# AI Misuse Has Entered a New Phase: Surveillance, Propaganda, and Weapons at Machine Speed

Artificial intelligence is no longer just a tool in the hands of malicious actors—it has become the operational machinery itself. Anthropic's latest Threat Intelligence report, covering December 2025 through August 2026, reveals a disturbing escalation in AI misuse across cybercrime, surveillance, propaganda, and even weapons development. From credential-harvesting pipelines processing 1.8 million Android apps to AI-powered dating fraud reaching 25,000 victims, the report demonstrates that AI is fundamentally changing the economics, speed, and scale of malicious operations.

## The Operational Layer: AI as a Force Multiplier

The most significant shift identified in Anthropic's threat intelligence report isn't the discovery of new attack techniques or novel malware. Instead, the report highlights how AI models now contribute across nearly the entire attack chain—from reconnaissance and tool development to exploitation, credential theft, data processing, and exfiltration. This represents a fundamental change in how cybersecurity threats operate.

Sophisticated attacks no longer require sophisticated attackers. Anthropic's analysis reveals that AI is compressing the gap that previously separated well-funded state-sponsored operations from smaller criminal groups. Tasks that once demanded teams of specialists—reconnaissance, exploitation, coding, and data analysis—can increasingly be delegated to AI systems running at machine speed.

Despite this automation, the underlying attack vectors remain familiar: stolen credentials, exposed services, vulnerable edge devices, phishing, and SQL injection still dominate. What has changed is the cost of assembling these elements at scale. A small team can now attempt operations that previously required a much larger workforce.

## The Credential Harvesting Pipeline: Automation in Action

One of the most striking examples involves a financially motivated operation that demonstrates just how automated cybercrime has become. A French-speaking operator using aliases including "MeowSHA," "frkoo," and "blazespider" ran a distributed credential-harvesting infrastructure across a fleet of 10 AWS EC2 workers.

This automated pipeline mass-downloaded 1.8 million distinct Android APK files from multiple app-store sources, decompiled them, and scanned for hardcoded secrets using tools like TruffleHog. Verified findings were routed in real time to a Telegram group organized into over 100 source types. A parallel operation harvested GitHub Personal Access Tokens through email harvesting. Together, these pipelines supplied the initial-access credentials for the bulk of confirmed breaches associated with this actor.

What makes this significant from a threat intelligence perspective is the automated pipeline connecting discovery, credential collection, validation, and subsequent intrusion activity. The scale—1.8 million applications analyzed—would be impossible for manual analysis. AI didn't need to invent a new attack; it simply automated the entire process.

## From Cybercrime to Surveillance: Watching Populations at Scale

The report becomes even more concerning when examining surveillance applications. Anthropic identified nation-state actors and commercial surveillance operators using Claude to build systems for monitoring populations, profiling individuals, and analyzing social media activity. These cases involve actors linked to China, Iran, and West Africa, as well as the commercial "surveillance-for-hire" market.

One particularly alarming case involves a consultant working for Malian national security authorities who used Claude to engineer a mass-interception platform capable of monitoring communications across the country's mobile operators and producing detailed dossiers on targets. This represents a dramatic lowering of the barrier to sophisticated surveillance infrastructure.

Chinese operators used AI to analyze large volumes of social media content, identify potential targets, and generate intelligence reports. One revealing operation targeted Uyghur communities in Syria, where an actor without Arabic-language skills used Claude to draft messages in the appropriate dialect, translate replies in real time, role-play as an expert to evaluate the operation, and prepare information for a suspected human case officer.

This demonstrates another critical shift: AI isn't merely analyzing surveillance data after collection. It's becoming part of the system that determines whom to watch, how to approach them, and how to transform raw information into actionable intelligence.

## Propaganda 2.0: Manufacturing Influence at Scale

AI-supported influence operations represent another evolving threat. Anthropic describes an operation linked with high confidence to UAE government officials where AI supported a network of roughly 300 inauthentic social media accounts. The operation created a front NGO using the identity of a real organization, produced apparent human-rights material, and ghost-wrote testimony intended for the UN Human Rights Council.

The actors also profiled 18 members of the European Parliament and journalists, preparing dossiers on UN Special Rapporteurs critical of UAE conduct in Sudan. The significance extends beyond simple propaganda generation—AI makes the process dramatically cheaper and more scalable while allowing operators to generate different narratives, personas, and documents for different audiences.

The line between genuine grassroots activity and centrally coordinated influence operations is becoming nearly impossible to distinguish.

