Anthropic Threat Intelligence Reports

Source: Anthropic — Threat Intelligence Report: August 2025 (PDF, 25 pages). Local copy: .raw/reports/anthropic-threat-intelligence-report-2025-08.pdf.

Key claim

Model-vendor abuse telemetry is an evidence class of its own. A vendor sees the operation from inside the tooling the attacker used, which means it can describe campaigns that produced no breach notification, no incident-response engagement, and no victim disclosure. The August 2025 edition uses that vantage to argue three positions that the wiki’s incident record had only partial support for: AI systems are executing operations rather than advising on them, actors without the underlying skills are running operations that previously required them, and AI now appears at every stage of a fraud supply chain rather than at one step of it.1

Series and editions

Anthropic publishes these as a continuing series and states the intent to keep doing so.1 The wiki tracks four artifacts in the line, of which the first two are the same reporting cadence and the third and fourth are its analytic products.

EditionDateContentsWiki page
Threat Intelligence Report: August 2025Aug 2025Nine case studies: extortion, DPRK employment fraud, ransomware-as-a-service, a nine-month PRC-aligned campaign, two disrupted operations, four fraud-ecosystem casesthis page
GTG-1002 disclosureNov 2025The first reported AI-orchestrated espionage campaign, published as a standalone report rather than a series editionGTG-1002: AI-Orchestrated Espionage Campaign
LLM ATT&CK NavigatorJun 2026A year of banned-account telemetry mapped to MITRE ATT&CK, plus the ARiES scoring methodologyLLM ATT&CK Navigator
Verizon DBIR 2026 contribution2026Eleven months of the Navigator dataset, published inside a third-party breach reportVerizon DBIR 2026

The August 2025 edition and the Navigator draw on overlapping populations: the Navigator’s window opens in March 2025, five months before the report, and both rest on accounts banned under the same Usage Policy enforcement pipeline.

Case studies in the August 2025 edition

Two cases have their own pages because they establish positions no other sourced incident in the wiki carries.

The remaining seven are summarized here.

CaseActorModel’s roleAnchoring figure
DPRK remote-worker fraudNorth Korean IT operativesPersona construction, interview coaching, and the delivered engineering work itself61% of observed usage was frontend development, 26% scripting, 10% interview preparation, 3% backend; roughly 80% of usage was consistent with active employment2
PRC-aligned campaign against Vietnamese infrastructureChinese-language actor, characteristics consistent with APT operationsPython scanners against Vietnamese IP ranges, upload fuzzing, WordPress exploitation, Hydra and hashcat tuning, Linux kernel privilege escalation, proxy chainsClaude used across 12 of 14 MITRE ATT&CK tactics over a nine-month campaign3
Contagious Interview account creationDPRK, tracked as Famous Chollima / DEV#POPPER / UNC5342Nothing; the accounts were banned before issuing a promptTwo of four accounts created 2024-10-22 auto-banned; the actor abandoned the other two4
Russian-language malware developmentWindows-internals-capable developerHell’s Gate syscall resolution, Early Bird process injection, Telegram command and control, sandbox detectionSamples appeared on VirusTotal within two hours of generation, submitted from Russia, the UK, and Ukraine5
Stealer-log profiling over MCPForum actor on xss[.]isCategorized stolen browser telemetry into behavioural victim profiles through an MCP integrationDemonstrated publicly on a Russian-language forum as a capability offering6
Carding storeSpanish-language operatorMulti-API validation with rotation across three card-checking services, failover, request throttling, batch schedulingInvite-only service operating at resale scale6
Romance-scam botChinese-language operatorEmotional-register response generation, marketed with Claude as the “high EQ model”Over 10,000 monthly users across US, Japanese, and Korean targeting6

A ninth case, synthetic-identity services, is listed in the report but its body text repeats the carding-store section verbatim, so the edition carries no usable detail on it.

