Diplomacy

Anthropic uncovers Claude use by Iranian, Houthi, and Russian units

Published

on

Artificial intelligence company Anthropic has disclosed attempted “abuses” of its Claude AI model ranging from conventional weapons to biological research by state-linked entities, foreign intelligence services, and cybercrime networks, publishing the findings in a detailed threat intelligence report.

A significant portion of the report comprised the development of guided missile software by the Houthis in northern Yemen and the conversion of the model into a military reconnaissance tool by Iran-linked actors seeking to target US naval assets in the Middle East.

Covering the period between December 2025 and August 2026, the report shared details of activities detected across seven primary areas: cyberattacks, influence operations, mass surveillance, conventional weapons development, biological risks, and unauthorised model distillation.

The company announced that it had terminated all accounts violating its rules and shared the resulting data with relevant international counterparts.

According to findings by Anthropic’s Threat Intelligence unit, a weapons cell based in northern Yemen, where the Houthis operate, substituted human software engineers with the Claude Code system across three distinct missile development programmes.

These efforts comprised a tactical rocket equipped with a terminal guidance system powered by a commercial smartphone processor, a multi-stage ballistic missile with a target range exceeding 2,000 kilometres, and missile designs carrying a hypersonic glide vehicle.

The cell utilised the artificial intelligence to adapt open-source autopilot software to the smartphone processor, optimize flight control algorithms, and compile firmware.

Structuring their Claude accounts like a virtual engineering team, the Houthis assigned one account to write code, another to conduct research, and a third to review and audit the written code.

The report noted that the group conducted an actual test launch with a guided rocket in the Yemeni theatre.

Immediately following the failure of the live-fire test, the actors were documented returning to the Claude platform within hours to upload telemetry data and diagnose the cause of the malfunction.

The cell was observed successfully compiling offline simulation tools capable of operating independently even if access to Claude were severed.

Iran tracked US warships and personnel

Another military case detailed in the report involved attempts by Iran-linked cyber actors to target US naval forces in the Middle East.

These actors were found to have scraped open-source military data to draft operational targeting manuals directed against American warships and personnel.

Iran extracted name rosters of American military personnel from the captions of publicly accessible military photographs, monitored vessel and aircraft transponder data, authored code to scan commercial satellite imagery, and mapped vulnerabilities in maritime satellite communication terminals.

Other networks linked to the Tehran government were determined to have developed domestic and regional surveillance systems. A Qom-based unit produced a malicious web browser extension disguised as a prayer-time application to harvest credentials from social network users, funneling the data into a central case management system designated “Arman”.

Additionally, official Iranian institutions reportedly cloned authors’ voices using AI and operated multilingual disinformation networks to lay the groundwork for the supreme leadership succession.

Russia also used it for an autonomous kamikaze drone swarm

The report stated that an independent Russia-based software team developed fully autonomous kamikaze uncrewed aerial vehicle swarm software dubbed “DronDoc” or “Serafim”.

Affiliated with a university connected to the Russian Academy of Sciences, the team was said to have trained the artificial intelligence to distinguish between friendly and hostile elements using footage retrieved from the Ukrainian battlefield.

The developed system was designed with the capability to select targets, execute live human classification, and issue detonation commands without requiring human intervention, with simulations run directly against coordinates in the Donetsk region.

Meanwhile, the Russian-origin “Midnight Blizzard” group targeted the Ukrainian drone supply chain and staged attacks aimed at foreign officials and drone engineers by compromising hotel Wi-Fi networks.

A procurement manager stationed at a design bureau in Moscow was also discovered drafting plans via Claude to circumvent European sanctions. The individual was recorded assembling fraudulent tender and logistics correspondence to transport German-made magnetometers, space-grade photovoltaic sheets, and military aviation oxygen systems into Russia through intermediary firms based in China and Hong Kong.

Biological threats and pathogen engineering

The report disclosed five concrete cases regarding the deployment of artificial intelligence in hazardous biological research. Virologists attached to a military research institute were documented using AI for gain-of-function research aimed at enhancing the transmissibility and immune-evasion capabilities of the mosquito-borne Chikungunya virus.

Similarly, experimental designs were prepared to adapt the H5 avian influenza variant, which carries a 50% mortality rate in humans, to mammals and confer airborne transmission capabilities, while immune-evasion mechanisms of pathogens from the smallpox virus family were modelled.

The identities of paralytic neurotoxins subject to export control lists and haemorrhagic fever virus proteins featured on the World Health Organization’s priority epidemic list were deliberately masked and submitted to the AI for analysis.

In addition, a consultant working on behalf of the Malian State Intelligence Service designed a mass surveillance platform designated “Lakana 360” with the assistance of Claude.

The system was designed to monitor approximately 25 million SIM cards registered across three mobile operators in the country without requiring court orders, intercept audio recordings, and cross-reference records with biometric databases.

Separately, leading Chinese artificial intelligence firms including Alibaba, Moonshot, DeepSeek, Zhipu, and Xiaomi were alleged to have initiated hundreds of millions of unauthorised sessions to extract the logical reasoning chains of Claude models. Moonshot and DeepSeek platforms reportedly routed their own users’ queries secretly through Claude, in the process exposing Chinese police surveillance feeds from hundreds of cameras covering military facilities in Chengdu, internal credentials of Chinese state-owned enterprises, and live database access codes connected to the Russian Defence Ministry to third parties.

Türkiye detail in the report

The report also detailed cases involving the abuse of the Claude AI model, incorporating findings concerning an Istanbul-based technology firm.

In case GTG-84005 of the intelligence report, an operation aimed at commercial election manipulation targeting voters in Malaysia was intercepted.

According to the findings, the operation operated under the guise of a startup providing cyber intelligence and counter-disinformation tools. Anthropic determined that Istanbul-based BBS Bilisim Teknolojileri was behind the infrastructure.

According to documents, the company marketed the architecture as a paid influence operation service styled as a “military-grade, AI-powered, real-time political operations ecosystem”.

Managing roughly 1,000 synthetic X accounts, the system processed demographic and electoral data across 222 parliamentary constituencies in Malaysia, calibrating targeting around sensitive social fault lines including ethnicity, religion, and the monarchy.

The network also circulated content from Russian and Chinese state media masquerading as independent Malaysian news via an artificial media outlet designated “Malaysia Pulse”, while manufacturing fraudulent intelligence dossiers targeting an opposition politician and civil society organisations.

Anthropic reported that the network received a request to generate 1 million artificial impressions in support of the Malaysian Prime Minister and sought to secure a contract with the country’s national communications regulatory authority.

While no evidence emerged that the undertaking succeeded, the associated user accounts were closed and operational digital indicators were shared.

MOST READ

Exit mobile version