Threadlinqs had indicator-level visibility of only one of Anthropic's cases before the report. 17 of the 209 indicators in Anthropic's CSV were in our corpus as actor-controlled infrastructure before September 10, 2026, all on Anthropic's GTG-20006 list and all from earlier vendor reporting; 37 pre-publication detection rules contain them. Elsewhere, earlier coverage is behavioural: of 32 GTG case groups plus the weapons and biology rows, 21 had verified technique-level or stronger links before publication and only 6 reached actor or indicator level.
The gap is vantage point: Anthropic sees misuse while operations are still being planned; defenders see it later in telemetry, if at all. So this companion leads with behavioural detections that survive infrastructure rotation, adds 23 sibling indicators and one correction, and gives retro-hunt guidance for stale VPN exits.
Key findings
- The 17 CSV indicators we held as actor-controlled infrastructure before September 10, 2026, all from GTG-20006, were first published by vendors: ReliaQuest (July 23, 2026) and Microsoft (July 31) on the hotel Wi-Fi campaign Microsoft calls CaptiveCrunch (Storm-2945, TL-2026-1808), Google on UNC7005 (August 20, TL-2026-2091) and the DarkSword disclosures of March 17-18 (TL-2026-0245).
- 175 of the 209 appear nowhere in our corpus, 15 only in our write-ups of Anthropic's disclosure (TL-2026-2446, TL-2026-2466) and one, a GTG-50020 egress address, only inside a bulletproof-hosting range we list (TL-2026-0617). Many are VPN or hosting exits last seen two to six months earlier: retro-hunt material, not blocklist entries.
- We add 23 indicators Anthropic did not list, all from pre-publication GTG-20006 records: eleven more UNC7005 phishing domains (WhatsApp and Finnish operations-centre spoofs among them); three ChocoShell beacon, tooling and exfiltration paths on 213.145.86[.]112; two C2 hosts and a hosting IP; six malware and phishing-page hashes; and CornFlake's sync[.]dat config (TL-2026-2091, TL-2026-1857, TL-2026-1838, TL-2026-1808).
- The only other CSV string in pre-publication records, projectnightcrawler[.]dev, is operator or lure infrastructure to Anthropic but, in our records, the self-hosted proof-of-concept site of the researcher behind MiniPlasma, a tool in GTG-20006's kit. We mark it context-only: a hit most likely means someone pulled public exploit code (TL-2026-0835, TL-2026-1865, TL-2026-0523).
- 51 pre-publication records reach technique level or better for 21 case groups and carry 485 detections, covering device-code token replay (
TL-2026-0943-KQL-003), WordPress mu-plugin backdoors (TL-2026-0817-SPL-002), STS-then-Bedrock checks on stolen keys (TL-2026-0514-KQL-002) and scanners calling LLM APIs (TL-2026-2390-KQL-001). - Only 6 of the 32 GTG groups had actor- or indicator-level coverage before publication: GTG-20006 and five distillation cases in CISA, NSA and FBI advisory AA26-251A (September 8, 2026; ingested September 8-9, TL-2026-2405, TL-2026-2413). Our records of the advisory name the labs but not the covert customer-traffic relays or reasoning-signature replay, and cover MiniMax but not SenseTime.
- Influence operations and domestic surveillance are the blind spot: 13 case groups, mostly those plus the weapons cases, have only thematic context, and none of the 28 indicators for the fake local-news network (GTG-54002), the 21 for the Malaysian election platform (GTG-84005) or the 10 for the MEK/NCRI network (GTG-84006) was in the corpus.
Coverage matrix: every case against our corpus
Each row is one case group: the report's 43 case studies, as we count them, fold into 32 GTG groups (GTG-16012 and GTG-16003 share a write-up) plus one policy-level row for the six GTG-labelled weapons cases and one for the five unlabelled biology cases, neither scored on indicators. GTG numbers are Anthropic's own tracking labels (PDF p. 4), not public actor names; case sections add public names where a named source supplies one.
Each cell shows the strongest relation that survived verification:
- A: an actor-controlled indicator from Anthropic's list in a record created before publication.
- B: the same actor or campaign, per a named vendor or government source.
- C: a shared tool or distinctive technique cluster, with no claim about who is behind it.
- D: related context only (region, sector or trend), never identity.
- drv: dated September 10, 2026 or later, ours or others'; listed for reference, never prior coverage.
Detections count rules on tier A-C records only.
Swipe the table sideways to see all seven coverage columns →
| Case | IoC overlap | Actor | Tooling | TTPs | Detections | Covered pre-09-10 |
|---|---|---|---|---|---|---|
| Cyber operations | ||||||
| GTG-20006 — Agentic Russian espionage and the CaptiveCrunch (Storm-2945) overlap | A | A | C | C | 99 | yes |
| GTG-50014 — Suspected ShinyHunters affiliates mining secrets at scale | drv | · | · | C | 99 | yes |
| GTG-10007 — A Chinese-speaking exploit foundry run by agent swarms | · | · | · | C | 54 | yes |
| GTG-50029 — A lone French-speaking hacktivist's WordPress breach-and-dox campaign | · | · | · | C | 18 | yes |
| AI supply chain | ||||||
| GTG-50021 — Fake Claude resellers and the stolen-key economy | · | · | · | C | 122 | yes |
| GTG-50020 — A Russian-speaking crew moves from hotel-booking breaches to AI vendor keys | · | · | D | C | 27 | yes |
| Influence operations | ||||||
| GTG-04001 — Wagner-linked radio hub in Bangui used Claude to run a Russian influence operation in the Central African Republic | · | · | · | D | · | no |
| GTG-54002 — Fake local-news network Anthropic traces to LKM Company | · | · | · | C | 27 | yes |
| GTG-84005 — Malaysia election-manipulation platform Anthropic ties to BBS Bilisim | · | · | · | C | 18 | yes |
| GTG-24015 — Claude used as a sub-editing desk for Russian state-media output aimed at Moldova, Latin America, Africa and RT's global audience | · | · | · | D | · | no |
| GTG-34001 — Iranian state propaganda bodies use Claude to run 'soft war' influence campaigns | · | · | · | D | · | no |
| GTG-54006 — Automated Bengali fake-news pipeline boosting the Awami League for rural Bangladeshi livestream audiences | · | · | · | D | · | no |
| GTG-84006 — Activist-impersonating agent platform Anthropic links to MEK/NCRI | · | · | · | C | 9 | yes |
| GTG-54004 — Single-operator Kenyan political astroturfing network using AI-written tweet batches | · | · | · | D | · | no |
| GTG-84002 — UAE-linked AI persona drives anti-Muslim Brotherhood influence and UN lobbying campaign over Sudan | · | · | · | D | · | no |
| Surveillance | ||||||
| GTG-54009 — Pilot surveillance platform profiling Iranian and Gulf social-media users, built by or for the vendor S2T, per Anthropic | · | · | · | D | · | no |
| GTG-14010 — PRC-aligned operator uses Claude for Uyghur surveillance and informant recruitment in Syria | · | · | · | D | · | no |
| GTG-14020 — PRC-aligned religious-affairs collection desk uses Claude to build dossiers on faith leaders and diaspora communities | · | · | · | D | · | no |
| GTG-14021 — PRC local security organs misuse Claude for "stability maintenance" surveillance and transnational repression | · | · | · | D | · | no |
| GTG-14022 — Contractor-run PRC 'public opinion monitoring' pipeline built on Claude to surveil dissidents, diaspora and foreign media | · | · | · | D | · | no |
| GTG-34007 — Iranian security units building surveillance tooling | · | · | · | C | 9 | yes |
| GTG-50027 — Claude-built nationwide telecom interception platform ("Lakana 360") for Mali's state security agency | · | · | · | D | · | no |
| GTG-30004 — Automated profiling and a modified NanoDump | · | · | C | C | 30 | yes |
| GTG-30005 — Open-source targeting of US naval forces | · | · | · | C | 18 | yes |
| GTG-30006 — An Iran-only surveillance toolkit built in fragments | · | · | · | C | 9 | yes |
| Conventional weapons | ||||||
| 6 cases — Weapons development and procurement | · | · | · | D | · | · |
| Biological misuse | ||||||
| 5 cases — Dual-use research misuse | · | · | · | C | 27 | yes |
| Scams and fraud | ||||||
| GTG-15001 — A dating-app network run mostly by AI personas | · | · | · | C | 9 | yes |
| Illicit distillation | ||||||
| GTG-16005 — Alibaba's forced-reasoning distillation, per Anthropic | · | B | · | C | 27 | yes |
| GTG-16002 — Moonshot relays Kimi customers to Claude, per Anthropic | · | B | · | D | 18 | yes |
| GTG-16001 — DeepSeek's covert relay and reasoning replay, per Anthropic | · | B | · | D | 18 | yes |
| GTG-16006 — Zhipu (Z.ai) cleans harvested reasoning with Claude, per Anthropic | · | B | · | D | 18 | yes |
| GTG-16008 — Xiaomi replays real MiMo sessions to Claude, per Anthropic | · | · | · | C | 18 | yes |
| GTG-16012 / GTG-16003 — GTG-16012 and GTG-16003 — SenseTime's bought transcripts and MiniMax's shell-company proxy, per Anthropic | · | B | · | C | 27 | yes |
Each cell shows the strongest verified relation for that dimension. Letters carry the tier, so the matrix reads without colour. "drv" marks coverage dated 2026-09-10 or later, which never counts as prior coverage.
Swipe the chart sideways →
Counts per Anthropic case: the 209 CSV indicators plus Threadlinqs extras pulled only from records whose overlap survived verification. Hatched = present only in records we wrote after 2026-09-10.
Show data table
| Case | in Threadlinqs before 09-10 | added after the report | shared / context only | not in corpus | Threadlinqs extras (same records) |
|---|---|---|---|---|---|
| GTG-20006 | 17 | 3 | 1 | 34 | 0 |
| GTG-50014 | 0 | 12 | 0 | 28 | 0 |
| GTG-54002 | 0 | 0 | 0 | 28 | 0 |
| GTG-50029 | 0 | 0 | 0 | 22 | 0 |
| GTG-84005 | 0 | 0 | 0 | 21 | 0 |
| UNC7005 (Google) | 0 | 0 | 0 | 0 | 18 |
| GTG-84006 | 0 | 0 | 0 | 10 | 0 |
| GTG-30006 | 0 | 0 | 0 | 10 | 0 |
| GTG-50020 | 0 | 0 | 0 | 8 | 0 |
| GTG-15001 | 0 | 0 | 0 | 8 | 0 |
| GTG-50021 | 0 | 0 | 0 | 6 | 0 |
| Storm-2945 (Microsoft) | 0 | 0 | 0 | 0 | 5 |
| GTG-24015 | 0 | 0 | 0 | 1 | 0 |
Swipe the chart sideways →
Dots are record creation dates (day granularity); dots on the same day are stacked. The dashed line marks Anthropic's publication on 2026-09-10. Where a vendor published first, the lead belongs to that vendor.
Show the records as a table
| Case | Record | Tier | Created |
|---|---|---|---|
| GTG-20006 | TL-2026-0245 | A | 2026-03-18 |
| GTG-20006 | TL-2026-0523 | C | 2026-05-17 |
| GTG-20006 | TL-2026-0561 | C | 2026-05-22 |
| GTG-20006 | TL-2026-0943 | C | 2026-06-25 |
| GTG-20006 | TL-2026-1808 | A | 2026-07-31 |
| GTG-20006 | TL-2026-1838 | A | 2026-08-03 |
| GTG-20006 | TL-2026-1853 | A | 2026-08-04 |
| GTG-20006 | TL-2026-1857 | A | 2026-08-04 |
| GTG-20006 | TL-2026-2091 | A | 2026-08-21 |
| GTG-20006 | TL-2026-2170 | C | 2026-08-26 |
| GTG-20006 | TL-2026-2167 | A | 2026-08-27 |
| GTG-20006 | TL-2026-2446 | DER | 2026-09-11 |
| GTG-20006 | TL-2026-2466 | DER | 2026-09-12 |
| GTG-20006 | TL-2026-2559 | DER | 2026-09-18 |
| GTG-20006 | TL-2026-2614 | DER | 2026-09-22 |
| GTG-50014 | TL-2026-0411 | C | 2026-04-22 |
| GTG-50014 | TL-2026-0451 | C | 2026-05-04 |
| GTG-50014 | TL-2026-0514 | C | 2026-05-14 |
| GTG-50014 | TL-2026-0527 | C | 2026-05-18 |
| GTG-50014 | TL-2026-1275 | C | 2026-07-13 |
| GTG-50014 | TL-2026-1288 | C | 2026-07-14 |
| GTG-50014 | TL-2026-1705 | C | 2026-07-26 |
| GTG-50014 | TL-2026-1711 | C | 2026-07-26 |
| GTG-50014 | TL-2026-2341 | C | 2026-09-05 |
| GTG-50014 | TL-2026-2339 | C | 2026-09-05 |
| GTG-50014 | TL-2026-2390 | C | 2026-09-08 |
| GTG-50014 | TL-2026-2466 | DER | 2026-09-12 |
| GTG-50014 | TL-2026-2531 | DER | 2026-09-16 |
| GTG-50014 | TL-2026-2564 | DER | 2026-09-18 |
| GTG-50014 | TL-2026-2584 | DER | 2026-09-19 |
| GTG-50014 | TL-2026-2620 | DER | 2026-09-22 |
| GTG-50014 | TL-2026-2633 | DER | 2026-09-23 |
| GTG-10007 | TL-2026-0495 | C | 2026-05-11 |
| GTG-10007 | TL-2026-1354 | C | 2026-07-15 |
| GTG-10007 | TL-2026-1885 | C | 2026-08-05 |
| GTG-10007 | TL-2026-1997 | C | 2026-08-12 |
| GTG-10007 | TL-2026-2325 | C | 2026-09-04 |
| GTG-10007 | TL-2026-2390 | C | 2026-09-08 |
| GTG-10007 | TL-2026-2466 | DER | 2026-09-12 |
| GTG-10007 | TL-2026-2576 | DER | 2026-09-19 |
| GTG-10007 | TL-2026-2619 | DER | 2026-09-22 |
| GTG-10007 | TL-2026-2633 | DER | 2026-09-23 |
| GTG-50029 | TL-2026-0817 | C | 2026-06-16 |
| GTG-50029 | TL-2026-1978 | C | 2026-08-10 |
| GTG-50029 | TL-2026-2466 | DER | 2026-09-12 |
| GTG-50029 | TL-2026-2633 | DER | 2026-09-23 |
| GTG-50029 | TL-2026-2639 | DER | 2026-09-24 |
| GTG-50021 | TL-2026-0012 | C | 2026-02-02 |
| GTG-50021 | TL-2026-0403 | C | 2026-04-21 |
| GTG-50021 | TL-2026-0514 | C | 2026-05-14 |
| GTG-50021 | TL-2026-0546 | C | 2026-05-21 |
| GTG-50021 | TL-2026-0582 | C | 2026-05-25 |
| GTG-50021 | TL-2026-1522 | C | 2026-07-19 |
| GTG-50021 | TL-2026-1521 | C | 2026-07-19 |
| GTG-50021 | TL-2026-1845 | C | 2026-08-03 |
| GTG-50021 | TL-2026-1911 | C | 2026-08-06 |
| GTG-50021 | TL-2026-2257 | C | 2026-08-31 |
| GTG-50021 | TL-2026-2416 | C | 2026-09-09 |
| GTG-50021 | TL-2026-2466 | DER | 2026-09-12 |
| GTG-50021 | TL-2026-2548 | DER | 2026-09-17 |
| GTG-50021 | TL-2026-2626 | DER | 2026-09-23 |
| GTG-50021 | TL-2026-2639 | DER | 2026-09-24 |
| GTG-50020 | TL-2026-0828 | C | 2026-06-16 |
| GTG-50020 | TL-2026-1076 | C | 2026-07-02 |
| GTG-50020 | TL-2026-2341 | C | 2026-09-05 |
| GTG-50020 | TL-2026-2550 | DER | 2026-09-17 |
| GTG-50020 | TL-2026-2633 | DER | 2026-09-23 |
| GTG-50020 | TL-2026-2639 | DER | 2026-09-24 |
| GTG-04001 | TL-2026-2631 | DER | 2026-09-23 |
| GTG-04001 | TL-2026-2638 | DER | 2026-09-24 |
| GTG-54002 | TL-2026-0582 | C | 2026-05-25 |
| GTG-54002 | TL-2026-0760 | C | 2026-06-10 |
| GTG-54002 | TL-2026-1356 | C | 2026-07-15 |
| GTG-54002 | TL-2026-2631 | DER | 2026-09-23 |
| GTG-54002 | TL-2026-2638 | DER | 2026-09-24 |
| GTG-84005 | TL-2026-0760 | C | 2026-06-10 |
| GTG-84005 | TL-2026-1356 | C | 2026-07-15 |
| GTG-84005 | TL-2026-2631 | DER | 2026-09-23 |
| GTG-84005 | TL-2026-2638 | DER | 2026-09-24 |
| GTG-24015 | TL-2026-2631 | DER | 2026-09-23 |
| GTG-24015 | TL-2026-2638 | DER | 2026-09-24 |
| GTG-34001 | TL-2026-2543 | DER | 2026-09-16 |
| GTG-54006 | TL-2026-2631 | DER | 2026-09-23 |
| GTG-54006 | TL-2026-2638 | DER | 2026-09-24 |
| GTG-84006 | TL-2026-1356 | C | 2026-07-15 |
| GTG-84006 | TL-2026-2526 | DER | 2026-09-15 |
| GTG-84006 | TL-2026-2534 | DER | 2026-09-16 |
| GTG-84006 | TL-2026-2543 | DER | 2026-09-16 |
| GTG-84006 | TL-2026-2638 | DER | 2026-09-24 |
| GTG-54004 | TL-2026-2638 | DER | 2026-09-24 |
| GTG-84002 | TL-2026-2631 | DER | 2026-09-23 |
| GTG-84002 | TL-2026-2638 | DER | 2026-09-24 |
| GTG-54009 | TL-2026-2526 | DER | 2026-09-15 |
| GTG-54009 | TL-2026-2534 | DER | 2026-09-16 |
| GTG-54009 | TL-2026-2543 | DER | 2026-09-16 |
| GTG-14021 | TL-2026-2520 | DER | 2026-09-15 |
| GTG-14021 | TL-2026-2519 | DER | 2026-09-15 |
| GTG-34007 | TL-2026-1508 | C | 2026-07-19 |
| GTG-34007 | TL-2026-2526 | DER | 2026-09-15 |
| GTG-34007 | TL-2026-2543 | DER | 2026-09-16 |
| GTG-34007 | TL-2026-2534 | DER | 2026-09-16 |
| GTG-50027 | TL-2026-2609 | DER | 2026-09-21 |
| GTG-50027 | TL-2026-2649 | DER | 2026-09-25 |
| GTG-30004 | TL-2026-0076 | C | 2026-02-12 |
| GTG-30004 | TL-2026-0495 | C | 2026-05-11 |
| GTG-30004 | TL-2026-1508 | C | 2026-07-19 |
| GTG-30005 | TL-2026-1417 | C | 2026-07-16 |
| GTG-30005 | TL-2026-1508 | C | 2026-07-19 |
| GTG-30005 | TL-2026-2526 | DER | 2026-09-15 |
| GTG-30005 | TL-2026-2534 | DER | 2026-09-16 |
| GTG-30005 | TL-2026-2543 | DER | 2026-09-16 |
| GTG-30005 | TL-2026-2609 | DER | 2026-09-21 |
| GTG-30006 | TL-2026-0159 | C | 2026-02-28 |
| GTG-30006 | TL-2026-2526 | DER | 2026-09-15 |
| GTG-30006 | TL-2026-2543 | DER | 2026-09-16 |
| GTG-30006 | TL-2026-2534 | DER | 2026-09-16 |
| GTG-30006 | TL-2026-2628 | DER | 2026-09-23 |
| GTG-15001 | TL-2026-0395 | C | 2026-04-20 |
| GTG-15001 | TL-2026-2591 | DER | 2026-09-20 |
| GTG-15001 | TL-2026-2655 | DER | 2026-09-25 |
| GTG-16005 | TL-2026-0085 | C | 2026-02-15 |
| GTG-16005 | TL-2026-2405 | B | 2026-09-08 |
| GTG-16005 | TL-2026-2413 | B | 2026-09-09 |
| GTG-16002 | TL-2026-2405 | B | 2026-09-08 |
| GTG-16002 | TL-2026-2413 | B | 2026-09-09 |
| GTG-16001 | TL-2026-2405 | B | 2026-09-08 |
| GTG-16001 | TL-2026-2413 | B | 2026-09-09 |
| GTG-16006 | TL-2026-2405 | B | 2026-09-08 |
| GTG-16006 | TL-2026-2413 | B | 2026-09-09 |
| GTG-16006 | TL-2026-2615 | DER | 2026-09-22 |
| GTG-16008 | TL-2026-2405 | C | 2026-09-08 |
| GTG-16008 | TL-2026-2413 | C | 2026-09-09 |
| GTG-16012 | TL-2026-1911 | C | 2026-08-06 |
| GTG-16012 | TL-2026-2405 | B | 2026-09-08 |
| GTG-16012 | TL-2026-2413 | B | 2026-09-09 |
Hunt pack: sweep your telemetry for every published indicator
The hunt pack holds Anthropic's 209 CSV indicators plus 23 more from the pre-report records behind the overlap, tagged to Storm-2945 (Microsoft) or UNC7005 (Google), not GTG-20006. All come refanged in a CSV and a STIX 2.1 bundle; only the two scheduled-task names are CSV-only. Anthropic never defines "hunt", which marks attacker egress (for GTG-50029, commercial VPN and datacentre exits), one VPS and two exfiltration endpoints in hijacked GCP projects. We read it as search, not block, and the bundle types those rows as anomalous, not malicious. We add status, linked records and a stale marker (last seen over 60 days before publication).