## Fraud Gets a Human Face Without the Human

The report provides a remarkably concrete example of AI-powered consumer fraud. A China-based app studio built more than 20 dating applications and used AI personas to communicate with users, advertising the service as fully human. Over a two-week window in April 2026, Anthropic discovered more than 4,700 distinct AI personas engaging in conversations with at least 25,000 unique individuals.

The operation combined AI and human workers strategically. Bots handled large volumes of conversations while real people performed activities like video calls and social media interactions designed to convince victims they were dealing with genuine users. The reported ratio was roughly three AI personas for every real person. Claude generated approximately 2.36 million messages during the period examined.

This previews how AI could fundamentally change online fraud. Attackers no longer need thousands of people to maintain thousands of conversations—a small human operation can supervise a much larger artificial workforce.

## Weapons Development: Engineering Assistance Without Engineers

While Anthropic did not identify a confirmed terrorist attack conducted with Claude, the report documents six cases involving weapons development, procurement, or intelligence gathering in China, Russia, and Yemen. These include guided rockets, ballistic-missile simulations, anti-torpedo systems, autonomous drone swarms, electronic-warfare targeting, and directed-energy weapons.

A particularly significant case from a counterterrorism perspective involves a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket using a commodity phone-class flight computer with final-phase homing guidance, a multi-stage ballistic missile with a stated range goal above 2,000 km, and a multi-variant missile including a hypersonic glide vehicle variant.

The group used Claude Code to work on guidance, navigation, and control software for the guided rocket, assigning multiple AI instances different roles including coding, research, and code review. Critically, the group conducted a real-world test of a guided rocket and returned to the model afterward to analyze the failure.

AI isn't giving a terrorist group the ability to build advanced weapon systems from nothing. What it does is reduce the amount of specialized engineering expertise required to modify, integrate, and troubleshoot technologies the group already possesses. For counterterrorism agencies, this creates a new problem: technical capability proliferation may no longer depend on recruiting highly specialized engineers.

## Biological Research: When Legitimate Science Looks Dangerous

Biological misuse presents perhaps the most difficult challenge because intent is hard to establish. Anthropic says today's models can assist with increasingly complex scientific research, making it harder to guarantee they cannot meaningfully support dangerous biological work.

The report describes five cases involving potentially sensitive research: gain-of-function work involving chikungunya, planning related to mammalian adaptation of avian influenza, an orthopoxvirus immune-evasion research proposal, optimization of venom peptides, and computational redesign of toxins.

Anthropic is careful not to claim these researchers intended to develop biological weapons. Instead, the cases demonstrate something more subtle: dangerous research can look identical to legitimate scientific research when viewed one request at a time. This makes traditional content filtering much harder. A sophisticated actor can divide prohibited work into apparently legitimate scientific tasks and combine the answers elsewhere.

## The AI Supply Chain Risk: When Your "AI" Isn't Your AI

Perhaps the most strategically important finding concerns illicit distillation. Several Chinese AI companies attempted to extract capabilities from Claude by creating large numbers of fraudulent accounts, routing enormous query volumes through proxy networks, and collecting model outputs for training.

Alibaba's operation reached nearly three million exchanges per day from more than 3,500 fraudulent accounts, with more than 151 million exchanges observed between May and July. The activity targeted agentic tasks, software engineering, kernel development, and long-horizon reasoning. Zhipu used hundreds of fraudulent accounts to extract reasoning traces. Moonshot allegedly forwarded customer requests to Claude while presenting responses as its own Kimi models.

The privacy implications are severe. Some rerouted requests contained sensitive corporate information, live credentials, and surveillance data. In one case, DeepSeek allegedly relayed requests containing internal AI-program specifications. Another exposed credentials associated with a Russian government database.

This creates a new category of AI supply-chain risk: organizations may believe they're using one AI service while their data and workloads are actually being processed by another.

## The Real Security Threshold

Anthropic reports that humans still tend to retain decisions that matter most, such as selecting targets and determining how to monetize results. But the operational workload between those decisions can increasingly be delegated to machines.

The question is no longer simply whether AI can be abused. It clearly can. The more important question is how much of a malicious operation can now be delegated to AI before a human must step in. Anthropic's report suggests the answer is already: quite a lot.

As the report concludes, "Sophisticated and persistent threat actors continuously test our safeguards and try to circumvent the technical measures we use to detect and prevent misuse. We'll continue to evolve our safeguards and coordinate with our partners to improve our ability to detect, disrupt, and prevent future misuse."

For security researchers and threat intelligence professionals, this report serves as both a warning and a roadmap. The threat landscape has fundamentally changed, and defensive strategies must evolve just as quickly as the operational capabilities AI now enables.