Governments and criminal organizations linked to countries such as China and Russia have been found to exploit U.S. advanced artificial intelligence (AI) for hacking, disinformation campaigns, and even the development of missiles and suicide drones. Analysis shows that as AI evolves from a mere “advisor” providing information to a “commander” writing code and executing attacks, security threats leveraging cutting-edge AI are rapidly escalating.
U.S. AI startup Anthropic on September 10 (local time) released a report titled ‘AI Misuse Detection and Response,’ detailing cases of misuse of its AI model “Claude” between December last year and August this year. Anthropic stated it identified and blocked accounts using Claude for conventional and biological weapons development, cyberattacks, and illegal surveillance.
◇AI Used in Missile and Suicide Drone Development
The most direct threat involved weapons development. Anthropic confirmed six cases related to conventional weapons: three linked to China, two to Russia, and one to Yemen. A weapons development organization in northern Yemen replaced human engineers with Anthropic’s coding AI “Claude Code” to develop flight control software for guided rockets. Claude was also used to simulate flight trajectories for multi-stage ballistic missiles with a range exceeding 2,000 km and hypersonic glide vehicles. The organization ran multiple Claude instances simultaneously, assigning each to coding, research, and code review. After a failed test launch, they input flight data into Claude within hours to analyze the cause.
In China, a case was detected where a defense proposal software for anti-submarine torpedoes and a 200-page technical proposal were prepared for the People’s Liberation Army Navy. Another Chinese researcher created approximately 16 software modules for electronic warfare and enemy air defense suppression, refining them 12 times. Simulated targets included 12 locations such as Taiwan’s command bunkers and early-warning radars. In Russia, freelance developers used Claude to develop software for autonomous suicide drone swarms capable of identifying human targets and attacking them independently.
Five cases involving potential misuse for biological weapons were also identified. A researcher used Claude to study modifying the avian influenza virus to infect mammals, including humans, and spread through the air. Claude assisted in designing experiments, analyzing results, and planning follow-up tests. Anthropic blocked the account, noting the research was in early stages but posed risks of being weaponized to create lethal viruses. Another case involved drafting a research proposal to enhance the transmissibility and immune-evasion capabilities of the Chikungunya virus, a mosquito-borne disease.
In cyberattacks and disinformation, AI’s role became more active. A Russia-linked hacking group automated phishing and messenger account hijacking targeting Ukrainian government and military entities using Claude. When malware was detected, the AI would rewrite the code for redistribution. A China-linked organization used AI to track Uyghurs and Uyghur militant groups in Syria, as well as to plan online operations to surveil overseas journalists and undermine the credibility of related media.
Experts assess that AI has advanced beyond merely providing information for malicious attacks to directly executing tasks and commanding entire processes. Once humans set objectives, multiple AI agents divide roles—gathering intelligence, designing software, writing and reviewing code, running simulations, and analyzing test results. Anthropic noted, “In most operations, AI directly executed tasks or commanded multiple agents, while humans only set attack goals and reviewed stolen data,” adding, “Sophisticated attacks no longer require sophisticated attackers.”
◇Large-Scale Illegal AI Distillation
Chinese AI companies conducted large-scale “illegal distillation” by using Claude’s outputs as training data to enhance their own models. Distillation involves training smaller “student” models using responses from high-performing “teacher” models. Seven Chinese firms, including Alibaba, Moonshot AI, and DeepSeek, secretly accessed Claude via fake accounts to collect responses and reasoning processes en masse. This allowed them to rapidly replicate competitors’ capabilities without massive computing resources or research costs.
To access Claude, blocked in China, these firms routed connections through intermediary servers in the U.S., Japan, and Singapore. They created accounts using fake identities, disposable emails, virtual or stolen credit cards, and hijacked corporate access keys, immediately switching to new accounts upon detection. Alibaba-linked groups interacted with Claude over 151 million times between May and July last year, using the data to train Alibaba’s AI model. Moonshot AI and DeepSeek employed a stealthier method: when users queried their models “Kimi” or DeepSeek, the companies secretly forwarded questions to Claude and relayed its responses.
Anthropic stated, “These cases are not typical misuse but the most notable and novel threat activities identified to date,” warning, “As AI models grow more powerful, risks will escalate unless developers and society strengthen safeguards.” It emphasized the need for joint responses from the AI industry and governments to address emerging threats.