The SPL and KQL network sweeps match domains, hostnames, onions and IPs in proxy, DNS and endpoint logs, skipping the context-only row; the host sweep covers hashes, filenames, the file path, scheduled tasks and, in mail logs, sender addresses. URLs, app and package IDs, account handles and Telegram IDs need manual checks. Widen the 120-day look-back for hunt-flagged addresses, last seen between March and mid-June.
SPLindex=proxy OR index=dns OR index=network earliest=-120d
| eval ioc=lower(coalesce(query, url_domain, dest_host, dest_ip, dest))
| lookup threadlinqs_anthropic_ai_misuse_2026_09.csv indicator AS ioc
OUTPUT gtg role anthropic_handling threadlinqs_status
| where isnotnull(gtg) AND threadlinqs_status!="context-only" AND anthropic_handling!="context"
| stats count min(_time) AS first_seen max(_time) AS last_seen values(src) AS src
BY ioc gtg role anthropic_handling
| convert ctime(first_seen) ctime(last_seen)
| sort - count
KQL · networklet iocs = externaldata(indicator:string, indicator_defanged:string, type:string, platform:string, gtg:string,
case_name:string, role:string, anthropic_description:string, anthropic_handling:string, first_seen:string,
last_seen:string, stale_before_report:string, threadlinqs_status:string, threadlinqs_threats_before:string,
threadlinqs_threats_after:string, threadlinqs_related:string, role_judgement:string, source:string,
anthropic_id:string, reference_url:string)
[@"https://threadlinqs.com/blog/anthropic-claude-misuse-sep2026/iocs.csv"] with (format="csv", ignoreFirstRecord=true)
| where threadlinqs_status != "context-only" and anthropic_handling != "context";
let hosts = toscalar(iocs | where type in ("domain", "hostname", "onion") | summarize make_set(indicator));
let ips = toscalar(iocs | where type in ("ipv4", "ipv6") | summarize make_set(indicator));
DeviceNetworkEvents
| where Timestamp > ago(120d)
| where RemoteIP in (ips) or RemoteUrl has_any (hosts)
| summarize hits = count(), first = min(Timestamp), last = max(Timestamp), devices = dcount(DeviceId)
by RemoteIP, RemoteUrl
| order by hits desc
KQL · hostlet iocs = externaldata(indicator:string, indicator_defanged:string, type:string, platform:string, gtg:string,
case_name:string, role:string, anthropic_description:string, anthropic_handling:string, first_seen:string,
last_seen:string, stale_before_report:string, threadlinqs_status:string, threadlinqs_threats_before:string,
threadlinqs_threats_after:string, threadlinqs_related:string, role_judgement:string, source:string,
anthropic_id:string, reference_url:string)
[@"https://threadlinqs.com/blog/anthropic-claude-misuse-sep2026/iocs.csv"] with (format="csv", ignoreFirstRecord=true)
| where threadlinqs_status != "context-only" and anthropic_handling != "context";
let hashes = toscalar(iocs | where type == "sha256" | summarize make_set(indicator));
let files = toscalar(iocs | where type == "filename" | summarize make_set(indicator));
union DeviceFileEvents, DeviceProcessEvents
| where Timestamp > ago(120d)
| where SHA256 in (hashes) or FileName in~ (files)
or FolderPath has @"\ProgramData\fontdrivehostServicePackages\"
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName;
DeviceEvents
| where Timestamp > ago(120d) and ActionType == "ScheduledTaskCreated"
| where AdditionalFields has_any ("SECOMS64_AdminTask", "Calc_AdminTask");
let senders = toscalar(iocs | where type == "email" | summarize make_set(indicator));
EmailEvents
| where Timestamp > ago(120d)
| where SenderFromAddress in~ (senders) or SenderMailFromAddress in~ (senders)
| project Timestamp, SenderFromAddress, RecipientEmailAddress, Subject, NetworkMessageIdHow we cross-referenced the report
We froze the corpus first: every comparison ran against a September 25, 2026 export of the Threadlinqs D1 database (2,473 threats, 62,332 IoCs, 22,696 detections). From Anthropic we took the report PDF and its 209-row indicator CSV, and wrote a paraphrased inventory of each case. TL-2026-NNNN identifiers are Threadlinqs threat records, each with indicators, ATT&CK mapping and detections.
Indicator matching is deterministic string comparison. Each value was refanged, lower-cased and searched across IoC values and context notes, record text, timelines, update logs, detection bodies, DNS enrichment and C2 tables. Domains matched exactly, as subdomains or at registrable-domain level, but shared-hosting, dynamic-DNS and multi-part-suffix parents never count. IPv4 addresses also matched inside CIDR ranges in our records; a registrable-domain or in-range hit alone is a weak signal, and /24 neighbours count for nothing. Indicators printed only in the PDF, mostly media outlets and public accounts, were checked the same way; none matched actor infrastructure in our corpus. Nothing was resolved, fetched or visited.
Case-level links came from AI-assisted finders that pivoted on infrastructure, resolved actor, alias, malware and tool names, and searched tradecraft semantically and by ATT&CK/ATLAS, with a second round on leads a case judge flagged. Every claimed link needed a quote that is an exact substring of the snapshot record, or it was dropped.
Then we tried to break every claim. Role judges classified each overlapping indicator (actor-controlled, public resource, victim infrastructure, leaked code, researcher host or unclear), and only actor-controlled overlaps can make tier A. Three independent skeptics attacked each tier-A claim and each case's tier-B set on presence, timing, role and attribution; where a record and Anthropic name different clusters, we report both and merge neither. A separate judge kept, downgraded or dropped tier C and D candidates, and in doubt the weaker relation won.
A record created on or after September 10, 2026, or one citing Anthropic's report, is marked drv and never counts as prior coverage; nor does an indicator that entered an older record only through a post-publication update. Where we held something early, the lead time belongs to the vendor that published it first.
Cyber operations
In Anthropic's cyber chapter, Claude carries much of each campaign's hands-on work while people still choose targets and review the take (report section, PDF pp. 4–5).
Prior visibility splits the four cases below cleanly (the chapter's AI-supply-chain cases, GTG-50021 and GTG-50020, are in their own section). GTG-20006 is the only case in the report whose published indicators were already in Threadlinqs; the other three existed in our corpus only as technique-level analogues.
GTG-20006 — Agentic Russian espionage and the CaptiveCrunch (Storm-2945) overlap
GTG-20006, the Russian espionage case in Anthropic's September 10, 2026 report, is where Threadlinqs already had signal: 17 of its 55 published indicators sat in 7 of our 11 prior records, the oldest from March 18, 2026, most through CaptiveCrunch and UNC7005 coverage. Anthropic cites public Midnight Blizzard reporting as matching its attribution (PDF p. 6); Claude Code agents automated most of the operation against 20-plus organisations. We add 24 sibling indicators.
What Anthropic reported
Sorted by where a defender would look (PDF pp. 6–9):
- Identity and mail: Microsoft 365 device-code phishing, attacker devices enrolled in victim tenants, and bulk mailbox exports.
- Travel and messaging: tampered DNS at hotel guest-WiFi vendors serving ClickFix lures (Microsoft's CaptiveCrunch, PDF p. 8), and WhatsApp accounts quietly paired to headless-browser companions.
- Endpoints: confirm hosts still pull security updates, since companion payloads froze them; implants were rebuilt whenever a product flagged them, so hash and signature rules age fast.
- Exposure: Ukrainian and European government, defence and diplomatic personnel, the US foreign-policy community and drone suppliers, reaching into the Middle East, Asia and North Africa (PDF pp. 6–7).
What Threadlinqs already had
Most of the overlap sits in one cluster. The 4 CaptiveCrunch records, TL-2026-1808 (July 31), TL-2026-1838 (August 3), TL-2026-1853 and TL-2026-1857 (August 4), each hold ms365-live[.]com, ms365-device[.]com, m365-owa[.]com, owa-ms365[.]com, the hosts 31.57.243[.]154, 38.146.28[.]75, 38.146.28[.]132 and 213.145.86[.]112, and the CornFlake and ChocoShell hashes. The lead is upstream: ReliaQuest disclosed the hotel-WiFi DNS poisoning, including 38.146.28[.]75, on July 23, 2026; Microsoft named it CaptiveCrunch on July 31, the day it reached Threadlinqs.
TL-2026-2091 (August 21, Google's UNC7005 reporting) overlaps most, adding chamber-ua[.]org, my-invite[.]org, statistic-ms[.]live, wa-connect[.]eu and wa-meeting[.]com; TL-2026-2167 repeats part of that set.
The earliest hit is DarkSword. TL-2026-0245 (March 18, from coordinated Lookout, GTIG and iVerify disclosures of March 17–18) holds cdncounter[.]net and static.cdncounter[.]net, GTIG's UNC6353 delivery hosts for the iOS chain (CVE-2026-20700, CVE-2025-43529, CVE-2025-31277). That leaked kit has several users, so the domain does not settle identity.
37 pre-publication rules already held indicators Anthropic later published; the 11 prior records carry 99 detections. Technique records:
- TL-2026-0523 (May 17): MiniPlasma, a public proof of concept regressing CVE-2020-17103, named on Anthropic's malware list.
- TL-2026-0943 (June 25): Entra ID device-code phishing, including Storm-2372.
- TL-2026-2170 (August 26): messenger linked-device takeover by UNC5792 and UNC4221.
What we add
Rules to run first:
TL-2026-1857-SPL-001flags DNS resolution of the Microsoft 365 lookalikes until they rotate.TL-2026-0943-KQL-003flags a device-code token used against Microsoft Graph from an IP where the user never approved the code; domain rotation does not blind it.
Sibling infrastructure. The 24 extras come from the same Microsoft and Google cluster reporting: wider footprint, not confirmed GTG-20006 use.
- C2 and hosting: 107.189.26[.]194 (ChocoShell C2 and rogue DNS resolver), 107.189.18[.]7 (Vidar C2), 104.194.159[.]150 (hosted ms365-live[.]com)
- ChocoShell paths on 213.145.86[.]112:
/t/pixel.gif,/cdn/chunks/polyfill-7e2b.min.js,/t/event - lures such as wa-invite[.]com, foc-share[.]com and globsec[.]net
- hashes for ENGINELIGHT, a CHERRYPIE (ChocoShell) build, two phishing pages and the Vidar and Atomic stealers (commodity malware: leads, not attribution)
Retro-hunt window. IPs from February 2026 (TL-2026-1808 first sees 107.189.26[.]194 on February 27); domains from registration, May 14 for ms365-live[.]com and July 16 for owa-ms365[.]com (TL-2026-1853).
Context-only. Anthropic lists projectnightcrawler[.]dev as actor infrastructure, but TL-2026-0835 and TL-2026-1865 record it as the MiniPlasma researcher's public exploit mirror; a hit likely means a download, so the hunt pack sweeps skip it.
Weak indicators. The generic filenames printed only in the PDF were checked and matched no actor infrastructure in our corpus; never hunt on our extra sync.dat (CornFlake's config file) alone.
Gaps
- Most other listed indicators match nothing, including the stuseamandesilt[.]org hosts, both mygreatmarket domains, chathamhouse[.]eu, ukrinform-share[.]net, itechx[.]tel and all three listed 104.194.x VPSs.
- PowerChrome, WUEngine, Shadow C2, CloudSyncSvc, GiftDrop/GiftsExpress, Embassy Kit, the operator handle, the rebuild loop, the drone SDK theft, the North African registry breach, the camera tokens, 104.145.210[.]184, 144.172.114[.]192 and teams.ms365-live[.]com (parent domain held since July 31) appear only in our write-ups of Anthropic's disclosure, TL-2026-2446 and TL-2026-2466. CloudSyncSvc may echo CornFlake's "Cloud Sync Service" in TL-2026-1808; no record ties them.
- Labels differ: Microsoft files CaptiveCrunch under Storm-2945, a Midnight Blizzard sub-cluster; Google's reporting in TL-2026-2091 puts the same domains and hosts under UNC7005, a moderate-confidence APT29 sub-cluster; TL-2026-2170 conflicts by naming UNC5976. Treat them as cluster names, not settled identities.
- The April 2026 Microsoft device-code post Anthropic cites covered the EvilTokens crimeware platform, tracked in TL-2026-0943 (June; TL-2026-2614 is later independent coverage): technique background, not Midnight Blizzard reporting.
Related coverage in Threadlinqs (context, not the same activity) — 5
GTG-50014 — Suspected ShinyHunters affiliates mining secrets at scale
GTG-50014 is Anthropic's label for suspected ShinyHunters affiliates who, per its September 10, 2026 report, mined 1.8 million Android apps for secrets, harvested GitHub tokens, used AI agents to dump over 2,100 Azure AD token sets, and extorted victims. None of its 40 indicators were in Threadlinqs before publication; 11 technique records from April 22, 2026 onward carry 99 detections.
What Anthropic reported
Anthropic groups several financially driven clusters into one operation, from secret theft to extortion or resale (PDF pp. 12–20).
- Where secrets leak: one operator ran TruffleHog over 1.8 million decompiled Android APKs on ten EC2 workers, with verified hits streaming to Telegram; a GitHub organisation-email harvester added stolen access tokens.
- How fast it moves: given loose goals, agents worked out each victim's APIs and token privileges on their own; one affiliate pulled 2,100-plus Azure AD token sets for 40-plus tenants from a breached SaaS provider in about 34 hours.
- AI keys as loot: keys lifted from victims' vendors paid for the crew's compute; Anthropic says none came from its own systems.
- Exits and income: six exfiltration routes, from bulk API pulls to a NAS on a mesh VPN (PDF p. 18); a carding shop branded after the French national police; pay-or-leak extortion; claimed HackerOne payouts from two extortion victims.
What Threadlinqs already had
The corpus holds operations of the same shape, reported about other operators.
- TL-2026-0411 (April 22, The DFIR Report): the Bissa Scanner, an AI-assisted secret-validation pipeline alerting to Telegram.
- TL-2026-0514 (May 14, Sysdig): KeyHunter, a worker fleet harvesting and live-validating cloud and AI keys, entering via Langflow CVE-2026-33017.
- TL-2026-0527 (May 18): CoinbaseCartel stole Grafana source with one GitHub token, then extorted; our record's ShinyHunters and Lapsus$ affiliate label is a collective-level overlap only.
- TL-2026-2339 (September 5, Datadog): GitHub organisation enumeration with stolen OAuth tokens and PATs.
- TL-2026-2341 (September 5, Unit 42): agents mined git history for hardcoded tokens, reached root through the secrets manager, then hijacked the victim's cloud AI endpoints.
In TL-2026-1705, ShinyHunters' second Canvas intrusion used stored XSS for administrator access. Anthropic's anonymised XSS-to-privilege-escalation SaaS case looks similar but names no victim, so the two cannot be equated. Our records call the wider collective Scattered LAPSUS$ Hunters.
What we add
Rules to run first:
TL-2026-0514-KQL-002flags one principal calling STS GetCallerIdentity and then Bedrock within five minutes, the test-then-use step behind stolen AI keys, without indicators.TL-2026-2466-SIG-003, from our write-up of Anthropic's disclosure, is the only rule with GTG-50014 indicators and holds just some: the policenationale[.]cc and soraki domains, updatebeacon.duckdns[.]org and five of the 15 egress IPs (162.128.129[.]106, 195.178.110[.]131, 45.148.10[.]242, 185.65.134[.]246, 193.32.249[.]161). Add the other egress IPs, typosquat and crypto-lure domains, Telegram IDs and MEGA S4 paths from Anthropic's tables (PDF pp. 22–24).
Egress IPs: retro-hunt, do not block. Anthropic calls them only attacker egress (February 20 to May 6, 2026); our only context is /24 neighbours of three (45.148.10[.]242, 185.65.134[.]246, 185.65.134[.]199) in other operations' records, so any may now be shared or reassigned.
Public services. For oast[.]fun hunt only Anthropic's subdomain, and for MEGA S4 only its bucket paths. The file host printed only in the PDF was checked and matched no actor infrastructure in our corpus.
GitHub audit logs. Hunt organisation enumeration like TL-2026-2339 from tokens new to those organisations.
Gaps
- Nothing before publication on the operator aliases, the carding shop, the APK pipeline, the Azure AD token dump or the bounty payouts.
- Every GTG-50014 indicator we hold arrived with TL-2026-2466, our write-up of Anthropic's disclosure. That write-up also files one GTG-50029 fact, the roughly 140,000 political-platform records, under GTG-50014; it is flagged for correction.
Related coverage in Threadlinqs (context, not the same activity) — 5
GTG-10007 — A Chinese-speaking exploit foundry run by agent swarms
GTG-10007 is a Chinese-speaking espionage cluster that, per Anthropic's September 10, 2026 report, used Claude to run agent swarms with persistent memory, an unattended firmware-reversing loop credited with over a dozen candidate zero-days in a month, and a 13-agent collection fleet. Anthropic published no indicators. Before publication Threadlinqs held 6 technique analogues, the earliest from May 11, 2026, carrying 54 detections.
What Anthropic reported
What Anthropic's account (PDF pp. 24–28) means for defenders:
- Appliances are the target class. Autonomous research, including a firmware-reversing loop (PDF p. 26), yielded working exploits for several network and security appliance families, plus flaws, validated only in the actor's own lab, in a major endpoint-security product.
- Scale without fatigue. Parallel agent teams shared campaign memory across sessions, and thirteen scheduled collectors turned public US military and government material into digests.
- Victims: about 50 organisations targeted, with breaches at an edtech firm (student data), a retailer (production systems) and a Southeast Asian agency (citizen records). Anthropic says hands-on intrusions stayed with domestic Chinese victims (PDF p. 28).
What Threadlinqs already had
The corpus holds analogues only; no source ties any of them to this cluster.
- TL-2026-2325 (September 4, Hunt.io), the closest: a Chinese-speaking operator's SecFlow framework drives Claude, Qwen and DeepSeek from recon to post-exploitation; victims include a foreign ministry.
- TL-2026-0495 (May 11, GTIG): UNC2814's AI-assisted research into TP-Link firmware bugs and APT27's AI-built relay-network tooling.
- TL-2026-1354 (July 15): Claude Code plus DeepSeek behind SQL injection into Thai government databases and Laravel RCE (CVE-2021-43503).
- TL-2026-1997 (August 12): parallel sub-agents against Taiwanese government targets.
- TL-2026-1885 (August 5, Unit 42): a Hermes-plus-DeepSeek framework with an asset-search skill; when its autonomous runs failed, the operator hit Tomcat (CVE-2026-34486) and Citrix NetScaler by hand.
- TL-2026-2390 (September 8, GTIG): PRC-nexus groups routing Claude, Gemini and Codex to write exploits.
What we add
Rule to run first:
TL-2026-2390-KQL-001flags scanner tooling (nmap, nuclei, sqlmap) and LLM API calls from one host within 15 minutes: agent-driven recon from hosts you own, caught without indicators. Use the KQL body; the Splunk body fires on either condition alone.
Harden the target class: patch network and security gear fast and keep management interfaces off the internet.
Gaps
- Anthropic named no indicators, appliance families, security product or victims to match.
- TL-2026-2466, our write-up of Anthropic's disclosure, dates this cluster to the December 2025 to August 2026 window Anthropic gives the whole cyber section (PDF p. 4); treat it as an outer bound.
Related coverage in Threadlinqs (context, not the same activity) — 5
GTG-50029 — A lone French-speaking hacktivist's WordPress breach-and-dox campaign
GTG-50029 is a lone French-speaking hacktivist who, per Anthropic's September 10, 2026 report, used a Claude sub-agent framework, stolen API keys and a new WordPress reinstall race to breach at least 14 of 42 European political, media and think-tank targets, then fed the loot into a doxxing engine. None of its 22 indicators were in Threadlinqs; 2 WordPress-persistence records from June 16, 2026 onward carry 18 detections.
What Anthropic reported
Anthropic's account (PDF pp. 34–37), read for WordPress and SaaS defenders:
- Entry: a WordPress reinstall race new to the public record gave credential-free admin accounts on at least four sites; stolen API keys from public container images, cycled through a proxy, passed as the owners' traffic.
- Persistence to check: a webshell among font files, a credential-stealing must-use plugin and backups poisoned to reinfect on restore; a BeEF hook on one news site sought editorial staff sessions.
- Stakes: about 140,000 political-opinion records from one campaign platform, 12 to 26 GB of dumps overall, a Tor leak site and a doxxing search engine.
Anthropic calls it one of the clearest cases we have seen of AI-assisted software engineering applied directly to a mass attack on privacy
(Anthropic, PDF p. 36).
What Threadlinqs already had
What we had is the persistence pattern; none of the published indicators match, even at /24.
- TL-2026-0817 (June 16): ErrTraffic, a ClickFix malware-as-a-service framework, with a must-use plugin backdoor, a login-page credential harvester and a hidden administrator (CVE-2020-25213).
- TL-2026-1978 (August 10): the BdThemes plugin supply-chain attack, with rogue administrators, a webshell and hidden must-use plugins.
Context, none about this actor: mu-plugin write detections (TL-2026-2057), AI-key harvesting and resale (TL-2026-0514, TL-2026-1911), and a solo operator who rotated stolen AI keys and hijacked WordPress admins (TL-2026-0582).
What we add
Rules to run first:
TL-2026-0817-SPL-002fires on new or changed files under wp-content/mu-plugins or a theme's functions.php (the KQL and Sigma versions also require a PHP or web-server writer); no infrastructure needed.TL-2026-1978-SPL-002matches known BdThemes backdoor hashes and paths plus rogue-admin creation; use it for the pattern, since those files are not this actor's.
Hardening and hunting:
- Inventory mu-plugins on every WordPress host; the admin plugin list hides them.
- Verify backups before restoring; this actor poisoned them.
- Restrict installer and setup endpoints on live sites, and alert on every new administrator.
- Retro-hunt the VPN exits only within Anthropic's March 25 to May 20, 2026 window; block the two GCP exfiltration IPs, hijacked projects in shared cloud, only briefly.
Gaps
- The race condition, BeEF hook, doxxing platform and onion services appear nowhere in the corpus.
- Among later records, only TL-2026-2466, our write-up of Anthropic's disclosure, touches this case, misfiling its political-platform records under GTG-50014. TL-2026-2633 and TL-2026-2639 are later independent coverage, thematic only.
