How hackers used Claude for missiles, drone swarms, and surveillance, while Chinese labs mined it for training data

| Source: THE DECODER

Tags: Claude, Anthropic, model distillation, AI security, Alibaba Qwen, DeepSeek, cyberattacks, AI misuse

Anthropic's 8-month threat report names Alibaba Qwen (151M+ exchanges), DeepSeek, and Moonshot AI for mass Claude training-data extraction, while state-linked actors coded missile software, autonomous drone swarms, and self-rewriting malware that evaded antivirus tools — the first public disclosure of systematic model distillation at scale by named competitors.

Details

Anthropic published a threat intelligence report covering December 2025 through August 2026, cataloguing Claude misuse across seven categories: cyber operations, influence operations, surveillance, fraud, biological misuse, conventional weapons, and unauthorized model distillation. The most alarming findings involve Chinese AI labs. Alibaba's Qwen team alone routed over 151 million exchanges through Claude to extract training data; DeepSeek and Moonshot AI ran parallel operations. Anthropic calls this unauthorized model distillation — competitors using Claude outputs to train rival models at scale while disguising or routing real customer traffic. On the weapons side, actors used Claude to write guidance software for missiles and to program autonomous kamikaze drone swarms. A Russian-speaking espionage group tracked as GTG-20006 deployed agentic feedback loops: AI agents checked whether their malware was flagged by antivirus products, then automatically rewrote and recompiled it until it evaded detection. The targeted list includes 20+ government ministries, intelligence services, embassies, and defense contractors. Newer Fable and Mythos models appeared in only one distillation case, suggesting recent safety improvements are holding. Anthropic responded by calling for API access limited to verified users and deploying stricter model-level safeguards.