is where Anthropic turns the instrument on itself, and it is the most useful part of the report. Five anonymised cases involve working scientists whom Claude assisted on potentially dangerous dual-use projects. In one, a biosecurity classifier blocked a grant application for gain-of-function research on chikungunya virus, work planned at a military research institute. The platform operator had built a fallback in advance: any request Claude refused was rerouted to a competitor's model. Most of the code for that fallback, according to the report, was written by Claude. Other projects ran with almost no friction, including help preparing an application to study immune-escape genes in orthopoxviruses. Anthropic's conclusion is that classifiers cannot be simultaneously useful and preventive, because in dual-use fields user intent cannot be reliably determined. It has responded with Claude Fable 5 and tighter handling of dual-use biology requests, and argues that the only safe route to frontier biological capability is verified-user programmes.

Notably absent from eight months of global review is any misuse originating with the United States or an allied government. Every state-linked actor named is Russian, Chinese, Iranian or Yemeni. That is either a finding about where the misuse is or a finding about where the company looked, and the report does not indicate which, or whether the question was asked. Two other gaps: there is no figure for how many legitimate dual-use researchers the stricter Fable 5 filters now turn away, and nothing on whether the hundreds of people whose names and contact details passed through relay accounts have been told.

The Mali case is the one that outlasts the report. Anthropic suspended the account and the surveillance platform kept running, because it had already moved to local models on its operator's own servers. Every enforcement mechanism in this document — classifiers, account bans, saved thinking, verified-user programmes — works only while the work is being done on Anthropic's machines. The company's own finding, that intent cannot be inferred in dual-use domains, points at the same wall from the other side: the controls that function are controls over access, and they stop mattering the moment the capability is running somewhere else.