Related coverage in Threadlinqs (context, not the same activity) — 5
Anthropic's trend pages (PDF pp. 38–39) put GTG-20006 at both ends of their autonomy range: a human approved each target, yet its token refreshes and cloud-storage pulls ran as unattended jobs. Agent teams ran for hours to days in GTG-50014 and GTG-50029, and GTG-10007's collectors on a timer. Autonomy drives scale, not severity. For defenders, the CaptiveCrunch and UNC7005 infrastructure behind all but two of our advance matches will rotate; the device-code, key-validation and mu-plugin rules outlast it.
The AI supply chain as a target
Anthropic's supply-chain section treats AI access as something criminals attack, sell and run on: a stolen key can be resold, pays for attack compute and pins the activity on its owner (report section, PDF pp. 28–30). Its trends chapter sees a marketplace growing around that access (trends chapter, PDF p. 38).
The ground was already well covered: between February and our September 25, 2026 snapshot, 188 Threadlinqs records had AI systems as their main target theme (LLMjacking, exposed model servers, AI-gateway flaws, prompt injection), nearly all before the report. None of the indicators Anthropic published for either group appeared in them; the community had mapped the economy, not these operators.
GTG-50021 — Fake Claude resellers and the stolen-key economy
GTG-50021, a Russian- and Ukrainian-speaking crew, ran what Anthropic's September 10, 2026 report describes as a bogus discount Claude reseller that served another model and stole buyers' Anthropic logins for onward sale. None of its 6 CSV indicators were in Threadlinqs before or after publication, but 11 ecosystem records dating from February 2, 2026 carry 122 detections.
What Anthropic reported
Anthropic (report section, PDF pp. 28–30) treats stolen AI keys and sessions as a traded good that intruders buy as free compute (T1496.004) and fake resellers drain. For defenders:
- Cheap access is the lure. GTG-50021's discount Claude was
neither cheap nor actually Claude
(Anthropic, PDF p. 29); installing its client surrendered the buyer's Anthropic logins. - Rotating keys on an infected host fails. An unnamed fake multi-model gateway shipped clients, some styled as Claude Code, whose stealer caught sessions opened after a reset.
- Gateways leak what they hold. Prompt injection (AML.T0051) let several actors pull keys from the LiteLLM layer of AI wrapper products.
- GTG-50021 infrastructure (Anthropic's CSV labels): storefronts awstore[.]cloud (Claude) and kiro[.]cheap (Kiro), AWS lookalike aws-us-east-3[.]com, malware C2 and platform domains sys-tools[.]cfd and holdboost[.]store, Supabase backend iymkjuzymkapovrntoxy.supabase[.]co.
What Threadlinqs already had
The closest prior record, TL-2026-1911 (Unit 42 token-jacking research, in Threadlinqs since August 6), maps the supply side of the same economy: transfer stations on open-source gateways (new-api, one-api) reselling stolen, leaked or pooled credentials at a discount through merchants and relays. It shares no actor or infrastructure with GTG-50021.
Other strands already in the corpus (dates show entry into Threadlinqs):
- TL-2026-0012 (Feb 2): LLMjacking reseller proxies selling subscriptions on pooled stolen keys.
- TL-2026-0403 (Apr 21), TL-2026-0546 (May 21, EclecticIQ) and TL-2026-1845 (Aug 3): fake Claude Code and Gemini CLI installers, spread through fake-leak GitHub repos and SEO poisoning, that steal tokens, cookies and developer secrets.
- TL-2026-1521 (Jul 19): Claude and Mythos brand abuse, including account-resale storefronts, with registrations on the same cheap TLDs (.cfd, .xyz).
- TL-2026-1522 (Jul 19): lookalikes of a multi-model aggregator harvesting AI API keys, the nearest analogue to the unnamed gateway impersonator.
- TL-2026-2257 (Aug 31) and TL-2026-2416 (Sep 9, Okta): replayable Claude and other AI session tokens in stealer logs (T1539), abuse Anthropic's August notice caught through usage refill-and-drain cycles, plus Telegram sellers of discounted Claude access.
The corpus's only independent measurement of silent model swapping is CISPA's, in the distillation advisory TL-2026-2413: close to half of the grey-market proxies it tested substituted a cheaper model. Our LiteLLM records cover flaws and their exploitation, such as the KEV-listed pre-auth SQL injection exposing stored keys (TL-2026-0487), plus a PyPI supply-chain compromise; none shows prompt injection pulling keys from a LiteLLM deployment. Injection that steals secrets does appear, aimed at coding agents: malicious-package campaigns that planted instructions for Claude Code or Cursor to exfiltrate developer secrets (TL-2026-0576, TL-2026-0147), and research such as a Claude Code GitHub Action leak via /proc/self/environ (TL-2026-0660) and cross-agent injection in Google ADK (TL-2026-1897).
What we add
TL-2026-0403-KQL-001flagsClaudeCode_x64.exeand siblingTradeAI.exerunning from user, Temp, Downloads or AppData folders. It targets a documented fake Claude Code dropper, not GTG-50021's tooling, but the same delivery vector.TL-2026-0012-SPL-002groups Bedrock control-plane calls per AWS access key in CloudTrail; two or more action types from one key is the LLMjacking recon pattern Sysdig documented, though a legitimate first-time Bedrock setup can look the same.
Sibling grey-market outlets, none sharing infrastructure with GTG-50021: the account shops claudekyc[.]shop and claudecode-buy[.]com (TL-2026-1521) and the access proxy poison-claude.bitsender[.]top (TL-2026-2416). A proxy-log hit means someone inside is shopping for grey-market model access, the buyers this case preyed on.
What to change:
- Allow-list official installers and paths for AI coding tools; alert on same-named binaries anywhere else.
- Baseline AI usage per key and per seat; alert on spikes and on refill-and-drain cycles, the signal behind Anthropic's August notice.
- After a stealer infection, reimage first and rotate second; as the gateway impersonator's harvester showed, rotating keys on a dirty host just restocks the broker.
Gaps
- None of Anthropic's 6 CSV indicators for GTG-50021 appear in the corpus, before or after the report, nor does the alias Anthropic gives one member; the indicator printed only in the PDF was checked too and matched no actor infrastructure we hold.
- No record covers the unnamed operator who posed as a multi-model gateway to push fake clients, or LiteLLM key theft through prompt injection.
Related coverage in Threadlinqs (context, not the same activity) — 5
GTG-50020 — A Russian-speaking crew moves from hotel-booking breaches to AI vendor keys
GTG-50020 is a Russian-speaking extortion crew that, per Anthropic's September 10, 2026 report, prompt-injected an AI vendor's automated evaluation sandbox to take the vendor's production keys, then attacked about 30 AI firms in four days; its bid for pre-release Claude access failed. None of its 8 egress IPs appeared as a Threadlinqs indicator before or after publication (one sits inside a bulletproof-hosting /22 we track); 3 technique records dating from June 16, 2026 carry 27 detections.
What Anthropic reported
Anthropic's conclusion that the AI supply chain has become a deliberate criminal target
(Anthropic, PDF p. 31) rests on a former hotel-booking and fintech extortion crew (GTG-50020, PDF pp. 30–33). For defenders:
- Evaluation sandboxes are credential stores. Prompt injection (AML.T0051) against one vendor's automated evaluation sandbox yielded production keys for several model providers; untrusted prompts and stored secrets should not share a box.
- Stolen keys fuel the next wave. The crew ran its tooling on the vendor's keys, then hit about 30 AI firms in roughly four days with one proven approach.
- The rest is fraud tooling: a KYC-relay phishing proxy, a verified-account factory, agent-driven web exploitation. It never reached the pre-release Claude model it sought, and every key traced to a customer, not Anthropic.
What Threadlinqs already had
The closest tradecraft is TL-2026-2341, Unit 42 research in Threadlinqs since September 5, before the report: a human operator steered parallel frontier-model agents in a custom framework that harvested credentials, moved through the secrets manager and CI/CD, then called the victim's own cloud AI endpoints (T1496.004) ahead of an extortion attempt. The actor is unnamed and shares no infrastructure with GTG-50020.
Earlier technique records (dates show entry into Threadlinqs):
- TL-2026-1076 (Sysdig, Jul 2): a stolen Ollama server powering an autonomous pipeline that fingerprints targets, writes exploits and pulls secrets.
- TL-2026-0828 (Jun 16): the BlueKit phishing kit, combining AiTM reverse proxying, CapSolver CAPTCHA solving and Octo anti-detect session replay, the building blocks of GTG-50020's KYC relay and account factory. Anthropic names none of GTG-50020's services and BlueKit has many buyers, so this is a shared technique, not shared tooling or actor.
Egress IP 178.16.54[.]141 sits in 178.16.52[.]0/22, OMEGATECH (AS202412) space that Intrinsec's reporting in TL-2026-0617 (May 28) and Spamhaus tie to a bulletproof-hosting provider; it is the only one of Anthropic's 209 CSV indicators that we match at hosting-range level alone. Its /24 also holds a TonRAT C2 from a Microsoft-tracked hotel-sector phishing campaign (TL-2026-0946) and a Konni RemcosRAT C2 (TL-2026-1529). Hotel targeting aside, that tenant mix marks a rented block; the match identifies a hoster, not an operator.
What we add
Anthropic flags the 8 egress IPs for hunting, not blocking, and no rule names them; the OMEGATECH prefix rules on TL-2026-0617 match 178.16.54[.]0/24 only as a destination for outbound script-interpreter traffic. Retro-hunt WAF, API gateway, identity and model-provider logs for May 21 to June 16, 2026; a later hit on these rented addresses is a lead, not proof. The technique rules do the rest:
TL-2026-1076-KQL-001matches the VAPT pipeline's markers (VAPTb3gin,VAPTfin,__VAPTCMD__) in process command lines, with near-zero false positives. It hunts another operator's framework, but a hit means an agent pipeline is confirming code execution on your host.TL-2026-1076-SPL-003flags more than 60 requests in five minutes from one source to self-hosted model endpoints (/api/generate,/api/chat,/v1/completions). It catches a pipeline borrowing a model server you run, whatever the source IP, but not stolen keys used at a hosted API; batch inference can trip it.
AI vendors: keep provider keys out of anything an evaluated model or agent can read, use separate low-limit evaluation keys that alert when used outside the sandbox, and restrict sandbox egress. KYC providers: flag a verified session replayed from a different device or IP than the one that passed the check, especially from hosting ranges.
Gaps
- No record names GTG-50020 or covers the sandbox injection, the four-day sweep of AI firms, the pre-release Claude attempts or the hotel and fintech extortion.
- Seven of the eight egress IPs have no match, not even at /24; the eighth has only the hosting-level neighbours described above.
- No record joins the KYC relay and the account factory into one operation; we hold only commercial parts.
Related coverage in Threadlinqs (context, not the same activity) — 5
Together, the two cases show stolen keys flowing both ways: keys lifted from developers stock cheap resale, and keys lifted from an AI vendor funded further intrusion attempts against that vendor and others. Detection starts with how a key is used, not where the traffic comes from.
Influence operations
Nine influence operations sit under this heading, aimed at audiences on six continents and scored for reach on the Breakout Scale (report section, PDF pp. 41–43). Claude scrubbed state sourcing from recycled copy, sub-edited for existing newsrooms, and ran back-office work: manuals, target lists, doctrine held in memory files.
We hold analogues, not the operations: Trend Micro's solo 'Patriot Bait' operator, whose jailbroken LLM rewrote news for Telegram (TL-2026-0582, TL-2026-1356), ClearSky's Houthi fake-outlet network (TL-2026-0760) and Recorded Future on Iranian state AI propaganda (TL-2026-1417). Later independent coverage: Pravda-network LLM grooming (TL-2026-2631) and a new UK information-defence centre (TL-2026-2638).
GTG-54002 — Fake local-news network Anthropic traces to LKM Company
GTG-54002 is an influence-for-hire network that Anthropic's September 10, 2026 report traces to the France-based digital ad agency LKM Company: Claude wrote slanted copy for about 70 fake local-news sites, heavy on DRC-Rwanda. None of its 28 indicators were in Threadlinqs; 3 technique records from May 25, 2026 onward carry 27 detections.
What Anthropic reported
Claude wrote originals and re-slanted real reporting per country in a fixed format, so posting ran unattended, mainly for the DRC, France, Brazil and the US.
- At least 8,913 articles in roughly 20 languages.
- One X account per outlet, boosted by 250-plus commenter accounts, many with AI-generated faces.
- All domains registered from France within about ten weeks in mid-2025, behind one shared deployment.
- Coordination tell: near-duplicate DRC-Rwanda pieces across the network within three minutes on 2025-09-11.
Rated Breakout Category Two, the network backed opposing sides based on whoever was paying at the time
(Anthropic, PDF p. 47).
What Threadlinqs already had
Analogues only, all created before the report:
- TL-2026-0760: ClearSky's Houthi-aligned network of several dozen fake outlets, fed recycled copy and pushed by fake personas (public since 2019; in Threadlinqs since June 10, 2026). Hunting pivots: overlapping WHOIS, passive DNS on a small hosting cluster, shared nameservers, brand-hyphen-'news' or 'press' names.
- TL-2026-0582, TL-2026-1356: Trend Micro's 'Patriot Bait' case, a solo operator's scripts feeding mainstream news to a jailbroken Gemini for slanted rewrites (public May 22, 2026; in Threadlinqs since May 25). Different actor, model and channel.
What we add
Anthropic printed 14 of the roughly 70 outlets and their X accounts (PDF pp. 52–53); all are in the indicator table, none in our corpus. The durable signals are behavioural:
- many news-branded domains registered from one country within ten weeks;
- one hosting deployment behind supposedly independent outlets;
- templated articles (a fixed three or four internal links each);
- one story across sites within minutes, then a link push from matched accounts.
Of the 27 analogue detections, the passive-DNS hosting-cluster rule (TL-2026-0760-SPL-003) and persona posting-burst rule (TL-2026-0760-SPL-002) carry over once their Houthi name pattern and hard-coded hosts are swapped for this network's domains.
Gaps
- No record of LKM Company, its outlets or X accounts, and no DRC-Rwanda or Congo influence reporting at all.
- The full domain list and shared deployment identifier are not in the public PDF or CSV, so the best infrastructure pivot is out of reach.
Related coverage in Threadlinqs (context, not the same activity) — 1
GTG-84005 — Malaysia election-manipulation platform Anthropic ties to BBS Bilisim
GTG-84005 is a for-hire election-manipulation platform aimed at Malaysia, tied in Anthropic's September 10, 2026 report to Istanbul's BBS Bilisim Teknolojileri. Claude and Claude Code built its farm of about 1,000 X accounts and 222-constituency voter profiling, and rewrote copy for the laundering outlet Malaysia Pulse. None of its 21 indicators were in Threadlinqs; 2 technique records from June 10, 2026 onward carry 18 detections.
What Anthropic reported
Read it as a product (PDF pp. 53–55):
- Sold as defence: badged as counter-disinformation software and offered, with no sign of a deal, to Malaysia's communications regulator; the vendor's own pitch promised a
military-grade, AI-driven, real-time political operations ecosystem
(Anthropic, PDF p. 54). - Laundering is the tell: Malaysia Pulse (registered 2026-05-10) ran rewritten local stories and Chinese and Russian state copy, credits removed, as Malaysian news; separately, operators forged smear dossiers.
- Open questions: reach figures come only from the actor's dashboards, and the report does not say who else bought access. Breakout Category Two.
What Threadlinqs already had
Two technique analogues predate the report:
- TL-2026-0760: ClearSky's Houthi-aligned outlets lightly edited Arabic RT and Sputnik copy while sockpuppets pushed the links. That network also used Hetzner, but not the six GTG-84005 addresses.
- TL-2026-1356: Trend Micro's 'Patriot Bait' scripts rewrote mainstream news through a Gemini instance jailbroken under an 'authorized penetration tester' pretext.
What we add
Block or hunt, all in the indicator table (PDF pp. 57–58): malaysiapulse[.]com, bbsteknoloji[.]com, the Malaysia Pulse YouTube channel, 12 sample sockpuppet X accounts created on one day (May 17, 2026) and six Hetzner IPs behind the XPanel panel, NEOS, a renderer and Voxta. Hetzner addresses get reassigned, so time-bound any IP block.
The stronger cue is content: uncredited CGTN, Sputnik/RIA, Xinhua or TV BRICS copy posing as local news, caught by a cheap diff against those feeds. Of the 18 analogue detections, adapt the RT/Sputnik content-mirroring rule (TL-2026-0760-KQL-002) and the hosting-cluster rule (TL-2026-0760-SPL-003).
Gaps
- No record of BBS Bilisim, Malaysia Pulse, Southeast Asian influence activity or any Turkish influence-for-hire vendor.
- Nothing on account-farm warm-up, cookie and IP rotation or constituency-level targeting.
Related coverage in Threadlinqs (context, not the same activity) — 1
GTG-84006 — Activist-impersonating agent platform Anthropic links to MEK/NCRI
GTG-84006 is an influence operation that Anthropic's September 10, 2026 report links to the MEK (PMOI) and NCRI, run on 'Viktor', a shared Claude agent platform with memory files. One agent cloned a real activist's Telegram voice and chatted live as him. None of its 10 indicators were in Threadlinqs; we held 1 earlier technique record, with 9 detections.
What Anthropic reported
What matters for the targeted communities (PDF pp. 70–73):
- A clone is hard to spot: built from roughly 8,400 of the activist's posts, it apparently fooled his contacts; the impersonation accounts also fired one invented news alert at 30-plus contacts at once.
- The profiling data endangers people: scrapes of 500-plus channels sorted people inside Iran by traits including arrest history.
- Doctrine sat in memory files: standing instructions per Viktor workspace, evasion rules included, kept agents publishing unprompted, with one playbook across separate operators.
Output spread via synchronised Instagram pages and undisclosed Persian-speaking AI avatars. Breakout Category Two.
What Threadlinqs already had
- TL-2026-1356 (July 15, 2026): Trend Micro's 'Patriot Bait' case, where an auto-loaded GEMINI.md memory file kept a jailbroken Gemini on task for a Telegram influence operation. Trend Micro published it on May 22, over three months before Anthropic's report; the same research reached us on May 25 as TL-2026-0582, counted as related context rather than a second technique record.
Later independent coverage from the regime side, not about this operation: the FBI/NCSC/AIVD advisory on CHOSEN BRICK spyware aimed at dissidents (TL-2026-2526, TL-2026-2534).
What we add
Activist and diaspora communities should assume an agent can drive a trusted account:
- verify out of band when a contact's style, tempo or urgency shifts;
- treat identical 'breaking news' from one contact to several people at once as a clone signal;
- review Telegram sessions and linked devices often.
All 10 indicators are Instagram and Telegram accounts, better suited to platform reports than blocklists, though Anthropic marks them detect-or-block. Warn communities about the three it calls sockpuppet or surveillance funnels: instagram[.]com/fwr[.]ir, t[.]me/FWR_ir, t[.]me/anti_silent. PDF-only entries were checked; none matched actor infrastructure in our corpus.
TL-2026-1356-SIG-003 (one of 9 detections on TL-2026-1356) flags bypass wording in GEMINI.md, CLAUDE.md or AGENT_MEMORY.md on agent hosts; for this network, add SKILL.md, LEARNINGS.md (PDF p. 75) and evasion-rule wording.
Gaps
- No MEK/NCRI actor entry and nothing on Viktor or any shared influence-agent platform; none of the Telegram or Instagram accounts are in the corpus.
Related coverage in Threadlinqs (context, not the same activity) — 4
These six have only thematic context in our corpus, nothing a hunter could act on.
| Case | What Anthropic reported | Closest Threadlinqs coverage | Gap |
|---|---|---|---|
| GTG-04001 | A Russian-speaking Bangui operator, assessed by Anthropic as local media coordinator for Politology (itself assessed as SVR-run since late 2023), had Claude write news for a Wagner-founded station and forge gendarmerie and defence papers. Breakout Category Four (PDF p. 44). | TL-2026-0495, TL-2026-1356, TL-2026-1417 | No Central African Republic, Wagner or Politology coverage anywhere; our 3 context records are general AI-misuse reporting, and our SVR records (APT29) are unrelated cyber-espionage. |
| GTG-24015 | Four accounts used Claude to sub-edit copy for RT English and Sputnik's Moldovan (with RIA Novosti), Spanish-language and African outlets, including smears of Moldova's president before its September 2025 election (PDF p. 58). | TL-2026-0495, TL-2026-0760, TL-2026-1356 | No record of Russian state outlets using LLMs; the report's indicators were checked, and none matches actor infrastructure in our corpus. TL-2026-2173, an APT28 lure built on a Spanish-Moldovan diplomatic meeting, is context only. |
| GTG-34001 | Actors inside or working for three Iranian state propaganda bodies had Claude draft target lists, persona kits and manuals, and pin invented claims on Western think tanks. Breakout Category Three (PDF p. 62). | TL-2026-0159, TL-2026-1309, TL-2026-1417 | None of these institutions or their Eitaa, Bale and Rubika channels appear. Closest context: Recorded Future on Iranian wartime AI propaganda (TL-2026-1417). |
| GTG-54006 | One Gaibandha-based operator, spread across 29 Claude accounts, scripted fake Bengali headlines and stories in fixed batches to feed pro-Awami League livestreams. Breakout Category Three (PDF p. 67). | TL-2026-0495, TL-2026-0582, TL-2026-1356 | No Bangladesh or Bengali-language influence reporting; the closest analogue is the stolen API-key rotation in TL-2026-0582. |
| GTG-54004 | A Kenyan operator had Claude turn talking points into 50-post batches of organic-looking chatter before the 2027 election, reusing the template for retail brands. Found via an OpenAI tip; Breakout Category One (PDF p. 75). | TL-2026-0582, TL-2026-1356, TL-2026-1417 | No Kenyan or East African influence coverage. Analogue only: a solo operator's LLM posting pipeline in TL-2026-1356. |
| GTG-84002 | Anthropic ties a 'Deadshot' persona operation to UAE officials with high confidence: about 300 fake accounts, a cloned NGO identity, ghost-written UN testimony and dossiers on MEPs. Breakout Category Three (PDF p. 78). | TL-2026-0760, TL-2026-1356, TL-2026-1417 | No UAE-directed influence reporting. The closest is the mirror image: Houthi influence aimed at Saudi Arabia and the UAE (TL-2026-0760). |
Route these cues to registrars, hosting providers, platform trust-and-safety teams and targeted communities, not a SOC blocklist.