Significance

Vendor telemetry closes cases that victim-side reporting never opens. Six of the nine case studies produced no public victim disclosure the wiki can locate, and two of them, the auto-disrupted Contagious Interview accounts and the abandoned targets listed in the GTG-2002 session summaries, describe operations that were stopped before they reached a victim at all. An incident record assembled only from breach notifications and vendor IR write-ups systematically misses this class, which matters for any wiki claim of the form “no sourced case exists”.

The reports extend the operator-autonomy spectrum at its low end. The wiki’s spectrum runs from an operator who sets the objective and relays results between separate agent instances (GTG-1002), through an operator who sets the objective while sub-agents coordinate among themselves (Taiwan), to no operator at all (OpenAI–Hugging Face). GTG-2002 sits below all three: the operator stayed on the keyboard throughout, which is the least autonomous configuration the wiki records. It is still a change, because it moves a different variable: the skill the operator had to bring. That variable is the subject of Capability Floor Collapse.

Disruption is described, and its limits are described with it. Every case study ends with a mitigation paragraph naming the specific control built in response: a tailored classifier for the extortion pattern, malware upload-and-generation detection for the ransomware case, improved indicator correlation for the employment fraud.7 The pattern is per-case classifier development after investigation, which bounds how far the disclosures support a claim of general prevention.

Limits

  • Single-vendor view. The report states that the patterns likely hold across frontier models but presents evidence only from Claude.1 Nothing here measures how much of each operation ran on other models.
  • Redacted throughout. Prompt excerpts are labelled as simulated reconstructions, victims are described by sector rather than named, and dollar amounts inside quoted extortion material are bracketed. The figures this wiki cites are the ones that survive redaction: the 17 organizations, the ransom band, the pricing tiers.
  • No denominator. The report gives no base rate: it does not say how many accounts were reviewed, how many were banned, or what share of platform traffic the cases represent. The LLM ATT&CK Navigator supplies that denominator for a later window, at the cost of dropping the case narratives.
  • A production defect in the primary. The synthetic-identity section duplicates the carding-store text, which is a reminder that a vendor PDF is a published artifact and not a dataset.

Relations

  • Supports Offensive AI: State of the Field — supplies the capability-transfer axis the page’s autonomy spectrum does not measure.
  • Supports Agentic AI Threat Classes — the DPRK employment-fraud case is a sourced instance of the AI-aware insider (Class 1) arriving through hiring rather than through an existing employee.
  • Tempers Verizon DBIR 2026 — Anthropic contributed eleven months of the successor dataset to that report, so the DBIR’s GenAI section and Anthropic’s own publications are not independent observations of the same population.8

See also

Notes

Footnotes

  1. Anthropic, Threat Intelligence Report: August 2025, executive summary, p. 3. The four stated findings are weaponization of agentic systems, lowered barriers to sophisticated cybercrime, AI embedded throughout criminal operations, and AI across all stages of fraud. The cross-model claim: “While specific to Claude, the case studies presented below likely reflect consistent patterns of behaviour across all frontier AI models.” 2 3

  2. Ibid., “Remote worker fraud”, pp. 11–14. Usage split and the ~80%-consistent-with-employment figure are Anthropic’s own telemetry; the revenue scale is attributed to FBI assessments, not measured by Anthropic.

  3. Ibid., “Chinese threat actor leveraging Claude across nearly all MITRE ATT&CK tactics”, p. 18. Targets described as Vietnamese telecommunications providers, government databases, and agricultural management systems.

  4. Ibid., “Auto-disruption of a North Korean malware distribution campaign”, p. 19. The 140+ victim figure is attributed to external security research, not to Anthropic telemetry.

  5. Ibid., “No-code malware development campaign”, p. 20. Discovered through Clio, Anthropic’s automated privacy-preserving analysis tool.

  6. Ibid., “AI-enhanced fraud”, pp. 21–26. 2 3

  7. Ibid., mitigation paragraphs at pp. 10, 14, and 17.

  8. Kyla Guru, Alex Moix, and Jacob Klein, Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator, Anthropic Frontier Red Team, 2026-06-03, footnote 1: “For the DBIR, we provided analysis of 11 months of threat actor data, and rounded this out to 12 months for this report.”