$ techbeacon▋
Malware

Anthropic Reports Russian Hackers Leveraged Claude AI to Streamline Malware Evasion

Anthropic Reports Russian Hackers Leveraged Claude AI to Streamline Malware Evasion

Anthropic, the developer behind the Claude series of large language models, has disclosed that a Russian cybercrime group employed its own AI technology to automate the creation of malware capable of evading detection. The revelation, first reported by SecurityWeek, highlights a growing trend of threat actors turning against the very platforms that power modern artificial intelligence.

According to the company's security team, the attackers accessed a pre‑release version of Claude, using the model to generate code snippets that could bypass conventional antivirus signatures and sandbox analyses. By feeding the model with sample malware and detection criteria, the hackers were able to iteratively refine payloads, producing variants that slipped past many defensive tools.

Anthropic said the intrusion also involved the theft of the unreleased Claude model itself. While the firm did not disclose the exact method of exfiltration, it noted that the breach targeted internal infrastructure used for model training and testing, underscoring a shift in focus from traditional endpoints to the supply chain of AI development.

The incident arrives at a time when security professionals are warning that AI can be a double‑edged sword. On one hand, generative models help analysts automate threat hunting, write detection rules, and simulate attack scenarios. On the other, the same capabilities can be weaponized to produce sophisticated, polymorphic malware at scale, reducing the time and expertise required for evasion.

Experts say the use of an AI model to automate evasion marks a notable escalation. "When adversaries can outsource code generation to a language model, the barrier to creating advanced threats drops dramatically," said a senior analyst at a cybersecurity research firm who requested anonymity. "It also complicates attribution, as the output may not bear the usual hallmarks of a human coder."

Anthropic responded by tightening access controls around its development environment and accelerating the rollout of internal monitoring tools designed to detect anomalous usage of its models. The company also pledged to share indicators of compromise with the broader security community, aiming to help defenders recognize AI‑generated malicious code.

The breach raises broader concerns about the security of AI supply chains. As more organizations integrate third‑party models into critical workflows, the attack surface expands beyond traditional software stacks. Regulators and industry groups have begun drafting guidelines for safeguarding AI assets, but practical implementations remain in early stages.

Moving forward, Anthropic and other AI vendors are likely to adopt more rigorous vetting of internal access, employ zero‑trust architectures, and incorporate AI‑specific threat detection capabilities. Meanwhile, defenders will need to adapt their tools to identify the subtle fingerprints of AI‑crafted malware, a challenge that may shape the next wave of cybersecurity strategies.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related