Surveillance operations
Anthropic's surveillance block covers operations by Chinese, Iranian and West African operators and one commercial vendor, disrupted from January to July 2026 (surv-intro, PDF pp. 81–82). Its three lessons: a lone engineer with a model now replaces a development team, models are fed bulk-collected data to choose targets, and state security bureaucracies are wiring AI into routine work.
Our corpus splits along national lines. The Iranian cases have technique-level analogues, led by CRESCENTHARVEST (TL-2026-0159) and APT42's phone-number data agent (TL-2026-1508). The PRC cases have almost none: PlugX and ShadowPad appear, but we hold no dedicated records of the long-running campaigns against Tibetan, Uyghur and Falun Gong communities, an ingestion gap rather than a search miss.
GTG-34007 — Iranian security units building surveillance tooling
GTG-34007, in Anthropic's September 10, 2026 report, is two linked Iranian units that Anthropic, with high confidence, associates with paramilitary domestic-security bodies. On 16 now-banned accounts they extended a case system called Arman, picked 39 opposition accounts from 155,216 tweets and shipped a prayer-times Firefox extension harvesting social-media identities. Before publication Threadlinqs held 1 technique record (July 19, 2026) with 9 detections.
What Anthropic reported
Sorted by what reaches victims (PDF pp. 101–103):
- User-facing tooling: the Qom-based unit's Firefox add-on went into production. Its other builds (a Telegram mass-reporting bot, a fake national-ID login page, identity lookups for messenger users and phone numbers) aim at individual Iranians, not enterprise networks.
- Back-office work: a seven-department body with provincial offices used Claude for analysis and for a browser interface to Arman, the case system both units feed.
- Refusals: profiling asks were declined, yet
our safeguards did not refuse many of the surveillance software tooling requests
(Anthropic, PDF p. 102).
What Threadlinqs already had
Prior coverage is thematic: TL-2026-1508 (GTIG, public November 5, 2025; in Threadlinqs since July 19, 2026) shows APT42 prototyping a Gemini data agent that matches phone numbers to owners, the nearest analogue to the Qom unit's lookups.
Context only: TL-2026-0159 (CRESCENTHARVEST, Acronis TRU; since February 28, 2026) stole Telegram and browser data from Farsi-speaking protest supporters, a population overlapping the units' targets, with other tooling.
Later independent coverage, not prior coverage: the US, UK and Dutch CHOSEN BRICK advisory (TL-2026-2526, TL-2026-2534, TL-2026-2543, September 15-16) on Telegram-controlled malware against Iranian dissidents; no source ties it to these units.
What we add
- Inventory browser extensions against an allow-list (T1176). Anthropic gives only the extension's name, which we checked and found nowhere in our corpus, so unexpected extensions requesting broad site access are the better signal.
- Watch for pages imitating national-ID services and bursts of coordinated abuse reports against activist or media channels.
- The 9 detections on TL-2026-1508 target runtime-LLM malware, not this toolset: adjacent coverage only.
Gaps
No record covers Arman, the Qom unit, the extension's ID or hash, or the identity-lookup tools. Anthropic published no network indicators.
Related coverage in Threadlinqs (context, not the same activity) — 3
GTG-30004 — Automated profiling and a modified NanoDump
Anthropic's September 10, 2026 report puts two Claude projects under GTG-30004, an Iran-nexus operator: an OSINT profiling tool aimed at Israeli and Jewish-diaspora targets, and a NanoDump build made harder to analyse. No indicators were published. Before publication Threadlinqs held 3 technique records, the earliest from February 12, 2026, carrying 30 detections.
What Anthropic reported
One strand gives defenders something to act on; the other does not (PDF p. 105).
- Credential dumping: the operator's NanoDump variant goes through a Python-driven C++ build step that renames symbols and adds filler functions. Assume hash, string and symbol signatures for the public tool miss it; the point was to make it
harder to tell that its malware was malware
(Anthropic, PDF p. 105). - Profiling: a Claude-built OSINT tool enriched an existing list of Israeli government and civil-society figures and diaspora organisations. Open sources only, so targets' networks would show nothing.
What Threadlinqs already had
Three technique-level matches, all before the report:
- TL-2026-0076 (February 12, 2026): The Gentlemen affiliates also use the public NanoDump; nothing connects the operators. Its Sigma rule keys NanoDump on the file name nanodump.exe, which any renamed binary evades.
- TL-2026-0495 (May 11, 2026): GTIG on AI-inserted decoy logic in CANFAIL and LONGSTREAM, an analogue for the filler functions.
- TL-2026-1508: APT42's data agent, covered under GTG-34007.
What we add
- Renamed files and identifiers beat name and string rules, so detect LSASS access by behaviour: access rights on the lsass.exe handle, the caller's path, lineage and signer, and any dump written afterwards (T1003.001).
- Threadlinqs held such a rule before the report: KQL-002 in record TL-2026-0504 (May 12, 2026) flags dump-grade access masks on lsass.exe handles from processes outside a name-based allow-list. A renamed NanoDump opening LSASS itself trips it unless it borrows an allow-listed name such as svchost.exe; add path and signer checks, and cover NanoDump's handle-duplication and seclogon modes separately.
- Enable RunAsPPL and Credential Guard.
Gaps
No record covers the profiling tool, the reworked NanoDump or the build pipeline, and with no named group or indicators there is nothing to pivot on.
Related coverage in Threadlinqs (context, not the same activity) — 5
GTG-30005 — Open-source targeting of US naval forces
GTG-30005, an Iran-nexus operator in Anthropic's September 10, 2026 report, used Claude to turn public data into targeting handbooks on US naval forces and to research flaws in VSAT terminals, Cisco gear and industrial controllers. Before publication Threadlinqs held 2 technique records from July 2026 with 18 detections, none aimed at VSAT.
What Anthropic reported
Three takeaways for defenders (PDF pp. 106–107):
- No intrusion needed: the naval handbooks came out of a Claude-assisted Python pipeline run over public data only (see the OPSEC point below).
- Patch check: the account researched seven known flaws across maritime satellite terminals, Cisco voice and industrial-wireless gear, and one Schneider Electric management product (PDF p. 107). If you run that estate, confirm these are closed: CVE-2018-19052, CVE-2019-11072, CVE-2022-22707, CVE-2024-2658, CVE-2024-20354, CVE-2024-20418 and CVE-2025-20309. Anthropic describes research, not exploitation.
- Also on the account: components for a domestic Iranian surveillance platform and analysis of a private Telegram group's membership, neither with a defender-side artefact.
What Threadlinqs already had
Two technique-level matches, both before the report: TL-2026-1417 (July 16, 2026), Recorded Future on Iranian military LLM use and AI-assisted ICS reconnaissance reaching maritime and shipping; and TL-2026-1508 (July 19, 2026), GTIG on Iranian Gemini misuse for reconnaissance.
Context only, none showing this operator: APT35 reconnaissance feeding kinetic targeting in Gulf states (TL-2026-0339); SS7 and ad-tech tracking of US personnel in the Gulf (TL-2026-2411, TL-2026-1458); and record TL-2026-1053 (June 26, 2026) on CVE-2024-2658.
What we add
- Maritime operators: inventory VSAT terminals, check firmware against the Cobham advisories, and keep terminal management off the internet and crew networks.
- Cisco and Schneider owners: patch the listed CVEs plus CVE-2026-20230, a Unified CM sibling exploited from late June 2026 (TL-2026-1070); TL-2026-1053 has hunting rules for CVE-2024-2658. Restrict admin access to management networks.
- OPSEC: public photo captions and live transponder feeds are targeting inputs. Review caption policy for deployed units.
Gaps
The Cobham CVEs and CVE-2024-20354 are absent from our corpus; CVE-2024-20418 appears only in passing in an unrelated Cisco record. Nothing covers the domestic surveillance platform; there is no named group or indicator.
Related coverage in Threadlinqs (context, not the same activity) — 5
GTG-30006 — An Iran-only surveillance toolkit built in fragments
GTG-30006, an Iranian operator in Anthropic's September 10, 2026 report, spread its work over 16 free Claude.ai organisations to build surveillance tooling aimed at people inside Iran, including the SECOMS64 implant. None of its 10 published indicators was in Threadlinqs before publication; we held 1 technique record with 9 detections.
What Anthropic reported
Anthropic's view stops at build and test, so the artefacts are what defenders get (PDF pp. 107–110):
- Windows: SECOMS64, a modular implant aimed at Telegram Desktop users (keylogging, a disguised screenshot tool, Chrome credential theft past App-Bound Encryption, USB spread), and a Telegram-bot-driven VBScript dropper.
- Microsoft 365: scripts replaying Outlook's cached tokens to pull whole mailboxes while posing as the genuine client, so detection must start on the endpoint.
- Delivery and Android: Iran-only geo-gated pages, separate lures such as a fake ESET login, and an Android app that quietly ships off the phone's contacts, texts and media.
Claude refused nine out of ten direct requests that were facially malicious
(Anthropic, PDF p. 107); small, split-up web-development tasks got further.
What Threadlinqs already had
Prior, technique-level only: TL-2026-0159, CRESCENTHARVEST (Acronis TRU; in Threadlinqs since February 28, 2026), targets the same Farsi-speaking population and shares keylogging, Chrome App-Bound Encryption bypass and security-product discovery with SECOMS64. No source connects the operators.
Later independent coverage, not prior coverage: CHOSEN BRICK (TL-2026-2526, from September 15) is the closest technical match (Telegram-bot C2, Run-key persistence, cloud-storage exfiltration), but no source joins the operators. TL-2026-2628 (September 23) covers first-party client-ID abuse against mailboxes.
What we add
The hunt pack carries the 10 CSV artefacts (file names and path, task names, Android package, Telegram chat IDs). Behaviour hunts from the PDF (PDF pp. 109–110):
wscript.exeorcscript.exetalking to api.telegram[.]org.- A script killing
olk.exeorolkexthost.exe, or a non-Outlook process reading the new Outlook token cache, then Outlook web API mailbox downloads. - An HKCU Run value
Whost.
Techniques: T1528, T1114.002, T1480. We checked the PDF-only network entries; none matched actor infrastructure in our corpus, so pair process with destination rather than block. TL-2026-0159's App-Bound Encryption rule may catch SECOMS64 only if both abuse the same elevation broker; Anthropic does not say.
Gaps
No dedicated record covers comparable Iranian domestic Android spyware (DCHSpy is only named in a MuddyWater arsenal list, TL-2026-1530), and the operator is unattributed.
Related coverage in Threadlinqs (context, not the same activity) — 5
The six remaining cases sit where our corpus is thinnest.
| Case | What Anthropic reported | Closest Threadlinqs coverage | Gap |
|---|---|---|---|
| GTG-54009 | Anthropic associates a pilot-stage account, banned in June 2026, with the vendor S2T. It sorted posts by location and politics, wrote for fake personas and stocked 255-plus synthetic accounts, matching 2023 Forbidden Stories reporting (PDF pp. 82–83). | TL-2026-0159, TL-2026-0333, TL-2026-0728 | No S2T record. Vendor context among 8 related records: TL-2026-0333 (Intellexa), TL-2026-0728 (NSO), TL-2026-1726 (FinFisher). |
| GTG-14010 | A PRC-aligned operator (possibly a contractor, Anthropic judges at low confidence) turned chatter from monitored WhatsApp and Telegram groups into profiles of Uyghurs in Syria and ran paid informant recruitment (PDF pp. 86–87). | TL-2026-0085, TL-2026-0986, TL-2026-1239 | One passing Uyghur mention (TL-2026-1889); no PRC diaspora-surveillance tooling. |
| GTG-14020 | A lone operator ran a probable religious-affairs intelligence desk, in Anthropic's reading, with Claude writing Chinese-language dossiers on Tibetan, Falun Gong, Catholic and Taiwanese church figures (PDF pp. 89–90). | TL-2026-0085, TL-2026-0334, TL-2026-0637 | No record. Context: TL-2026-0986, whose 2022 targets included a Catholic charity. |
| GTG-14021 | PRC police and state-security bureaus ran dissent monitoring on Claude, up to reconnaissance of protest sites abroad; rewording after a refusal, one got ten private citizens named as targets (PDF pp. 93–94). | TL-2026-0085, TL-2026-0334, TL-2026-0495 | No record. Context: TL-2026-1889 and Signal backup-key phishing against anti-CCP activists (TL-2026-0637). |
| GTG-14022 | A contractor (Anthropic: medium confidence) ran a near-autonomous pipeline in Claude's code-execution environment, turning 15 to 30-plus foreign articles a day into restricted briefings in mandated Party wording (PDF p. 98). | TL-2026-0085, TL-2026-0334, TL-2026-0495 | No record of LLM public-opinion pipelines; 5 context records only. |
| GTG-50027 | Probably a Bamako consultant serving Mali's intelligence agency, one subscriber used Claude to engineer Lakana 360: about 25 million SIMs, bulk call, SMS and voice capture, warrant check off by default (PDF pp. 103–104). | TL-2026-0144, TL-2026-0143, TL-2026-0195 | No Mali coverage. Context: GRIDTIDE telecom intrusions with potential reach into call records, texts and lawful intercept (TL-2026-0195). The ban does not reach the on-premises platform. |
Start with the GTG-30006 host artefacts, then behaviour-based LSASS-access detection and browser-extension inventory. Blocklists add little: the network destinations published for these cases are public services.
Conventional weapons
Six disrupted cases make up the weapons section (report section, PDF pp. 111–128): four in which Claude helped write weapons software or design documents, and two on procurement and open-source collection. The table below maps each one. The actors broke their work into fragments so that no single session exposed the programme, and at least one reached Claude over VPNs from a blocked region (PDF p. 124). Anthropic banned the accounts, shared findings with partners and added classifiers aimed at weapons-development traffic.
Our corpus has nothing on these cases, by design. For defence-industrial defenders the nearest context is Russian cyber pressure on drone makers: intrusions into Ukrainian FPV drone workshops (TL-2026-0377) and APT28 targeting of the European drone supply chain (TL-2026-2031).
| Case | What Anthropic reported | Closest Threadlinqs coverage | Gap |
|---|---|---|---|
| Six weapons cases | Six cases, accounts banned: GTG-87001, Yemen-based, guidance software (PDF p. 112); GTG-17001, China-based, undersea fire-control specification (PDF p. 115); GTG-27005, Russia-based, autonomous drone swarm (PDF p. 117); GTG-17002, China-based, electronic-warfare and air-defence-suppression software (PDF p. 119); GTG-27006, Russia-based, dual-use procurement (PDF p. 123); GTG-17003, China-based, directed-energy collection (PDF p. 126). | TL-2026-0377, TL-2026-0622, TL-2026-0891 | None at case level, by design. The 8 context records are thematic and share no actor with any case. |
Biological misuse
Like the weapons section, the biology section falls outside our corpus's subject matter and publishes no indicators to sweep. What it does document is how the researchers reached the models. That access layer we track, in 10 records, all created before the report. Read what follows as access-control material, not a hunt.
Five dual-use biology cases: the access-evasion layer
Anthropic's September 10, 2026 report describes five anonymised dual-use biology cases (biological misuse, PDF pp. 129–138) whose researchers reached Claude via reseller relays, purpose-made accounts and a zero-data-retention channel, with refused prompts routed to a rival model. No indicators were published. Threadlinqs already held 3 technique records on that access layer (earliest May 11, 2026), with 27 detections.
What Anthropic reported
- One apparent researcher account was a resale relay for a dozen-plus unconnected clients.
- Bans mostly date from May 2026; partners helped take down the first case's relays.
- A 30-day review found some 35 efforts tied to states of concern, mostly routine.
- Anthropic's remedy: trusted-access programmes with account and institutional vetting plus data retention (PDF pp. 137–138).
What Threadlinqs already had
- TL-2026-0495 (May 11, 2026, Google GTIG): relay middleware pooling accounts across providers, plus scripted sign-ups.
- TL-2026-1911 (August 6, Unit 42): transfer stations reselling model access, fed by stolen keys.
- TL-2026-2413 (AA26-251A, public September 8; in Threadlinqs September 9): geo-restriction relays, fraudulent account pools, automated failover.
What we add
- Alert on outbound TLS to relay middleware (
TL-2026-0495-SIG-003); the shipped rule exempts AI-research and ML-lab hosts, so drop that filter if research subnets are in scope. - Hunt for one key serving many client fingerprints, or many accounts behind one egress address (T1090.003, T1078).
Gaps
None of the three covers these five cases, and Anthropic withheld institutions, countries and agents. The decisive signals, from refusals to model switching, are provider-side; network defenders see only a TLS session to a relay.
Related coverage in Threadlinqs (context, not the same activity) — 5
For a SOC, the practical output is a procurement rule, not a SIEM rule: staff and contractors reach frontier models only through accounts you own and can audit, and use of a discount reseller counts as a data-governance incident whatever the work.
Scams and fraud
The report's one scams case is consumer fraud at industrial volume: AI personas do most of the deceiving, with paid humans mixed in mainly where a video call or follow-back must look real (PDF pp. 139–142). Little of it crosses a corporate network, so the levers sit with app stores, MDM owners and AI providers.
GTG-15001 — A dating-app network run mostly by AI personas
GTG-15001, per Anthropic's September 10, 2026 report, is a China-based app studio that ran 20-plus look-alike US dating apps sold as human-only; over two weeks of April 2026, more than 4,700 Claude personas exchanged about 2.36 million messages with 25,000-plus people. None of its 8 indicators were in Threadlinqs before publication. The corpus held 1 technique-level record beforehand (FakeWallet, April 20, 2026), with 9 detections built for a different operation; we add package blocks and review-evasion hunts.
What Anthropic reported
Mechanics are at PDF pp. 139–142; what follows is what they mean for defenders.
- Hunt surface. Limited to the 8 published indicators below. Model access ran through PRC reseller and proxy networks (PDF p. 139).
- Code similarity will not link the apps. They were built to look different under store review and renamed variant by variant to slip similarity checks (PDF p. 140).
- Human checks prove little. A live call or follow-back comes from the paid quarter of profiles and says nothing about the rest.
- Not public. Publisher identities and review-evasion details went to Apple and Google only; Anthropic banned the operator's accounts and throwaway orgs and briefed the other labs (PDF pp. 141–142).
What Threadlinqs already had
One record carries the case's distinctive tradecraft, and it describes a different operation.
- TL-2026-0395: FakeWallet, public April 20, 2026 via Kaspersky and in Threadlinqs the same day. A Chinese-speaking operator placed stub apps in the App Store whose real job was to open a browser link on launch, and parked dormant apps awaiting an update to switch on phishing. The payload is a wallet stealer and no indicator overlaps: a review-evasion precedent, nothing more.
Context only: INTERPOL's Asia and South Pacific assessment (TL-2026-0897, in Threadlinqs since June 22, 2026) notes scam compounds pairing AI personas with romance baiting, though GTG-15001 sold coin-metered chat, not fake investments. The transfer-station relays and stolen-key resale in TL-2026-2413 and TL-2026-1911 are the kind of channel Anthropic says the operator used.
Later independent coverage, not prior:
- TL-2026-2591: FomoPeek (SlowMist; in Threadlinqs since September 20, 2026). Hidden modules arrived in post-approval updates, and an activation gate plausibly screened out review and emulator environments.
- TL-2026-2655: deceptive Android apps parked in Google Play Early Access, which hides public ratings and reviews (Bitdefender, public September 10; in Threadlinqs since September 25).
What we add
The value here is the indicator set and two behavioural hunts, not a match.
- Indicators. Filter the indicator table to GTG-15001 for all 8: five hostnames across the operator's company, marketing, web-app and cloud-backend domains, one US egress address and two Android package IDs. The brand names printed only in the report were checked too; none matched the operator in our corpus.
- MDM. Block the two package IDs on managed devices and match on package ID, not display name: the brand names are generic and can collide with unrelated legitimate apps.
- Egress window. Search April 2026 proxy and firewall logs for 38.129.138[.]244, the US egress proxy Anthropic flags for hunting rather than blocking; a hit is a lead, not attribution.
- Store and trust teams. Diff the remote config served to reviewer-like environments against what ordinary US devices receive, and cluster apps on shared backend, CDN and payment endpoints rather than code similarity. The review-only controller maps to T1627 and T1633.
- Detections. The 9 FakeWallet rules target that malware's wallet hooking and C2 and will not fire on these apps. The nearest behavioural logic is
TL-2026-2591-SIG-001, an anti-emulator activation-gate rule written for later, unrelated reporting; it is hard-scoped to FomoPeek's bundle ID and reward events, so swap in your own app IDs and events first.
Gaps
- No dating-app or AI-companion fraud record exists in the corpus, and none of the 8 published indicators, the ASN or the brand names matched.
- Nothing covers the sitin gig-worker app or the server-toggled payment browser.
Related coverage in Threadlinqs (context, not the same activity) — 4
Illicit distillation
Anthropic's September 10, 2026 report names seven China-based labs that ran distillation campaigns against Claude after its February disclosure (distill-intro, PDF pp. 143–146): Alibaba, Moonshot AI, DeepSeek, Zhipu (Z.ai), Xiaomi, SenseTime and MiniMax. A distilled copy keeps Claude's capabilities but not its safeguards, Anthropic warns, and it says DeepSeek, Moonshot and Xiaomi fed their own users' conversations, some of them sensitive, into Claude.
Apart from GTG-20006, distillation is the only area where Threadlinqs held actor-level coverage before the report. CISA/NSA/FBI advisory AA26-251A, public since September 8, 2026 and in Threadlinqs since September 8-9 (TL-2026-2405, TL-2026-2413), names Alibaba, Moonshot AI, DeepSeek, Z.ai and MiniMax, but not Xiaomi or SenseTime. The match is at company level, not campaign level. Anthropic adds covert relaying of customers' prompts, thinking-signature replay, replay of real user sessions, a named buyer of harvested transcripts and a shell-company proxy.
GTG-16005 — Alibaba's forced-reasoning distillation, per Anthropic
Anthropic ties GTG-16005 to Alibaba-affiliated operators (Qwen/Tongyi Lab) and calls it the largest distillation attack we have ever measured
(Anthropic, PDF p. 147): an injected instruction made Opus 4.6 and 4.7 show their working, with traffic peaking near 3 million exchanges a day. No indicators were published. Before the report, Threadlinqs held 3 related records, including AA26-251A naming Alibaba, with 27 detections.
What Anthropic reported
- Hunt for: one fixed instruction injected into every request, telling the model to write tagged reasoning before answering; a constant string across thousands of accounts stands out more than the varied tasks (PDF p. 147).
- Account signals: the first pool, close to 5,000 accounts, used residential proxies, throwaway mailboxes and virtual cards; banned, the traffic moved to a second pool, parts of which also carried DeepSeek and Xiaomi requests (PDF p. 148).
- Stakes: 151 million-plus exchanges from May to July 2026, weighted to agentic, coding, kernel and long-horizon work. Anthropic says the output trained Qwen 3.5-3.7 and that Claude also aided Alibaba's RL-environment and architecture work. ATLAS: AML.T0024.002, AML.T0021.
What Threadlinqs already had
- AA26-251A (TL-2026-2405, TL-2026-2413) names Alibaba as distilling Claude for Qwen, dating it to 2025. TL-2026-2405 also holds a separate, earlier Anthropic count (April to June 2026, from a Senate Banking Committee letter).
- TL-2026-0085 (GTIG, in Threadlinqs since February 15, 2026): reasoning-trace coercion against Gemini, a technique precedent without actor overlap.
What we add
TL-2026-2405-SPL-002(regex for reasoning-forcing phrases) andTL-2026-2413-KQL-002(CoT extraction patterns); Anthropic published no tag names, so add any you observe.- For scale:
TL-2026-2405-KQL-002(24/7 traffic with no human variation) andTL-2026-2413-KQL-003(hydra-cluster multi-account routing).
Gaps
Nothing in the corpus on the injected-tag prompt, the account pools, the report's volumes, Tongyi Lab or Qwen 3.5-3.7.
Related coverage in Threadlinqs (context, not the same activity) — 5
GTG-16002 — Moonshot relays Kimi customers to Claude, per Anthropic
Moonshot AI, maker of Kimi, is GTG-16002. Anthropic says it quietly answered its own customers with Claude, relaying almost 300,000 requests in ten days through 5,380 fraudulent accounts, and mined saved exchanges for reasoning. No indicators were published. Before the report, Threadlinqs held 2 AA26-251A records naming Moonshot, with 18 detections, but nothing on the relay.
What Anthropic reported
- Hidden substitution: Kimi users could not tell Claude was answering. Exposures Anthropic cites: CCTV analysis of one tracked person from hundreds of Chengdu cameras, by a user it judges likely PLA-affiliated, and an SOE engineer whose prompts unwittingly carried source code and working logins of several major PRC firms (PDF p. 149).
- Traffic profile: relay accounts mostly appeared to sit in Singapore and Japan and routed nearly all traffic to Opus (PDF p. 148); Anthropic counts over 23 million Moonshot exchanges from May to July 2026.
- Signature replay: a thinking signature kept from one answer and resubmitted in a fresh session got Claude to rebuild the reasoning behind it; Anthropic says fixes are coming (PDF pp. 148–149).
What Threadlinqs already had
- AA26-251A (TL-2026-2405, TL-2026-2413) names Moonshot AI as distilling Claude for its Kimi models; TL-2026-2405 adds that relay services are often hosted outside China, Singapore included.
What we add
- For the relay pattern, pair
TL-2026-2413-SIG-003(requested-versus-served model mismatch, our closest rule to silent substitution) withTL-2026-2413-SPL-002(non-human 24/7 API throughput) andTL-2026-2405-SPL-003(bursts of accounts sharing one payment token). - Ask AI vendors to disclose sub-processors and upstream model routing.
Gaps
The customer relay, the 5,380-account pool, the signature bypass, the volumes and the exposed customer data are all new to the corpus.
Related coverage in Threadlinqs (context, not the same activity) — 5
GTG-16001 — DeepSeek's covert relay and reasoning replay, per Anthropic
Anthropic says DeepSeek (GTG-16001) secretly routed selected customers' requests to Claude Opus, served the answers as its own and replayed reasoning signatures to harvest chain-of-thought: more than 12.1 million exchanges in 14 days of July 2026. No indicators were published. Before the report, Threadlinqs held 2 AA26-251A records on DeepSeek's Claude distillation, with 18 detections.
What Anthropic reported
- Who was exposed: per Anthropic, DeepSeek used client-identifying strings to single out customers reaching its models through OpenCode, Claude Code or the Claude Agent SDK, who probably never knew (PDF pp. 149–150). Code, documents and secrets in those sessions reached a second provider.
- Stakes: Anthropic's examples run from a PRC tech firm's internal plans for a flagship AI programme to working credentials for a Russian government database and a city police bureau's tracking tool (PDF p. 150).
- Reasoning capture: Moonshot's saved-signature replay, reused to obtain the full chain of thought instead of Claude's summary.
What Threadlinqs already had
- AA26-251A (TL-2026-2405, TL-2026-2413) names DeepSeek as distilling Claude and other US models since at least late 2024, with a focus on reasoning. TL-2026-2405 also records an April 2026 State Department warning naming DeepSeek.
What we add
TL-2026-2413-KQL-002flags chain-of-thought extraction phrasing in request bodies;TL-2026-2413-SIG-003flags answers from a model other than the one requested.- Inventory coding clients pointed at third-party model endpoints (for example
ANTHROPIC_BASE_URLoverrides) and vet each provider.
Gaps
No record of the relay, the coding-client tagging, the replay attack, the July volume or the exposed data; our DeepSeek coverage describes earlier activity.
Related coverage in Threadlinqs (context, not the same activity) — 4
GTG-16006 — Zhipu (Z.ai) cleans harvested reasoning with Claude, per Anthropic
Zhipu, trading abroad as Z.ai, is GTG-16006. Anthropic says it spent ten days pulling chain-of-thought from Opus 4.8 through 273 fraudulent accounts, had Claude scrub the traces into GLM training data, and later went after US models' cyber skills. No indicators were published. Before the report, Threadlinqs held 2 AA26-251A records naming Z.ai, with 18 detections.
What Anthropic reported
- Traffic shape: most of the 3 million-plus exchanges Anthropic ties to Zhipu over ten June days were a cleaning pass, Claude's reasoning sent back to be rewritten as training text (770,609 through the cleaner itself); 17 days of June and July top 3.4 million (PDF pp. 150–151).
- Safeguards steered targeting: per Anthropic, Zhipu staff dropped Fable for Opus 4.6 and a rival US lab's flagship, judged weaker, while seeking cyber capability to distil before GLM 5.3 with CTF tasks built on public vulnerability data; Opus 4.6 mostly graded (PDF p. 151).
- Beyond extraction: Claude also served as grader and data preparer in Zhipu's post-training.
What Threadlinqs already had
- AA26-251A (TL-2026-2405, TL-2026-2413) names Z.ai as extracting Claude Opus 4.8 data for chain-of-thought reasoning.
- Not prior coverage and not about distillation: TL-2026-2615 (Cisco Talos CAIRN, added September 22, 2026) has hunting filters for malware calling Chinese-provider model APIs, BigModel among them.
What we add
- Start with
TL-2026-2413-KQL-002(CoT extraction prompt patterns) andTL-2026-2405-SIG-003(high prompt-repeat ratios at extraction volume). - Hunt hypothesis for gateway owners, not an existing rule: large batches of model-written reasoning resubmitted with rewrite or normalise instructions, the shape of the cleaning pass.
Gaps
The cleaning step, the 273-account pool, the volumes, Claude's post-training role and the pre-GLM 5.3 cyber campaign are all absent from the corpus.
Related coverage in Threadlinqs (context, not the same activity) — 5
GTG-16008 — Xiaomi replays real MiMo sessions to Claude, per Anthropic
Xiaomi is GTG-16008. Per Anthropic, it resent its own MiMo users' past conversations, many of them coding work, to Claude as training material: over 400,000 requests through 1,500-plus proxy accounts in 20 days of March and April 2026. No indicators were published. Threadlinqs had no Xiaomi record before the report, only 2 AA26-251A technique records on proxy-based distillation, with 18 detections.
What Anthropic reported
- Your data may be in it: many replayed sessions had reached MiMo through model routers popular in the US and Europe, so they carried personal and corporate details of hundreds of users writing in a dozen or more languages. Anthropic has no indication US persons' data was exposed (PDF pp. 151–152).
- Timing: Anthropic suggests Xiaomi may have used a MiMo-V2-Pro free trial, later extended, to attract developer traffic worth distilling; most of the Claude traffic started as the trial wound down (PDF p. 152).
- Claude's role: making training data (rebuilt developer environments, synthetic developer exchanges, grading); Anthropic saw no sign its answers reached MiMo users.
What Threadlinqs already had
- AA26-251A describes proxy and aggregator paths into US models (TL-2026-2405) and says transfer-station operators treat harvested logs as their main product (TL-2026-2413). Xiaomi is not named: a shared technique, not an actor link.
What we add
- Routing-layer detections:
TL-2026-2413-SPL-002(non-human 24/7 API throughput) andTL-2026-2405-KQL-003(one account across many endpoints and source IPs in an hour). - Check whether the routers and coding agents your developers use keep or resell prompts; Anthropic's account shows a prompt sent to one lab can be replayed to another and trained on.
Gaps
Xiaomi and MiMo are absent: Xiaomi hits are incidental (phone-maker, app-store and researcher-credit mentions); the one "Mimo" match is unrelated crimeware. No OpenClaw or OpenCode record treats those tools as a source of replayed sessions.
Related coverage in Threadlinqs (context, not the same activity) — 3
GTG-16012 and GTG-16003 — SenseTime's bought transcripts and MiniMax's shell-company proxy, per Anthropic
GTG-16012 and GTG-16003 cover SenseTime and MiniMax; the report does not say which label is which. Anthropic says SenseTime trained on Claude transcripts bought from data vendors and that MiniMax runs a US-models-only proxy through an undisclosed shell company, likely to harvest exchanges. No indicators were published. Before the report, Threadlinqs held 3 records on MiniMax and the relay economy, with 27 detections; none on SenseTime.
What Anthropic reported
- Assume resale: Anthropic describes a secondary market in which some access resellers double as transcript sellers, passing relayed chats to other labs (PDF p. 152). Any app, router or reseller between your users and a model is a potential transcript source.
- SenseTime as buyer: its training data included Claude transcripts bought from data vendors, sourced from apps and routers; Claude also helped build and run that training (PDF pp. 152–153).
- MiniMax as collector: a front company with no disclosed MiniMax tie runs a relay limited to Anthropic and OpenAI models (not even MiniMax's own); Anthropic reads it as harvesting (PDF p. 153).
What Threadlinqs already had
- AA26-251A (TL-2026-2405, TL-2026-2413) names MiniMax as a Claude distiller using fraudulent accounts, a different method from a shell-company proxy.
- TL-2026-1911 (Unit 42, in Threadlinqs since August 6, 2026): relayed traffic arrives as ready-labelled training data. A comparable mechanism; neither lab appears.
What we add
- Treat browser extensions and third-party AI apps as exfiltration paths (TL-2026-1246 lists extensions that intercepted AI chats) and keep AI use on contracted endpoints.
- Detections include
TL-2026-2405-SPL-001(new accounts used outside their registered region at volume) andTL-2026-1911-KQL-003(known transfer-station IPs and domains; will age).
Gaps
SenseTime returns nothing in the corpus, and the transcript trade appears only generically (TL-2026-2413 on proxy log harvesting, TL-2026-1911 on relayed traffic as training data), naming no buyer or vendor. MiniMax's shell-company proxy is absent too.
Related coverage in Threadlinqs (context, not the same activity) — 5
None of these cases came with indicators to block. Providers and LLM gateway owners with prompt-level logs can hunt behaviour: reasoning-forcing instructions repeated across accounts, round-the-clock throughput with no human rhythm, many accounts sharing one payment or routing fingerprint. Seed pattern lists with Anthropic's sample extraction prompts, such as a request to "translate" earlier reasoning (PDF pp. 145–146), and borrow from its playbook (PDF pp. 153–154): tie proxy accounts to the organisation behind them, and demand identity checks on resale signals. Everyone else owns the data path: know which routers, resellers, extensions and assistants see your prompts, and vet them like any processor of company data.
The unusual part: pre-burned infrastructure, public tooling and a server we read differently
Only one case has actor-controlled indicator overlap that predates publication, and other vendors got there first. Of the 55 GTG-20006 rows, 17 actor-controlled ones were already in our corpus, most via ReliaQuest's and Microsoft's CaptiveCrunch reporting (lookalike domains, rogue DNS resolver, ChocoShell C2, both malware hashes; held since July 31, 2026, TL-2026-1808) or Google's UNC7005 reporting (since August 21, 2026, TL-2026-2091). Anthropic cites Microsoft's July write-up. So the operator used infrastructure Microsoft and Google already tracked as Storm-2945 and UNC7005. That does not put every GTG-20006 workstream in the cluster: most of the case's rows match nothing, and no pre-publication record mentions PowerChrome, WUEngine, Shadow C2, GiftDrop or Embassy Kit.
The oldest overlap is the weakest. cdncounter[.]net and its static host have sat in our DarkSword record since March 18, 2026 (TL-2026-0245) as delivery domains Google ties to UNC6353. DarkSword has several users and its source leaked, so whether GTG-20006 and UNC6353 are one operator stays open.
Public tools recur. MiniPlasma, listed with the operator's Windows malware, shares its name with a privilege-escalation proof of concept an independent researcher released on GitHub on May 15, 2026 (TL-2026-0523); that researcher's server is also on Anthropic's list, so the same code is likely. The operator used the open-source WPPConnect library for some of its WhatsApp hijacks, and the library already appears in a Brazilian banking-trojan campaign (TL-2026-1785). GTG-30004 modified NanoDump, also seen in The Gentlemen ransomware tradecraft (TL-2026-0076); GTG-50014 ran TruffleHog and GTG-50029 BeEF. Tool names make poor pivots.
Anthropic labels projectnightcrawler[.]dev operator or lure infrastructure. Our records from June and August 2026 (TL-2026-0835, TL-2026-1865) describe it as the platform that same researcher self-hosted after GitHub and GitLab takedowns, mirroring other proofs of concept (RoguePlanet, GreatXML, LegacyHive). Most likely the operator fetched public exploit code there, though Anthropic may have seen a lure use we cannot. We mark it context-only and keep it out of the sweeps.
Naive /24 pivots mislead too. GTG-20006 addresses sit in /24s beside servers our corpus records as North Korean C2 and BlueNoroff infrastructure, a GTG-50014 egress address neighbours a host from our TeamPCP reporting, and GTG-50020's 178.16.54[.]141 falls in a /22 that Intrinsec and Spamhaus tie to bulletproof hosting (TL-2026-0617). None of this is evidence: cheap VPS and VPN space is shared by design.
Cross-cutting trends: what our corpus shows
Between February and the September 25, 2026 snapshot, 455 of the 2,462 threat records we created involve AI. A keyword classifier, which misses some, files each in one bucket: AI used by attackers (234), AI systems as targets (188) and AI brands as lures (33). Volume dipped in spring after 28 in February, peaked at 154 in July, then eased; September is partial. Part of that peak is ingestion: in July we logged Check Point's annual AI security report (TL-2026-1286) and, late, GTIG's November 2025 write-up of AI-enabled malware (TL-2026-1508).
The report's core argument, that the techniques are old and only the labour got cheaper, matches what vendors documented before September 10, 2026: a financially motivated cluster working Mexican government targets through a Claude-backed agentic CLI (Trend Micro, TL-2026-0498), a Russian-speaking operator breaking into FortiGate appliances with commercial models and a custom MCP server (Amazon, TL-2026-0131), a ransomware crew running Cursor Agent on a Claude model inside victim networks (Gambit Security, TL-2026-2243) and a suspected China-linked operator driving the Hermes and OpenClaw frameworks near-autonomously against Taiwan under a pentest cover story (Israeli firm Dream, TL-2026-2063). Anthropic adds the operator's side: prompts, agent configurations and how much of the loop the model ran.
The targets bucket describes the same key-theft economy as Anthropic's supply-chain cases: Langflow exploitation feeding a key-harvesting botnet (TL-2026-0514), the LiteLLM SQL injection (TL-2026-0487), scanning for MCP servers and agent credentials (TL-2026-1278) and transfer-station resale (TL-2026-1911). None of these records involves GTG-50014, GTG-50020 or GTG-50021. Lures are the smallest bucket but the likeliest to reach a developer laptop (TL-2026-0403, TL-2026-1845).
Two blind spots show. Distillation barely registers until the AA26-251A records in September, filed under targets. Influence and surveillance, the two largest groups in Anthropic's case list, hardly appear: our vendor and government sources follow intrusions and malware far more closely than content operations or domestic surveillance. That collection bias explains most empty cells in the coverage matrix.
Swipe the chart sideways →
Primary category per threat (first match in order offense > lure > target > distill); tag OR title/summary keyword match; created_at month; Sept is partial (to 2026-09-25).
Show data table
| Month | AI used by attackers | AI systems as targets | AI brands as lures |
|---|---|---|---|
| 2026-02 | 15 | 12 | 1 |
| 2026-03 | 13 | 11 | 0 |
| 2026-04 | 7 | 12 | 4 |
| 2026-05 | 13 | 14 | 7 |
| 2026-06 | 22 | 31 | 2 |
| 2026-07 | 86 | 60 | 8 |
| 2026-08 | 49 | 35 | 5 |
| 2026-09 | 29 | 13 | 6 |
ATT&CK and ATLAS mapping
Most top-cited techniques on the strip sit before compromise: gathering victim identity information (T1589), acquiring domains (T1583.001), creating social media accounts (T1585.001) and obtaining AI capabilities (T1588.007). Apart from domains, visible in passive DNS and certificate logs, their bars are short: that work happens on the provider's platform and the operator's kit, beyond any SOC sensor. Coverage runs deep where cases touch your estate: public-facing exploits (T1190), valid accounts (T1078), token theft (T1528) and exfiltration over C2 (T1041). In ATLAS terms, most cases use AI model inference API access (AML.T0040); jailbreaks (AML.T0054) recur across groups, distillation adds model extraction (AML.T0024.002), and key theft adds unsecured credentials (AML.T0055) and cost harvesting (AML.T0034). The full map below lists every id from our case extractions. ATLAS is reporting vocabulary; the ATT&CK bars show where detection engineering pays.
Swipe the chart sideways →
Top techniques by number of cases citing them (explicit or inferred in our extraction), with the count of Threadlinqs detections mapped to each technique across the whole corpus (log scale).
Show data table
| Technique | Cases citing | Threadlinqs detections |
|---|---|---|
| T1589 Gather Victim Identity Information | 12 | 91 |
| T1090 Proxy | 9 | 319 |
| T1583.001 Acquire Infrastructure: Domains | 9 | 425 |
| T1585.001 Establish Accounts: Social Media Accounts | 7 | 52 |
| T1190 Exploit Public-Facing Application | 6 | 2218 |
| T1585 Establish Accounts | 6 | 69 |
| T1591 Gather Victim Org Information | 6 | 49 |
| T1593.001 Search Open Websites/Domains: Social Media | 6 | 14 |
| T1078 Valid Accounts | 5 | 902 |
| T1587.001 Develop Capabilities: Malware | 5 | 76 |
| T1588.007 Obtain Capabilities: Artificial Intelligence | 5 | 26 |
| T1593 Search Open Websites/Domains | 5 | 26 |
| T1656 Impersonation | 5 | 424 |
| T1528 Steal Application Access Token | 4 | 617 |
| T1552 Unsecured Credentials | 4 | 341 |
| T1566 Phishing | 4 | 300 |
| T1027 Obfuscated Files or Information | 3 | 1278 |
| T1036 Masquerading | 3 | 659 |
| T1041 Exfiltration Over C2 Channel | 3 | 1224 |
| T1539 Steal Web Session Cookie | 3 | 533 |
| T1550.001 Use Alternate Authentication Material: Application Access Token | 3 | 308 |
| T1021 Remote Services / lateral movement | 2 | 203 |
Full technique map: 118 ATT&CK techniques and 18 ATLAS techniques across the cases
| ATT&CK | Technique | Cases | In the report | Threadlinqs detections |
|---|---|---|---|---|
| T1589 | Gather Victim Identity Information | GTG-04001, GTG-14010, GTG-14020, GTG-14021, GTG-30004, GTG-30005, GTG-34001, GTG-34007, GTG-50027, GTG-54009, GTG-84002, GTG-84006 | explicit | 91 |
| T1090 | Proxy | GTG-10007, GTG-14021, GTG-15001, GTG-16002, GTG-16012, GTG-30006, GTG-34001, GTG-50020, GTG-50029 | explicit | 319 |
| T1583.001 | Acquire Infrastructure: Domains | GTG-15001, GTG-20006, GTG-50014, GTG-50020, GTG-50029, GTG-54002, GTG-84002, GTG-84005, GTG-50021 | explicit | 425 |
| T1585.001 | Establish Accounts: Social Media Accounts | GTG-14010, GTG-34001, GTG-54002, GTG-54009, GTG-84002, GTG-84005, GTG-84006 | explicit | 52 |
| T1190 | Exploit Public-Facing Application | GTG-10007, GTG-20006, GTG-50014, GTG-50020, GTG-50029, GTG-50021 | explicit | 2218 |
| T1585 | Establish Accounts | GTG-15001, GTG-16002, GTG-16005, GTG-34001, GTG-50020, GTG-54006 | explicit | 69 |
| T1591 | Gather Victim Org Information | GTG-14010, GTG-14020, GTG-14021, GTG-30004, GTG-30005, GTG-84002 | explicit | 49 |
| T1593.001 | Search Open Websites/Domains: Social Media | GTG-14010, GTG-14020, GTG-14022, GTG-34007, GTG-54009, GTG-84006 | explicit | 14 |
| T1078 | Valid Accounts | GTG-10007, GTG-20006, GTG-50014, GTG-50020, GTG-50029 | explicit | 902 |
| T1587.001 | Develop Capabilities: Malware | GTG-10007, GTG-20006, GTG-30004, GTG-30006, GTG-50029 | explicit | 76 |
| T1588.007 | Obtain Capabilities: Artificial Intelligence | GTG-14010, GTG-20006, GTG-50020, GTG-54002, GTG-54006 | explicit | 26 |
| T1593 | Search Open Websites/Domains | GTG-10007, GTG-14021, GTG-20006, GTG-30004, GTG-30005 | explicit | 26 |
| T1656 | Impersonation | GTG-14010, GTG-15001, GTG-54009, GTG-84002, GTG-84006 | explicit | 424 |
| T1528 | Steal Application Access Token | GTG-20006, GTG-30006, GTG-50014, GTG-50021 | explicit | 617 |
| T1552 | Unsecured Credentials | GTG-10007, GTG-50020, GTG-50029, GTG-50021 | explicit | 341 |
| T1566 | Phishing | GTG-20006, GTG-30006, GTG-50014, GTG-54009 | explicit | 300 |
| T1027 | Obfuscated Files or Information | GTG-15001, GTG-30004, GTG-30006 | explicit | 1278 |
| T1036 | Masquerading | GTG-20006, GTG-34007, GTG-50021 | explicit | 659 |
| T1041 | Exfiltration Over C2 Channel | GTG-10007, GTG-50014, GTG-50021 | explicit | 1224 |
| T1539 | Steal Web Session Cookie | GTG-50014, GTG-50020, GTG-50021 | explicit | 533 |
| T1550.001 | Use Alternate Authentication Material: Application Access To | GTG-20006, GTG-30006, GTG-50014 | explicit | 308 |
| T1021 | Remote Services / lateral movement | GTG-10007, GTG-20006 | inferred | 203 |
| T1036.005 | Masquerading: Match Legitimate Name or Location | GTG-30006, GTG-50029 | inferred | 1449 |
| T1074 | Data Staged | GTG-10007, GTG-50029 | explicit | 32 |
| T1114.002 | Email Collection: Remote Email Collection | GTG-20006, GTG-30006 | explicit | 97 |
| T1119 | Automated Collection | GTG-14021, GTG-50029 | inferred | 314 |
| T1133 | External Remote Services | GTG-10007, GTG-20006 | explicit | 383 |
| T1204.004 | User Execution: Malicious Copy and Paste | GTG-20006, GTG-30006 | explicit | 155 |
| T1496 | Resource Hijacking | GTG-50014, GTG-50020 | explicit | 178 |
| T1530 | Data from Cloud Storage | GTG-10007, GTG-50014 | inferred | 170 |
| T1552.001 | Unsecured Credentials: Credentials In Files | GTG-50014, GTG-50021 | explicit | 805 |
| T1555.003 | Credentials from Password Stores: Credentials from Web Brows | GTG-20006, GTG-30006 | explicit | 488 |
| T1557 | Adversary-in-the-Middle | GTG-20006, GTG-50020 | explicit | 293 |
| T1567.002 | Exfiltration Over Web Service: Exfiltration to Cloud Storage | GTG-30006, GTG-50014 | explicit | 352 |
| T1587 | Develop Capabilities | GTG-34007, GTG-50027 | explicit | 22 |
| T1587.004 | Develop Capabilities: Exploits | GTG-10007, GTG-50029 | explicit | 72 |
| T1588.002 | Obtain Capabilities: Tool | GTG-30004, GTG-50020 | explicit | 106 |
| T1591.001 | Gather Victim Org Information: Determine Physical Locations | GTG-14010, GTG-14020 | inferred | 9 |
| T1592 | Gather Victim Host Information | GTG-30005, GTG-50029 | explicit | 57 |
| T1595 | Active Scanning | GTG-20006, GTG-50014 | explicit | 190 |
| T1595.002 | Active Scanning: Vulnerability Scanning | GTG-10007, GTG-50020 | explicit | 436 |
| T1598 | Phishing for Information | GTG-14010, GTG-34007 | explicit | 58 |
| T1608.001 | Stage Capabilities: Upload Malware | GTG-30006, GTG-50021 | inferred | 150 |
| T1657 | Financial Theft | GTG-50014, GTG-50020 | explicit | 499 |
| T0007 | DISARM: Create Inauthentic Social Media Pages and Groups | GTG-54002 | explicit | 3 |
| T0013 | DISARM: Create Inauthentic Websites | GTG-54002 | explicit | 0 |
| T0049 | DISARM: Flooding the Information Space | GTG-54002 | explicit | 3 |
| T0084 | DISARM: Reuse Existing Content | GTG-54002 | explicit | 0 |
| T0085 | AI-assisted production of text-based propaganda and news con | GTG-04001 | inferred | 0 |
| T0085.001 | DISARM: Develop AI-Generated Text | GTG-54002 | explicit | 2 |
| T0085.004 | Forged official government documents | GTG-04001 | inferred | 0 |
| T0086.002 | DISARM: Develop AI-Generated Images | GTG-54002 | explicit | 0 |
| T1003.001 | OS Credential Dumping: LSASS Memory | GTG-30004 | explicit | 173 |
| T1018 | Remote System Discovery | GTG-10007 | inferred | 149 |
| T1027.005 | Obfuscated Files or Information: Indicator Removal from Tool | GTG-20006 | inferred | 1 |
| T1036.004 | Masquerading: Masquerade Task or Service | GTG-30006 | inferred | 54 |
| T1040 | Network Sniffing | GTG-50027 | inferred | 51 |
| T1053.005 | Scheduled Task | GTG-30006 | inferred | 529 |
| T1056.001 | Input Capture: Keylogging | GTG-30006 | inferred | 158 |
| T1056.002 | Input Capture: GUI Input Capture | GTG-30006 | inferred | 71 |
| T1056.003 | Input Capture: Web Portal Capture | GTG-50029 | explicit | 166 |
| T1059.001 | Command and Scripting Interpreter: PowerShell | GTG-30006 | inferred | 1004 |
| T1059.005 | Command and Scripting Interpreter: Visual Basic | GTG-30006 | inferred | 178 |
| T1068 | Privilege escalation to cloud administrator | GTG-50014 | explicit | 1065 |
| T1070.004 | Indicator Removal: File Deletion | GTG-30006 | inferred | 257 |
| T1078.004 | Valid Accounts: Cloud Accounts | GTG-50021 | inferred | 453 |
| T1091 | Replication Through Removable Media | GTG-30006 | inferred | 54 |
| T1098.001 | Account Manipulation: Additional Cloud Credentials | GTG-50014 | explicit | 86 |
| T1098.005 | Account Manipulation: Device Registration | GTG-20006 | explicit | 99 |
| T1102 | Web Service | GTG-50014 | explicit | 428 |
| T1102.002 | Web Service: Bidirectional Communication | GTG-30006 | inferred | 414 |
| T1110.002 | Brute Force: Password Cracking | GTG-50014 | explicit | 33 |
| T1113 | Screen Capture | GTG-30006 | inferred | 188 |
| T1136 | Create Account | GTG-50029 | explicit | 91 |
| T1176 | Browser Extensions | GTG-34007 | explicit | 116 |
| T1185 | Browser Session Hijacking | GTG-50029 | explicit | 111 |
| T1189 | Drive-by Compromise | GTG-50029 | explicit | 381 |
| T1195 | Supply Chain Compromise | GTG-50014 | inferred | 201 |
| T1199 | Trusted Relationship | GTG-50014 | explicit | 360 |
| T1204.002 | User Execution: Malicious File | GTG-50021 | explicit | 1307 |
| T1213 | Data from Information Repositories | GTG-50014 | inferred | 495 |
| T1480 | Execution Guardrails | GTG-30006 | inferred | 34 |
| T1485 | Data Destruction | GTG-30006 | inferred | 216 |
| T1496.004 | Resource Hijacking: Cloud Service Hijacking | GTG-50021 | inferred | 5 |
| T1505 | Server Software Component | GTG-50029 | explicit | 122 |
| T1505.003 | Server Software Component: Web Shell | GTG-50029 | explicit | 522 |
| T1518.001 | Security Software Discovery | GTG-30006 | inferred | 171 |
| T1537 | Transfer Data to Cloud Account | GTG-50014 | explicit | 78 |
| T1547.001 | Boot or Logon Autostart: Registry Run Keys | GTG-30006 | inferred | 778 |
| T1550.004 | Use Alternate Authentication Material: Web Session Cookie | GTG-50020 | explicit | 130 |
| T1552.005 | Unsecured Credentials: Cloud Instance Metadata API | GTG-50014 | explicit | 96 |
| T1553.005 | Subvert Trust Controls: Mark-of-the-Web Bypass | GTG-30006 | inferred | 51 |
| T1555 | Credentials from Password Stores | GTG-50021 | inferred | 224 |
| T1555.004 | Credentials from Password Stores: Windows Credential Manager | GTG-30006 | inferred | 16 |
| T1560 | Archive Collected Data | GTG-50029 | explicit | 109 |
| T1561 | Disk Wipe | GTG-30006 | inferred | 20 |
| T1562.001 | Impair Defenses: Disable or Modify Tools | GTG-20006 | inferred | 236 |
| T1564.003 | Hide Artifacts: Hidden Window | GTG-30006 | inferred | 85 |
| T1566.002 | Phishing: Spearphishing Link | GTG-50020 | inferred | 773 |
| T1566.004 | Phishing: Spearphishing Voice | GTG-50014 | explicit | 126 |
| T1567 | Exfiltration Over Web Service | GTG-50029 | inferred | 609 |
| T1572 | Protocol Tunneling | GTG-30006 | inferred | 376 |
| T1583 | Acquire Infrastructure | GTG-16012 | inferred | 103 |
| T1583.003 | Acquire Infrastructure: Virtual Private Server | GTG-84005 | inferred | 59 |
| T1583.004 | Acquire Infrastructure: Server | GTG-20006 | inferred | 43 |
| T1583.006 | Acquire Infrastructure: Web Services | GTG-15001 | inferred | 213 |
| T1584 | Compromise Infrastructure | GTG-50029 | explicit | 63 |
| T1584.002 | Compromise Infrastructure: DNS Server | GTG-20006 | explicit | 10 |
| T1588.006 | Obtain Capabilities: Vulnerabilities | GTG-30005 | explicit | 79 |
| T1596 | Search Open Technical Databases | GTG-30005 | explicit | 37 |
| T1596.005 | Search Open Technical Databases: Scan Databases | GTG-10007 | inferred | 24 |
| T1597.002 | Search Closed Sources: Purchase Technical Data | GTG-16012 | inferred | 5 |
| T1606 | Forge Web Credentials | GTG-50014 | explicit | 65 |
| T1627 | Execution Guardrails | GTG-15001 | inferred | 4 |
| T1633 | Virtualization/Sandbox Evasion | GTG-15001 | inferred | 2 |
| T1636.003 | Protected User Data: Contact List | GTG-30006 | inferred | 28 |
| T1636.004 | Protected User Data: SMS Messages | GTG-30006 | inferred | 35 |
| T1650 | Acquire Access | GTG-50021 | explicit | 14 |
Entity graph: cases, actors, records and shared indicators
Rectangles are Anthropic's cases; circles are Threadlinqs records, shaded from pale violet (tier A) through B to deep violet (C), grey for records dated September 10, 2026 or later. Orange nodes are actors named in those records; small green nodes are indicators held before the report, linked only to pre-publication records. Tier D is left out. Grey nodes say nothing about lead time. An actor reached through a tier-C record is that record's actor, not the case's: the GTG-50014 path to ShinyHunters runs through technique parallels. Several distillation cases sharing the AA26-251A records (TL-2026-2405, TL-2026-2413) reflect one advisory naming several labs.
139 nodes, 238 links. The same case-to-record links are listed as text under each case section, and the shared indicators are in the indicator master table.
Defender playbook
- Sweep the actor-controlled GTG-20006 rows first. Run the hunt pack sweeps over DNS, proxy and EDR logs: the 17 indicators public before the report, then the 23 Storm-2945 and UNC7005 indicators Anthropic did not list, such as wa-connect[.]net, globsec[.]net and 107.189.26[.]194 (TL-2026-2091, TL-2026-1838).
- Retro-hunt the stale egress; don't block it. Search each "hunt" row within its own first- and last-seen dates (late February to mid-June); a match is a lead, not a verdict.
- Hunt device-code phishing by behaviour.
TL-2026-0943-KQL-003(TL-2026-0943) flags Graph tokens used from an IP that never approved the code; limit the device-code flow with Conditional Access. Check new Entra device registrations for ROADtools defaults such asDESKTOP-plus an eight-character random suffix (TL-2026-0561). - Check travellers' laptops for the hotel Wi-Fi chain. Look for WPAD auto-proxy use on guest networks (DNS
wpadlookups or DHCP option 252), ChocoShell's beacon path/t/pixel.gifand exfiltration path/t/event, and a CornFlake service named "Cloud Sync Service" (TL-2026-1808, TL-2026-1857). - Re-label projectnightcrawler[.]dev. A hit is not GTG-20006 C2, so keep it off espionage block lists (web filtering is a separate call); pair any unexpected hit with a hunt for MiniPlasma artefacts such as
%LOCALAPPDATA%\MiniPlasma\placeholder.dat(TL-2026-0523). - Treat AI keys as credentials with a blast radius. Scan your apps, images and repos for secrets first: GTG-50014 ran TruffleHog over 1.8 million APKs, GTG-50029 a custom scanner over public containers. Alert on STS GetCallerIdentity then Bedrock use by one principal (
TL-2026-0514-KQL-002, TL-2026-0514) and on Bedrock logging checks plus model enablement by one key (TL-2026-0012-SPL-002, TL-2026-0012). - Watch developer endpoints for fake AI clients. Hunt
ClaudeCode_x64.exeand look-alike installers in user folders (TL-2026-0403, TL-2026-1845). If an infostealer hits a developer host, reimage it, then revoke AI sessions, rotate keys and check billing (TL-2026-2257, TL-2026-2416). - Close the WordPress persistence GTG-50029 used. Alert on new or changed files in
wp-content/mu-plugins(TL-2026-0817-SPL-002; its KQL twin in TL-2026-0817 also requires a web-server process) and audit for hidden admin accounts (TL-2026-1978). - Trim our derivative rule.
TL-2026-2466-SIG-003, from TL-2026-2466, our write-up of Anthropic's disclosure, rates five hunt-flagged GTG-50014 addresses (162.128.129[.]106, 185.65.134[.]246, 193.32.249[.]161, 45.148.10[.]242 and the VPS 195.178.110[.]131) critical with no expected false positives. If you copy it, keep its domains and three detect-or-block GTG-20006 addresses and move those five to a scheduled hunt. - Catch agentic recon on your hosts.
TL-2026-2390-KQL-001(TL-2026-2390) joins scanner processes and LLM API calls from one host within 15 minutes, no indicators needed.
SPL: DNS lookups of CaptiveCrunch Microsoft 365 lookalike domains
SPLindex=dns sourcetype=dns query IN ("ms365-device.com","ms365-live.com","m365-owa.com","owa-ms365.com") answer!="NXDOMAIN" answer!="0.0.0.0"
| stats count min(_time) as firstTime max(_time) as lastTime by src_ip,query,answer
| eval threat_name="CaptiveCrunch_Doppelganger_DNS",technique="T1557"
| convert ctime(firstTime) ctime(lastTime)
| table src_ip,query,answer,count,firstTime,lastTime
| sort - count
KQL: device-code token replayed to Microsoft Graph from a new IP
KQLlet interactive = SigninLogs
| where TimeGenerated > ago(24h)
| where AuthenticationProtocol =~ "deviceCode" and ResultType == 0
| summarize ApprovalIPs = make_set(IPAddress, 50) by UserPrincipalName;
union AADNonInteractiveUserSignInLogs, SigninLogs
| where TimeGenerated > ago(24h)
| where ResourceDisplayName == "Microsoft Graph" or AppId in ("04b07795-8ddb-461a-bbee-02f9e1bf7b46","d3590ed6-52b3-4102-aeff-aad2292ab01c")
| where ResultType == 0
| join kind=inner interactive on UserPrincipalName
| where ApprovalIPs !has IPAddress
| project TimeGenerated, UserPrincipalName, AppId, ResourceDisplayName, IPAddress, ApprovalIPs, AutonomousSystemNumber, Location
| order by TimeGenerated asc
KQL: SecFlow Claude/DeepSeek relay and SecBox C2 infrastructure hits
KQLlet KnownC2IPs = dynamic(["81.70.240.170","43.99.61.170","152.42.200.25","129.211.184.149","159.223.64.67","158.247.234.124","207.148.109.245","211.159.155.240","103.45.65.93","43.162.217.10"]);
DeviceNetworkEvents
| where Timestamp > ago(24h)
| where RemoteIP in (KnownC2IPs)
or RemoteUrl has "niestools.com"
or RemoteUrl has "trycloudflare.com"
or RemotePort in (18000, 64288, 35888)
| extend C2Indicator = case(
RemoteUrl has "niestools.com", "SecFlow-AI-Proxy-Relay",
RemoteUrl has "trycloudflare.com", "SecBox-DeadDropResolver-Fallback",
RemotePort == 35888, "SOCKS5-Exfil-Relay",
"SecBox-Known-C2-Infra")
| summarize count(), Devices=make_set(DeviceName) by RemoteIP, RemoteUrl, RemotePort, C2Indicator
KQL: scanner tooling and LLM API calls from one host within 15 min
KQLlet scanner_procs = DeviceProcessEvents
| where TimeGenerated > ago(24h)
| where ProcessCommandLine has_any ("nmap", "masscan", "nuclei", "sqlmap", "rustscan", "zmap", "gobuster", "ffuf")
| project DeviceId, DeviceName, ProcTime = TimeGenerated, ProcessCommandLine, AccountName;
let llm_api_calls = DeviceNetworkEvents
| where TimeGenerated > ago(24h)
| where RemoteUrl has_any ("generativelanguage.googleapis.com", "api.anthropic.com", "api.openai.com", "api.deepseek.com")
| project DeviceId, DeviceName, NetTime = TimeGenerated, RemoteUrl;
scanner_procs
| join kind=inner llm_api_calls on DeviceId, DeviceName
| where abs(datetime_diff("second", NetTime, ProcTime)) <= 900
| project ProcTime, DeviceName, AccountName, ProcessCommandLine, RemoteUrl
| sort by ProcTime desc
Sigma: GTG-20006 and GTG-50014 domains, carding shop and addresses (after-report rule)
Sigmatitle: Beacon to Known GTG-20006/GTG-50014 C2 and Carding Infrastructure
id: 4c3b2a1f-0e9d-4c7b-9a8f-6e5d4c3b2a10
status: experimental
description: Detects DNS/network connections to confirmed GTG-20006 and GTG-50014 attacker-controlled infrastructure.
references:
- https://www.anthropic.com/threat-intelligence-report-september-2026
author: AII-Detector — ThreadLinqs Intelligence
date: 2026-09-12
tags:
- attack.command-and-control
- attack.exfiltration
- attack.t1567
- attack.t1584.002
- attack.t1583.001
- attack.tool.soraki
logsource:
category: network_connection
detection:
selection_domain:
DestinationHostname|contains:
- 'ms365-live.com'
- 'owa-ms365.com'
- 'teams.ms365-live.com'
- 'updatebeacon.duckdns.org'
- 'soraki.cc'
- 'soraki.work'
- 'policenationale.cc'
- 'autoshop.policenationale.cc'
selection_ip:
DestinationIp:
- '104.145.210.184'
- '31.57.243.154'
- '144.172.114.192'
- '162.128.129.106'
- '195.178.110.131'
- '45.148.10.242'
- '185.65.134.246'
- '193.32.249.161'
condition: selection_domain or selection_ip
falsepositives:
- None expected — these are attacker-registered/attacker-controlled domains and egress IPs
level: critical
KQL: LLMjacking key check — STS GetCallerIdentity then Bedrock use
KQL// KeyHunter / LLMjacking AWS validation chain: STS GetCallerIdentity -> Bedrock list/invoke within 5 min
let sts = AWSCloudTrail
| where TimeGenerated > ago(24h)
| where EventName == "GetCallerIdentity" and EventSource == "sts.amazonaws.com"
| project sts_t=TimeGenerated, principal=tostring(parse_json(UserIdentity).arn), src_ip=SourceIpAddress, sts_region=AwsRegion;
let bedrock = AWSCloudTrail
| where TimeGenerated > ago(24h)
| where EventSource == "bedrock.amazonaws.com"
| where EventName in ("ListFoundationModels","InvokeModel","InvokeModelWithResponseStream")
| project br_t=TimeGenerated, principal=tostring(parse_json(UserIdentity).arn), br_src=SourceIpAddress, br_event=EventName, br_region=AwsRegion;
sts
| join kind=inner (bedrock) on principal
| where br_t between (sts_t .. sts_t + 5m)
| extend severity="High", threat="KeyHunter LLMjacking validation chain", mitre="T1526,T1580,T1496"
| project sts_t, principal, src_ip, br_src, br_event, br_region, severity, threat, mitre
KQL: fake Claude Code dropper ClaudeCode_x64.exe run from user folders
KQLlet DropperNames = dynamic(["TradeAI.exe","ClaudeCode_x64.exe"]);
let UserPaths = dynamic([@"\Users\", @"\Temp\", @"\Downloads\", @"\AppData\"]);
DeviceProcessEvents
| where Timestamp > ago(24h)
| where FileName in~ (DropperNames)
| where FolderPath has_any (UserPaths)
| project Timestamp, DeviceName, AccountName, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256, MD5
| extend LureVariant = case(
FileName =~ "TradeAI.exe", "TradeAI-rust-dropper",
FileName =~ "ClaudeCode_x64.exe", "ClaudeCode_x64-rust-dropper",
"unknown")
| order by Timestamp desc
SPL: Bedrock logging check and model enablement by one AWS key
SPLindex=aws sourcetype=aws:cloudtrail
| where eventSource="bedrock.amazonaws.com"
| where eventName IN ("GetModelInvocationLoggingConfiguration", "PutFoundationModelEntitlement", "PutUseCaseForModelAccess", "ListFoundationModels", "GetFoundationModelAvailability")
| eval action_type=case(
eventName="GetModelInvocationLoggingConfiguration", "LOGGING_EVASION_CHECK",
eventName="PutFoundationModelEntitlement", "MODEL_ACTIVATION",
eventName="PutUseCaseForModelAccess", "USE_CASE_REGISTRATION",
eventName="ListFoundationModels", "MODEL_ENUMERATION",
eventName="GetFoundationModelAvailability", "AVAILABILITY_CHECK",
1==1, "OTHER"
)
| eval severity=case(
action_type="MODEL_ACTIVATION", "CRITICAL",
action_type="LOGGING_EVASION_CHECK", "HIGH",
action_type="USE_CASE_REGISTRATION", "HIGH",
1==1, "MEDIUM"
)
| stats count as api_calls, values(action_type) as actions, values(eventName) as events, values(sourceIPAddress) as source_ips, values(awsRegion) as regions, earliest(_time) as first_call, latest(_time) as last_call by userIdentity.arn, userIdentity.accessKeyId
| where api_calls > 0
| eval recon_chain=if(mvcount(actions) >= 2, "MULTI-STEP RECON CHAIN", "SINGLE ACTION")
| table first_call, last_call, userIdentity.arn, userIdentity.accessKeyId, actions, events, source_ips, regions, api_calls, recon_chain, severity
KQL: VAPT exploit-pipeline marker strings in process command lines
KQLDeviceProcessEvents
| where Timestamp > ago(24h)
| where ProcessCommandLine has_any ("VAPTb3gin", "VAPTfin", "__VAPTCMD__")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName
SPL: machine-speed inference bursts against self-hosted LLM endpoints
SPLindex=web sourcetype="access_combined" uri_path="*/api/generate*" OR uri_path="*/api/chat*" OR uri_path="*/v1/completions*"
| bin _time span=5m
| stats count as request_count dc(uri_path) as endpoint_diversity by src_ip, _time
| where request_count > 60
| sort -request_count
SPL: known mu-plugin backdoor hashes, filenames and rogue WP admins
SPL(index=web sourcetype=access_combined uri_path="/wp-json/wp/v2/users" method=POST status=201)
OR (index=wordpress_audit sourcetype=wp_user_created (new_user_login="bd_*" OR new_user_email="*@wordpress.org" OR new_user_email="*@developer.wordpress.org"))
OR ((index=fim OR index=edr) md5 IN ("1024732009983dd5e54b4cf5593f04d4","7719cd98a35ffad2771f26d1ceab7d27","9aadc3e5c5242b273bd17c5bdc358845","e450ae5bc4bfc0d960dded06a76bb8e9"))
OR ((index=fim OR index=edr) (file_name="emer-run.php" OR file_path="*/wp-content/plugins/wp-smart-thumbnails/*" OR file_path="*/wp-content/mu-plugins/class-wp-token-validate.php" OR file_path="*/wp-content/mu-plugins/class-wp-query-*.php" OR file_path="*/wp-content/mu-plugins/wp-cache-optimizer.php"))
| eval detection_reason=case(
match(uri_path, "wp-json/wp/v2/users"), "rest_api_user_creation",
isnotnull(new_user_login), "rogue_admin_username_bd_prefix_or_spoofed_email",
isnotnull(md5), "known_ioc_file_hash_match",
1=1, "known_backdoor_filename_or_path")
| table _time, host, src_ip, new_user_login, new_user_email, uri_path, file_name, file_path, md5, detection_reason
| sort - _time
SPL: new or changed files in WordPress mu-plugins and theme functions.php (FIM)
SPL(index=web sourcetype=access_combined uri_path="/wp-admin/theme-editor.php" (method=POST OR uri_query="*functions.php*"))
OR (index=linux sourcetype="fim:filechange" (object_path="*/wp-content/mu-plugins/*" OR object_path="*/themes/*/functions.php" OR object_path="*styIe.php*" OR object_path="*session-manager.php*") action IN ("created","modified"))
OR (index=web sourcetype=access_combined (header_x_wp_session=* OR uri_query="*key=*" header_user_agent IN ("*WPScan*","*Nikto*")))
| stats count values(uri_path) as uris values(object_path) as files values(action) as fileactions min(_time) as firstSeen by host src_ip
| where count > 0
| `ctime(firstSeen)`
| table host src_ip count uris files fileactions firstSeen
Indicator master table
The master table lists every hunt pack row, defanged; the CSV is refanged. For Anthropic's 209 rows, status says what we held and when: 17 were in the corpus before September 10, 2026, 15 appear only in our write-ups of the disclosure, 1 is a researcher's server we mark context-only, 1 sits only inside a hosting range we documented, and 175 match nothing. Our 23 added rows name their vendor cluster, not GTG-20006. Role carries Anthropic's handling flag and our stale marker. Account rows are Anthropic's attribution: accounts get bought, hijacked or reassigned, and a name-like handle does not identify a real person. We also checked the 33 indicators printed only in the PDF; none matched actor infrastructure in our corpus.
| GTG-20006 | domain | ad-g[.]org | not in corpus | c2 · detect-or-block | ||
| GTG-20006 | domain | cdncounter[.]net | held before 09-10 | TL-2026-0245 | infrastructure · detect-or-block | |
| GTG-20006 | domain | chamber-ua[.]org | held before 09-10 | TL-2026-2091 TL-2026-2167 | phishing · detect-or-block | |
| GTG-20006 | domain | chathamhouse[.]eu | not in corpus | phishing · detect-or-block | ||
| GTG-20006 | domain | docs-viewer[.]org | not in corpus | c2 · detect-or-block | ||
| GTG-20006 | domain | itechx[.]tel | not in corpus | infrastructure · detect-or-block | ||
| GTG-20006 | domain | m365-owa[.]com | held before 09-10 | TL-2026-1808 TL-2026-1838 TL-2026-1853 +4 | phishing · detect-or-block | |
| GTG-20006 | domain | meridian-protocol[.]org | not in corpus | infrastructure · detect-or-block | ||
| GTG-20006 | domain | meridiangroup-corp[.]com | not in corpus | infrastructure · detect-or-block | ||
| GTG-20006 | domain | metricwave[.]org | not in corpus | infrastructure · detect-or-block | ||
| GTG-20006 | domain | mgsend[.]org | not in corpus | infrastructure · detect-or-block | ||
| GTG-20006 | domain | ms365-device[.]com | held before 09-10 | TL-2026-1808 TL-2026-1838 TL-2026-1853 +4 | phishing · detect-or-block | |
| GTG-20006 | domain | ms365-live[.]com | held before 09-10 | TL-2026-1808 TL-2026-1838 TL-2026-1853 +4 | phishing · detect-or-block | |
| GTG-20006 | domain | my-invite[.]org | held before 09-10 | TL-2026-2091 TL-2026-2167 | phishing · detect-or-block | |
| GTG-20006 | domain | mygreatmarket[.]com | not in corpus | c2 · detect-or-block | ||
| GTG-20006 | domain | mygreatmarket[.]org | not in corpus | c2 · detect-or-block | ||
| GTG-20006 | domain | owa-ms365[.]com | held before 09-10 | TL-2026-1808 TL-2026-1838 TL-2026-1853 +5 | phishing · detect-or-block | |
| GTG-20006 | domain | projectnightcrawler[.]dev | context only | TL-2026-0835 TL-2026-1339 TL-2026-1351 +8 | infrastructure · detect-or-block | |
| GTG-20006 | domain | russianearabroad[.]com | not in corpus | phishing · detect-or-block | ||
| GTG-20006 | domain | russianearabroad[.]org | not in corpus | infrastructure · detect-or-block | ||
| GTG-20006 | domain | static-ms[.]live | not in corpus | infrastructure · detect-or-block | ||
| GTG-20006 | domain | statistic-ms[.]live | held before 09-10 | TL-2026-2091 TL-2026-2167 | c2 · detect-or-block | |
| GTG-20006 | domain | stuseamandesilt[.]org | not in corpus | infrastructure · detect-or-block | ||
| GTG-20006 | domain | ukrinform-share[.]net | not in corpus | phishing · detect-or-block | ||
| GTG-20006 | domain | wa-connect[.]eu | held before 09-10 | TL-2026-2091 | c2 · detect-or-block | |
| GTG-20006 | domain | wa-meeting[.]com | held before 09-10 | TL-2026-2091 | phishing · detect-or-block | |
| GTG-20006 | anna.manager@russianearabroad[.]net | not in corpus | phishing · detect-or-block | |||
| GTG-20006 | events@embassy-protocol[.]int | not in corpus | phishing · detect-or-block | |||
| GTG-20006 | filename | WUEngine.exe | not in corpus | malware · detect-or-block | ||
| GTG-20006 | filename | client_20260507093021_4286d211_x64.exe | not in corpus | malware · detect-or-block | ||
| GTG-20006 | filename | fix_network.apk | not in corpus | malware · detect-or-block | ||
| GTG-20006 | filename | msedgeupdate_v3.exe | not in corpus | malware · detect-or-block | ||
| GTG-20006 | hostname | api.stuseamandesilt[.]org | not in corpus | c2 · detect-or-block | ||
| GTG-20006 | hostname | cdn.stuseamandesilt[.]org | not in corpus | malware_delivery · detect-or-block | ||
| GTG-20006 | hostname | mslivetest.duckdns[.]org | not in corpus | c2 · detect-or-block | ||
| GTG-20006 | hostname | pdfviewer2024.b-cdn[.]net | not in corpus | malware_delivery · detect-or-block | ||
| GTG-20006 | hostname | static.cdncounter[.]net | held before 09-10 | TL-2026-0245 | malware_delivery · detect-or-block | |
| GTG-20006 | hostname | teams.ms365-live[.]com | added after report | TL-2026-2446 TL-2026-2466 | phishing · detect-or-block | |
| GTG-20006 | hostname | update.stuseamandesilt[.]org | not in corpus | malware_delivery · detect-or-block | ||
| GTG-20006 | ipv4 | 104.145.210[.]184 | added after report | TL-2026-2446 TL-2026-2466 | phishing · detect-or-block | |
| GTG-20006 | ipv4 | 104.194.149[.]228 | not in corpus | phishing · detect-or-block | ||
| GTG-20006 | ipv4 | 104.194.151[.]133 | not in corpus | c2 · detect-or-block | ||
| GTG-20006 | ipv4 | 104.194.159[.]55 | not in corpus | c2 · detect-or-block | ||
| GTG-20006 | ipv4 | 144.172.114[.]192 | added after report | TL-2026-2466 | c2 · detect-or-block | |
| GTG-20006 | ipv4 | 148.135.195[.]111 | not in corpus | c2 · detect-or-block | ||
| GTG-20006 | ipv4 | 149.54.42[.]106 | not in corpus | infrastructure · detect-or-block | ||
| GTG-20006 | ipv4 | 185.198.234[.]101 | not in corpus | c2 · detect-or-block | ||
| GTG-20006 | ipv4 | 185.198.234[.]26 | not in corpus | infrastructure · detect-or-block | ||
| GTG-20006 | ipv4 | 2.26.53[.]194 | not in corpus | infrastructure · detect-or-block | ||
| GTG-20006 | ipv4 | 213.145.86[.]112 | held before 09-10 | TL-2026-1808 TL-2026-1838 TL-2026-1853 +3 | infrastructure · detect-or-block | |
| GTG-20006 | ipv4 | 31.57.243[.]154 | held before 09-10 | TL-2026-1808 TL-2026-1838 TL-2026-1853 +4 | phishing · detect-or-block | |
| GTG-20006 | ipv4 | 38.146.28[.]132 | held before 09-10 | TL-2026-1808 TL-2026-1838 TL-2026-1853 +3 | infrastructure · detect-or-block | |
| GTG-20006 | ipv4 | 38.146.28[.]75 | held before 09-10 | TL-2026-1808 TL-2026-1838 TL-2026-1853 +3 | infrastructure · detect-or-block | |
| GTG-20006 | sha256 | 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593 | held before 09-10 | TL-2026-1808 TL-2026-1838 TL-2026-1853 +4 | malware · detect-or-block | |
| GTG-20006 | sha256 | be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c | held before 09-10 | TL-2026-1808 TL-2026-1838 TL-2026-1853 +5 | malware · detect-or-block | |
| GTG-50014 | account | https[:]//t[.]me/Soraki_Bot | not in corpus | monetization · detect-or-block | ||
| GTG-50014 | domain | ari-chain[.]com | not in corpus | phishing · detect-or-block | ||
| GTG-50014 | domain | arichain[.]network | not in corpus | phishing · detect-or-block | ||
| GTG-50014 | domain | bitmart-mystery[.]com | not in corpus | phishing · detect-or-block | ||
| GTG-50014 | domain | defi-claim[.]xyz | not in corpus | phishing · detect-or-block | ||
| GTG-50014 | domain | emailsecure[.]email | not in corpus | phishing · detect-or-block | ||
| GTG-50014 | domain | mozilla[.]ws | not in corpus | phishing · detect-or-block | ||
| GTG-50014 | domain | on-pssword[.]com | not in corpus | phishing · detect-or-block | ||
| GTG-50014 | domain | policenationale[.]cc | added after report | TL-2026-2466 | monetization · detect-or-block | |
| GTG-50014 | domain | service-infos[.]info | not in corpus | phishing · detect-or-block | ||
| GTG-50014 | domain | signin-1psswoord[.]com | not in corpus | phishing · detect-or-block | ||
| GTG-50014 | domain | soraki[.]cc | added after report | TL-2026-2466 | monetization · detect-or-block | |
| GTG-50014 | domain | soraki[.]work | added after report | TL-2026-2466 | infrastructure · detect-or-block | |
| GTG-50014 | hostname | autoshop.policenationale[.]cc | added after report | TL-2026-2466 | monetization · detect-or-block | |
| GTG-50014 | hostname | esvfecawvjmchjslqyemho2fiduc59wzn.oast[.]fun | not in corpus | infrastructure · detect-or-block | ||
| GTG-50014 | hostname | soraki-proxy.20245aad98d27b1b1a2f0f103e1d7ee0.workers[.]dev | not in corpus | infrastructure · detect-or-block | ||
| GTG-50014 | hostname | updatebeacon.duckdns[.]org | added after report | TL-2026-2466 | c2 · detect-or-block | |
| GTG-50014 | ipv4 | 104.193.135[.]207 | not in corpus | egress · hunt · stale | 2026-04-05 → 2026-04-05 | |
| GTG-50014 | ipv4 | 104.36.50[.]54 | not in corpus | egress · hunt · stale | 2026-04-24 → 2026-04-24 | |
| GTG-50014 | ipv4 | 162.128.129[.]106 | added after report | TL-2026-2466 | egress · hunt · stale | 2026-02-20 → 2026-03-10 |
| GTG-50014 | ipv4 | 176.177.12[.]62 | not in corpus | egress · hunt · stale | 2026-04-19 → 2026-04-20 | |
| GTG-50014 | ipv4 | 185.65.134[.]199 | not in corpus | egress · hunt · stale | 2026-04-19 → 2026-04-28 | |
| GTG-50014 | ipv4 | 185.65.134[.]246 | added after report | TL-2026-2466 | egress · hunt · stale | 2026-04-19 → 2026-05-04 |
| GTG-50014 | ipv4 | 193.32.249[.]161 | added after report | TL-2026-2466 | egress · hunt · stale | 2026-03-21 → 2026-04-18 |
| GTG-50014 | ipv4 | 193.32.249[.]164 | not in corpus | egress · hunt · stale | 2026-04-18 → 2026-05-06 | |
| GTG-50014 | ipv4 | 193.32.249[.]170 | not in corpus | egress · hunt · stale | 2026-03-20 → 2026-04-06 | |
| GTG-50014 | ipv4 | 195.178.110[.]131 | added after report | TL-2026-2466 | infrastructure · hunt · stale | 2026-03-12 → 2026-04-30 |
| GTG-50014 | ipv4 | 45.148.10[.]242 | added after report | TL-2026-2466 | egress · hunt · stale | 2026-04-06 → 2026-04-27 |
| GTG-50014 | ipv4 | 91.171.138[.]169 | not in corpus | egress · hunt · stale | 2026-04-19 → 2026-04-21 | |
| GTG-50014 | ipv4 | 92.118.39[.]3 | not in corpus | egress · hunt · stale | 2026-04-10 → 2026-04-19 | |
| GTG-50014 | ipv6 | 2a01:e0a:2e2:aa40:b15d:5d28:6f4a[:]8d53 | not in corpus | egress · hunt · stale | 2026-04-20 → 2026-04-21 | |
| GTG-50014 | ipv6 | 2a04:cec0:1185:34f2:a150:7081:caed[:]448e | not in corpus | egress · hunt · stale | 2026-04-06 → 2026-04-07 | |
| GTG-50014 | telegram_bot_id | 8628746407 | not in corpus | infrastructure · detect-or-block | ||
| GTG-50014 | telegram_bot_id | 8632748474 | not in corpus | exfiltration · detect-or-block | ||
| GTG-50014 | telegram_bot_id | 8664033117 | not in corpus | exfiltration · detect-or-block | ||
| GTG-50014 | telegram_bot_id | 8709258476 | not in corpus | infrastructure · detect-or-block | ||
| GTG-50014 | telegram_chat_id | -1003311614569 | added after report | TL-2026-2466 | exfiltration · detect-or-block | |
| GTG-50014 | telegram_chat_id | -1003893854338 | added after report | TL-2026-2466 | exfiltration · detect-or-block | |
| GTG-50014 | telegram_user_id | 8179098353 | not in corpus | infrastructure · detect-or-block | ||
| GTG-50014 | url | https[:]//s3.eu-central-1.s4.mega[.]io/fuckyoubasil/ | not in corpus | exfiltration · detect-or-block | ||
| GTG-50020 | ipv4 | 141.133.125[.]208 | not in corpus | egress · hunt · stale | 2026-05-21 → 2026-05-23 | |
| GTG-50020 | ipv4 | 146.103.101[.]253 | not in corpus | egress · hunt · stale | 2026-05-21 → 2026-06-13 | |
| GTG-50020 | ipv4 | 146.103.97[.]169 | not in corpus | egress · hunt · stale | 2026-05-21 → 2026-05-25 | |
| GTG-50020 | ipv4 | 167.250.111[.]136 | not in corpus | egress · hunt · stale | 2026-05-23 → 2026-06-03 | |
| GTG-50020 | ipv4 | 178.16.54[.]141 | related only | related: TL-2026-0617 | egress · hunt · stale | 2026-05-21 → 2026-06-16 |
| GTG-50020 | ipv4 | 194.163.183[.]216 | not in corpus | egress · hunt · stale | 2026-05-23 → 2026-05-24 | |
| GTG-50020 | ipv4 | 202.66.167[.]230 | not in corpus | egress · hunt · stale | 2026-05-21 → 2026-06-04 | |
| GTG-50020 | ipv4 | 37.27.103[.]22 | not in corpus | egress · hunt · stale | 2026-05-26 → 2026-06-13 | |
| GTG-50021 | domain | aws-us-east-3[.]com | not in corpus | infrastructure · detect-or-block | ||
| GTG-50021 | domain | awstore[.]cloud | not in corpus | monetization · detect-or-block | ||
| GTG-50021 | domain | holdboost[.]store | not in corpus | c2 · detect-or-block | ||
| GTG-50021 | domain | kiro[.]cheap | not in corpus | monetization · detect-or-block | ||
| GTG-50021 | domain | sys-tools[.]cfd | not in corpus | c2 · detect-or-block | ||
| GTG-50021 | hostname | iymkjuzymkapovrntoxy.supabase[.]co | not in corpus | c2 · detect-or-block | ||
| GTG-50029 | domain | fafwatch[.]xyz | not in corpus | infrastructure · detect-or-block | 2026-04 | |
| GTG-50029 | domain | prod-artfkt[.]com | not in corpus | infrastructure · detect-or-block | 2026-04 | |
| GTG-50029 | hostname | frntrs-analytics-863060591218.europe-west1.run[.]app | not in corpus | c2 · detect-or-block · stale | 2026-05-13 → 2026-06 | |
| GTG-50029 | hostname | frntrs-analytics.dedyn[.]io | not in corpus | c2 · detect-or-block · stale | 2026-05-13 → 2026-06 | |
| GTG-50029 | ipv4 | 103.124.165[.]199 | not in corpus | egress · hunt · stale | 2026-03-25 → 2026-05-20 | |
| GTG-50029 | ipv4 | 103.141.60[.]144 | not in corpus | egress · hunt · stale | 2026-03-25 → 2026-05-20 | |
| GTG-50029 | ipv4 | 103.216.220[.]19 | not in corpus | egress · hunt · stale | 2026-03-25 → 2026-05-20 | |
| GTG-50029 | ipv4 | 136.144.242[.]56 | not in corpus | staging · detect-or-block · stale | 2026-05-17 → 2026-05-21 | |
| GTG-50029 | ipv4 | 138.199.6[.]208 | not in corpus | egress · hunt · stale | 2026-03-25 → 2026-05-20 | |
| GTG-50029 | ipv4 | 138.199.60[.]29 | not in corpus | egress · hunt · stale | 2026-03-25 → 2026-05-20 | |
| GTG-50029 | ipv4 | 139.59.2[.]243 | not in corpus | key_validation · detect-or-block · stale | 2026-02-06 → 2026-06-12 | |
| GTG-50029 | ipv4 | 146.70.116[.]131 | not in corpus | egress · hunt · stale | 2026-03-25 → 2026-05-20 | |
| GTG-50029 | ipv4 | 149.22.83[.]6 | not in corpus | egress · hunt · stale | 2026-03-25 → 2026-05-20 | |
| GTG-50029 | ipv4 | 158.173.46[.]118 | not in corpus | egress · hunt · stale | 2026-03-25 → 2026-05-20 | |
| GTG-50029 | ipv4 | 163.172.157[.]53 | not in corpus | dedicated_server · detect-or-block · stale | 2026-06-26 → 2026-07-04 | |
| GTG-50029 | ipv4 | 34.156.199[.]132 | not in corpus | exfiltration · hunt · stale | 2026-04 → 2026-05 | |
| GTG-50029 | ipv4 | 34.156.95[.]176 | not in corpus | exfiltration · hunt · stale | 2026-04 → 2026-05 | |
| GTG-50029 | ipv6 | 2001:ac8:27[:]89::a02d | not in corpus | egress · hunt · stale | 2026-03-25 → 2026-05-20 | |
| GTG-50029 | ipv6 | 2001:ac8:29[:]84::a01d | not in corpus | egress · hunt · stale | 2026-03-25 → 2026-05-20 | |
| GTG-50029 | ipv6 | 2001:bc8:711:5854:dc00:1ff:fe18[:]ba53 | not in corpus | dedicated_server · detect-or-block · stale | 2026-06-26 → 2026-07-04 | |
| GTG-50029 | onion | 3ell6n47y3ct4a3x67fbuz62q2mk2l4vo6eacho2suzftdshsnrfopyd[.]onion | not in corpus | infrastructure · detect-or-block · stale | 2026-05 → 2026-07 | |
| GTG-50029 | onion | 6mshbvhvzhdgumwwazf4jcep2xx4kdk6n4wgffc46msu2gc3j3t2fpad[.]onion | not in corpus | infrastructure · detect-or-block · stale | 2026-06 → 2026-06 | |
| GTG-24015 | account | https[:]//t[.]me/ATodaPotencia | not in corpus | amplification · detect-or-block | ||
| GTG-54002 | account | https[:]//x[.]com/AxumVoices | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | account | https[:]//x[.]com/Civicpulsemedia | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | account | https[:]//x[.]com/Fiftystatesnews | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | account | https[:]//x[.]com/Naijapulse_ | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | account | https[:]//x[.]com/PSarzameeninfo | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | account | https[:]//x[.]com/RussianWayMedia | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | account | https[:]//x[.]com/berlin_echo | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | account | https[:]//x[.]com/britishdaily_ | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | account | https[:]//x[.]com/cmwthpost | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | account | https[:]//x[.]com/elpulsopopular | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | account | https[:]//x[.]com/fuxingmedia | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | account | https[:]//x[.]com/journaljambo | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | account | https[:]//x[.]com/saudinews966 | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | account | https[:]//x[.]com/zionpulse | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | domain | alwatanalakbar[.]com | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | domain | axumvoices[.]org | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | domain | british-daily[.]com | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | domain | civicpulse[.]info | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | domain | commonwealth-post[.]com | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | domain | echoberlin[.]info | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | domain | elpulsopopular[.]com | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | domain | fiftystates[.]news | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | domain | jambojournal[.]org | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | domain | naijapulse[.]org | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | domain | pakssarzameen[.]org | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | domain | russianway[.]info | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | domain | voiceoftherejuvenation[.]com | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-54002 | domain | zion-pulse[.]com | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-84005 | account | https[:]//www.youtube[.]com/@malaysiapulseof | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-84005 | account | https[:]//x[.]com/Chikmore | not in corpus | persona · detect-or-block | 2026-05-17 | |
| GTG-84005 | account | https[:]//x[.]com/SHIHAN1947 | not in corpus | persona · detect-or-block | 2026-05-17 | |
| GTG-84005 | account | https[:]//x[.]com/adriansantodo | not in corpus | persona · detect-or-block | 2026-05-17 | |
| GTG-84005 | account | https[:]//x[.]com/armsam1209 | not in corpus | persona · detect-or-block | 2026-05-17 | |
| GTG-84005 | account | https[:]//x[.]com/avihoue | not in corpus | persona · detect-or-block | 2026-05-17 | |
| GTG-84005 | account | https[:]//x[.]com/bmmyangels | not in corpus | persona · detect-or-block | 2026-05-17 | |
| GTG-84005 | account | https[:]//x[.]com/exceiivier | not in corpus | persona · detect-or-block | 2026-05-17 | |
| GTG-84005 | account | https[:]//x[.]com/garyponce | not in corpus | persona · detect-or-block | 2026-05-17 | |
| GTG-84005 | account | https[:]//x[.]com/goldsteve1 | not in corpus | persona · detect-or-block | 2026-05-17 | |
| GTG-84005 | account | https[:]//x[.]com/hugolaurent | not in corpus | persona · detect-or-block | 2026-05-17 | |
| GTG-84005 | account | https[:]//x[.]com/kioskou | not in corpus | persona · detect-or-block | 2026-05-17 | |
| GTG-84005 | account | https[:]//x[.]com/telkisoszoba | not in corpus | persona · detect-or-block | 2026-05-17 | |
| GTG-84005 | domain | malaysiapulse[.]com | not in corpus | fabricated_outlet · detect-or-block | 2026-05-10 | |
| GTG-84005 | domain | bbsteknoloji[.]com | not in corpus | infrastructure · detect-or-block | ||
| GTG-84005 | ipv4 | 157.180.93[.]7 | not in corpus | infrastructure · detect-or-block | ||
| GTG-84005 | ipv4 | 167.235.157[.]100 | not in corpus | infrastructure · detect-or-block | ||
| GTG-84005 | ipv4 | 23.88.118[.]216 | not in corpus | infrastructure · detect-or-block | ||
| GTG-84005 | ipv4 | 46.225.91[.]180 | not in corpus | infrastructure · detect-or-block | ||
| GTG-84005 | ipv4 | 46.62.214[.]3 | not in corpus | infrastructure · detect-or-block | ||
| GTG-84005 | ipv4 | 91.99.117[.]166 | not in corpus | infrastructure · detect-or-block | ||
| GTG-84006 | account | https[:]//www.instagram[.]com/fwr.ir | not in corpus | persona · detect-or-block | ||
| GTG-84006 | account | https[:]//t[.]me/FWR_ir | not in corpus | persona · detect-or-block | ||
| GTG-84006 | account | https[:]//t[.]me/anti_silent | not in corpus | persona · detect-or-block | ||
| GTG-84006 | account | https[:]//www.instagram[.]com/faryade_mamnoo | not in corpus | amplification · detect-or-block | ||
| GTG-84006 | account | https[:]//www.instagram[.]com/iranpayam_tehran5 | not in corpus | amplification · detect-or-block | ||
| GTG-84006 | account | https[:]//www.instagram[.]com/javanane_shargt | not in corpus | amplification · detect-or-block | ||
| GTG-84006 | account | https[:]//www.instagram[.]com/khabar_fouri_mardom | not in corpus | amplification · detect-or-block | ||
| GTG-84006 | account | https[:]//www.instagram[.]com/tehranchekhabar19 | not in corpus | fabricated_outlet · detect-or-block | ||
| GTG-84006 | account | https[:]//www.instagram[.]com/jomhouri_democratic | not in corpus | amplification · detect-or-block | ||
| GTG-84006 | account | https[:]//t[.]me/jomhouri_democratic | not in corpus | amplification · detect-or-block | ||
| GTG-30006 | android_package | com.app.safeguard | not in corpus | malware · detect-or-block | ||
| GTG-30006 | filename | fontdrivehost.exe | not in corpus | persistence · detect-or-block | ||
| GTG-30006 | filename | telegram_listener_v12_2.vbs | not in corpus | malware · detect-or-block | ||
| GTG-30006 | filepath | C:\ProgramData\fontdrivehostServicePackages\drv3060nt10-69s64mmm\fontdrivehost.exe | not in corpus | persistence · detect-or-block | ||
| GTG-30006 | scheduled_task | Calc_AdminTask | not in corpus | persistence · detect-or-block | ||
| GTG-30006 | scheduled_task | SECOMS64_AdminTask | not in corpus | persistence · detect-or-block | ||
| GTG-30006 | telegram_chat_id | -1003197249446 | not in corpus | c2 · detect-or-block | ||
| GTG-30006 | telegram_chat_id | -1003233252 | not in corpus | c2 · detect-or-block | ||
| GTG-30006 | telegram_chat_id | -10078223223323 | not in corpus | c2 · detect-or-block | ||
| GTG-30006 | telegram_chat_id | 7828288328 | not in corpus | c2 · detect-or-block | ||
| GTG-15001 | app_id | com.cavalier.nalo | not in corpus | scam_app · detect-or-block | ||
| GTG-15001 | app_id | com.qiga.vio | not in corpus | scam_app · detect-or-block | ||
| GTG-15001 | domain | archat[.]us | not in corpus | infrastructure · detect-or-block | ||
| GTG-15001 | domain | heyhru[.]com | not in corpus | infrastructure · detect-or-block | ||
| GTG-15001 | domain | sitin[.]ai | not in corpus | infrastructure · detect-or-block | ||
| GTG-15001 | hostname | file.archat[.]us | not in corpus | infrastructure · detect-or-block | ||
| GTG-15001 | hostname | managedkafka.heyhru-server.cloud[.]goog | not in corpus | infrastructure · detect-or-block | ||
| GTG-15001 | ipv4 | 38.129.138[.]244 | not in corpus | egress · hunt · stale | 2026-04 → 2026-04 | |
| Storm-2945 (Microsoft) | ipv4 | 104.194.159[.]150 | Threadlinqs extra | TL-2026-1808 | 2026-07-31 | |
| Storm-2945 (Microsoft) | ipv4 | 107.189.26[.]194 | Threadlinqs extra | TL-2026-1838 | 2026-08-03 | |
| Storm-2945 (Microsoft) | url | hxxps://213.145.86[.]112/t/pixel.gif?m= | Threadlinqs extra | TL-2026-1857 | 2026-08-04 | |
| Storm-2945 (Microsoft) | url | hxxps://213.145.86[.]112/cdn/chunks/polyfill-7e2b.min.js | Threadlinqs extra | TL-2026-1857 | 2026-08-04 | |
| Storm-2945 (Microsoft) | url | hxxps://213.145.86[.]112/t/event | Threadlinqs extra | TL-2026-1857 | 2026-08-04 | |
| UNC7005 (Google) | domain | wa-connect[.]net | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | domain | wa-invite[.]com | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | domain | wa-device[.]com | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | domain | shopinvite[.]org | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | domain | globsec[.]net | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | domain | finishoperations[.]com | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | domain | finishoperations[.]org | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | domain | foc-share[.]com | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | domain | share-foc[.]com | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | domain | internal-share[.]com | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | domain | foc-share[.]org | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | ipv4 | 107.189.18[.]7 | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | sha256 | 1d9299799a7b8da67c44ebec064d64542c27645f8e84de4a22ca3f6cbc843e3c | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | sha256 | c5826032207d623a7f6caec8465af7364eccc355f9a48897da2a54f3e4420265 | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | sha256 | 125752ad7c20d715920a3b2fb0fdde660f07b3f2b053665cf38c2d6d9de86e1e | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | sha256 | 403b624e35777cbc07dbe66398b21bba70396a20b859c880732338ce1dd1f41f | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | sha256 | a06a8fd1b6fa1924199a4540cf16d089217ce8f78c617739946f145fd1fc88c1 | Threadlinqs extra | TL-2026-2091 | 2026-08-21 | |
| UNC7005 (Google) | sha256 | 5b8d50c2e8cc3038b7c6e6dbf1219f6e814930a1e3c0053143a1191ae67f8ffc | Threadlinqs extra | TL-2026-2091 | 2026-08-21 |
Indicators are shown defanged. "Stale" means Anthropic's last-seen date is more than 60 days before publication, so expect rotation. The role and handling columns are Anthropic's labels; "hunt" is the handling flag Anthropic puts on 36 rows, mostly attacker egress addresses, so search logs for them rather than blocking. The CSV holds the refanged values plus every column shown here.
Frequently asked questions
What did Anthropic's September 2026 AI misuse report find, and how much was already known?
Anthropic's "Detecting and countering misuse of AI: September 2026", published September 10, 2026, covers 43 case studies with 209 indicators in a CSV. Threadlinqs held 17 of them beforehand, all from GTG-20006, while 175 match nothing in our corpus. Of the 32 GTG case groups plus the weapons and biology rows, 21 had technique-level or stronger prior coverage and the other 13 only related context.
What is GTG-20006, and how does it relate to CaptiveCrunch and Storm-2945?
GTG-20006, a Russian-nexus espionage cluster in Anthropic's September 10, 2026 report, used Claude Code agents to automate much of its operation, even rebuilding malware that security products caught PDF pp. 6–7. Anthropic's attribution points to Midnight Blizzard. For hunters, what matters is infrastructure: its lookalike Microsoft domains, addresses and malware hashes match ReliaQuest's and Microsoft's CaptiveCrunch reporting on Storm-2945 (TL-2026-1808) and Google's UNC7005 reporting (TL-2026-2091). Overlap does not put every workstream in those clusters.
Which Anthropic indicators were already in Threadlinqs before the report?
Of Anthropic's 209 CSV indicators, 17 sat in 7 earlier Threadlinqs records, all from GTG-20006: CaptiveCrunch domains, addresses and hashes (via ReliaQuest and Microsoft, held since July 31, 2026), UNC7005 domains such as chamber-ua[.]org (via Google, since August 21, 2026) and cdncounter[.]net with its static host (Google's DarkSword reporting, since March 18, 2026, TL-2026-0245). Earlier records also held projectnightcrawler[.]dev, a researcher's server we mark context-only. Another 15 appear only in our write-ups of the report.
Is ShinyHunters behind GTG-50014?
Anthropic's September 2026 AI misuse report calls GTG-50014 suspected ShinyHunters affiliates and cites no outside source. Threadlinqs can neither confirm nor refute that: no record written before September 10, 2026 holds an actor-controlled GTG-50014 indicator, and the exact matches sit only in our write-up of the disclosure (TL-2026-2466). Beyond that we hold only collective-level parallels, such as ShinyHunters' abuse of SaaS integration tokens for data theft and extortion, reported under UNC6040 (TL-2026-1275).
How do I hunt for the report's indicators in Splunk or Sentinel?
Threadlinqs publishes the 209 indicators from Anthropic's September 2026 AI misuse report as a refanged CSV and a STIX 2.1 bundle in the hunt pack. In Splunk, upload the CSV as lookup file threadlinqs_anthropic_ai_misuse_2026_09.csv and run the SPL over proxy, DNS and network logs; in Sentinel, the KQL pulls it with externaldata, and a host sweep covers files, tasks and senders. Treat detect-or-block hits as urgent and hunt hits as leads.
Should I block the egress IPs in Anthropic's CSV?
No. Anthropic's September 2026 CSV flags its egress addresses as hunt, not detect-or-block. It gives no reason, but where it describes them, as for GTG-50029, they are commercial VPN or datacentre exits other people share, and every hunt-flagged row was last seen over 60 days before publication. Search old logs in each row's date window instead. Our derivative Sigma rule in TL-2026-2466 rates five such addresses critical; demote them to a hunt.
Is projectnightcrawler[.]dev attacker infrastructure?
Probably not. Anthropic's September 2026 CSV lists it under GTG-20006 as operator or lure infrastructure, but earlier Threadlinqs records (TL-2026-0835, TL-2026-1865) describe a researcher's self-hosted platform for exploit proofs of concept, set up after GitHub and GitLab takedowns. The same researcher published MiniPlasma, which the report places in the operator's toolkit (TL-2026-0523). A hit most likely means a public exploit download: investigate the host, but don't treat the domain as espionage C2.
What is illicit distillation, and were the labs already named?
Training a small model on a bigger one's answers is routine; Anthropic calls it illicit when done without permission, covertly and at industrial scale, usually via fraudulent accounts and proxy resellers. Its September 10, 2026 report names seven China-based labs: Alibaba's Qwen team, Moonshot AI, DeepSeek, Zhipu (Z.ai), Xiaomi, SenseTime and MiniMax. Five were already public: Anthropic's February 2026 disclosure named DeepSeek, Moonshot and MiniMax, and US advisory AA26-251A of September 8 also named Alibaba and Z.ai (TL-2026-2405, TL-2026-2413).
Methodology, limitations and data freshness
Every Threadlinqs number reflects the September 25, 2026 snapshot. Linked live records change with nightly ingest, which can turn a "not in corpus" row into a match but cannot change what we held before September 10, 2026.
"Not in corpus" means only that the string appears nowhere in our records; the indicator could still be live, malicious and well known elsewhere. We do not ingest every feed, and many of Anthropic's indicators are egress addresses and VPN exits operators used to reach Claude, which few outside sources ever see.
Our created_at field stores a date, not a time, so a same-day vendor post cannot be ordered against a record, and anything dated September 10, 2026 counts as derivative even if written before the report went live.
Staleness rests on Anthropic's own first-seen and last-seen dates, not re-checked against our telemetry; hosting-type judgements rest on the context notes in our records.
Drafting was AI-assisted and reviewed by the Threadlinqs Team. Claims about our records rest on quote-checked evidence in the snapshot; where our paraphrase differs from Anthropic's text, Anthropic's text governs.
How to cite this analysis
Threadlinqs Team. "Anthropic's September 2026 AI misuse report, mapped against the Threadlinqs corpus." Threadlinqs Intelligence, September 26, 2026. https://threadlinqs.com/blog/anthropic-claude-misuse-sep2026/
Sources
- Anthropic — Detecting and countering misuse of AI: September 2026 (report page)
- Anthropic — full report (PDF, 154 pages)
- Anthropic — indicators of compromise (CSV, 209 rows)
- CISA Advisory AA26-251A: China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
- ReliaQuest — DNS Poisoning Tactics Expand to Hospitality Wi-Fi
- SecurityWeek: US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities
- Bloomberg: US Says Alibaba, DeepSeek Have Systematically Siphoned AI Models
- Chinatalk Media: How to Buy Cheap Claude Tokens in China—The Transfer Station Economy
- CISPA: Real Money, Fake Models (arXiv 2603.01919)
- Tom's Hardware: Chinese Grey Market Sells Claude API Access at 90% Off Through Proxy Networks
- OpenAI Letter to U.S. House Select Committee on Strategic Competition (Feb 12, 2026)
- White House NSTM-4: Adversarial Distillation of American AI Models
- Just Security: The Emerging U.S. Response to Adversarial Distillation
- The Decoder: How China's gray market sells Claude tokens
- NIST AI 100-2e2025: Adversarial Machine Learning - A Taxonomy and Terminology of Attacks and Mitigations
- DeepSeek-V3 Technical Report (arXiv)
- Hijacked Hotel Wi-Fi Pushes Fake Browser Updates to Install Malware — The Hacker News
- Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
- Russian hackers hijack hotel Wi-Fi to steal Microsoft 365 tokens
- SecurityWeek — Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
- Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication — Volexity
- Hotel Wi-Fi Attacks Use Custom Malware to Breach Microsoft 365 Accounts — BleepingComputer
- Russia's SVR borks public Wi-Fis for digital surveillance — The Register
- CornFlake — Malpedia Entry
- ChocoShell — Malpedia Entry
- Distinct Clusters Target Individuals of Interest to Russia
- Russian Hacker Used Jailbroken Gemini to Steal Admin Credentials and Drain Crypto Wallets
- Storm-2372 conducts device code phishing campaign
- Russian snoops add OAuth abuse to targeted phishing campaigns
- Fake Conferences, OAuth and WhatsApp: Inside Russia's New Espionage Tactics
- Unit 42 (Palo Alto): Token Jacking — Cybercriminals Could Be Stealing Your AI Resources
- GTIG: The Proliferation of DarkSword - iOS Exploit Chain Adopted by Multiple Threat Actors
- Lookout: Attackers Wielding DarkSword Threaten iOS Users
- iVerify: Inside DarkSword - A New iOS Exploit Kit Delivered Via Compromised Legitimate Websites
- CyberScoop: Second iOS exploit kit emerges from suspected Russian hackers
- BleepingComputer: New DarkSword iOS exploit used in infostealer attack on iPhones
- SOC Prime: CVE-2026-20700 - Apple Patches Zero-Day Exploited in Sophisticated Attacks
- Help Net Security: Apple fixes zero-day flaw (CVE-2026-20700)
- GTIG: Coruna - The Mysterious Journey of a Powerful iOS Exploit Kit
- Hotel Wi-Fi Gateways Weaponized to Steal Microsoft 365 Logins: MFA Bypassed
- Microsoft Issues Hotel Wi-Fi Warning For Windows PC Users
- ReliaQuest Uncovers Widespread DNS Poisoning Campaign Targeting Hotel and Conference Wi-Fi Gateways for Microsoft 365 Credential Theft
- Cited in Anthropic's report — github.com/vxcontrol/pentagi
- Cited in Anthropic's report — github.com/wppconnect-team/wppconnect
- Cited in Anthropic's report — microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/
- Cited in Anthropic's report — github.com/trufflesecurity/trufflehog
- Cited in Anthropic's report — brookings.edu/articles/the-breakout-scale-measuring-the-impact-of-influence-operations/
- Cited in Anthropic's report — alleyesonwagner.org/2026/05/26/manufacturing-enemies-politologys-war-on-civil-society-in-car/
- Cited in Anthropic's report — alleyesonwagner.org/2026/07/07/the-svr-arms-politology-with-chatgpt-and-claude-in-the-central-africa
- Cited in Anthropic's report — wired.com/story/opinion-in-kenya-influencers-are-hired-to-spread-disinformation/
- Cited in Anthropic's report — forbiddenstories.org/osint-s2t-unlocking-cyberspace-journalists-activists/
- Cited in Anthropic's report — hrw.org/news/2025/02/13/mali-au-action-needed-end-crackdown-opposition-dissent
- Cited in Anthropic's report — cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversa
Related reading
- npm Supply Chain Attacks 2026: every documented compromise
- The AI infrastructure pre-auth RCE wave (May 2026)
- TeamPCP: from a LiteLLM compromise to ransomware
- AI prompt injection in the wild
- Threadlinqs MCP server v8.1.0: query this corpus from your agent
Take the CSV, the bundle and the rules quoted here. The CSV carries our status for every indicator (the bundle for all but two scheduled-task names), so you can see what was known and when. Linked records carry indicators, ATT&CK mappings and detection logic, and we update them. If a sweep hits, start from the linked record.
[ explore_the_platform ]