ANTHROPIC-AI-MISUSE-2026-09HIGHPublished Companion Analysis

Independent analysis · not affiliated with or endorsed by Anthropic

Threadlinqs companion to Anthropic's "Detecting and countering misuse of AI: September 2026"

Threadlinqs checked every case study and all 209 CSV indicators in Anthropic's September 2026 report on AI misuse. Only 17, all from the Russian espionage case GTG-20006, were in our corpus as actor infrastructure before publication; other prior coverage is mostly technique-level, and most influence and PRC or Malian surveillance cases have thematic context only.

79 min read

Independent analysis by the Threadlinqs Team, not affiliated with or endorsed by Anthropic. Except for short credited quotes and the indicator descriptions reproduced from Anthropic's CSV, what we say about the report is our paraphrase, with page links; its indicators and their descriptions are republished, credited, for defensive use alongside their status in our corpus.

anthropicai-misusegtg-20006midnight-blizzardshinyhunterscaptivecrunchai-supply-chainllmjackingdistillationinfluence-opsiocsspl-kql-sigma
Jump to section
  1. Key findings
  2. Coverage matrix: every case against our corpus
  3. Hunt pack: sweep your telemetry for every published indicator
  4. How we cross-referenced the report
  5. Cyber operations
  6. The AI supply chain as a target
  7. Influence operations
  8. Surveillance operations
  9. Conventional weapons
  10. Biological misuse
  11. Scams and fraud
  12. Illicit distillation
  13. The unusual part: pre-burned infrastructure, public tooling and a server we read differently
  14. Cross-cutting trends: what our corpus shows
  15. ATT&CK and ATLAS mapping
  16. Entity graph: cases, actors, records and shared indicators
  17. Defender playbook
  18. Indicator master table
  19. Frequently asked questions
  20. Methodology, limitations and data freshness
  21. Sources
  22. Related reading
threadlinqs@intel:~$ xref --source anthropic-ai-misuse-2026-09 --corpus threadlinqs --since 2026-02-01source Anthropic — Detecting and countering misuse of AI: September 2026 (2026-09-10) cases 43 case studies · 209 published indicators corpus 2,473 threats · 62,332 IoCs · 22,696 detections (snapshot 2026-09-25) result 17 IoCs held before 09-10 · 21 cases with prior coverage · 51 records linked

Threadlinqs had indicator-level visibility of only one of Anthropic's cases before the report. 17 of the 209 indicators in Anthropic's CSV were in our corpus as actor-controlled infrastructure before September 10, 2026, all on Anthropic's GTG-20006 list and all from earlier vendor reporting; 37 pre-publication detection rules contain them. Elsewhere, earlier coverage is behavioural: of 32 GTG case groups plus the weapons and biology rows, 21 had verified technique-level or stronger links before publication and only 6 reached actor or indicator level.

The gap is vantage point: Anthropic sees misuse while operations are still being planned; defenders see it later in telemetry, if at all. So this companion leads with behavioural detections that survive infrastructure rotation, adds 23 sibling indicators and one correction, and gives retro-hunt guidance for stale VPN exits.

Key findings

  • The 17 CSV indicators we held as actor-controlled infrastructure before September 10, 2026, all from GTG-20006, were first published by vendors: ReliaQuest (July 23, 2026) and Microsoft (July 31) on the hotel Wi-Fi campaign Microsoft calls CaptiveCrunch (Storm-2945, TL-2026-1808), Google on UNC7005 (August 20, TL-2026-2091) and the DarkSword disclosures of March 17-18 (TL-2026-0245).
  • 175 of the 209 appear nowhere in our corpus, 15 only in our write-ups of Anthropic's disclosure (TL-2026-2446, TL-2026-2466) and one, a GTG-50020 egress address, only inside a bulletproof-hosting range we list (TL-2026-0617). Many are VPN or hosting exits last seen two to six months earlier: retro-hunt material, not blocklist entries.
  • We add 23 indicators Anthropic did not list, all from pre-publication GTG-20006 records: eleven more UNC7005 phishing domains (WhatsApp and Finnish operations-centre spoofs among them); three ChocoShell beacon, tooling and exfiltration paths on 213.145.86[.]112; two C2 hosts and a hosting IP; six malware and phishing-page hashes; and CornFlake's sync[.]dat config (TL-2026-2091, TL-2026-1857, TL-2026-1838, TL-2026-1808).
  • The only other CSV string in pre-publication records, projectnightcrawler[.]dev, is operator or lure infrastructure to Anthropic but, in our records, the self-hosted proof-of-concept site of the researcher behind MiniPlasma, a tool in GTG-20006's kit. We mark it context-only: a hit most likely means someone pulled public exploit code (TL-2026-0835, TL-2026-1865, TL-2026-0523).
  • 51 pre-publication records reach technique level or better for 21 case groups and carry 485 detections, covering device-code token replay (TL-2026-0943-KQL-003), WordPress mu-plugin backdoors (TL-2026-0817-SPL-002), STS-then-Bedrock checks on stolen keys (TL-2026-0514-KQL-002) and scanners calling LLM APIs (TL-2026-2390-KQL-001).
  • Only 6 of the 32 GTG groups had actor- or indicator-level coverage before publication: GTG-20006 and five distillation cases in CISA, NSA and FBI advisory AA26-251A (September 8, 2026; ingested September 8-9, TL-2026-2405, TL-2026-2413). Our records of the advisory name the labs but not the covert customer-traffic relays or reasoning-signature replay, and cover MiniMax but not SenseTime.
  • Influence operations and domestic surveillance are the blind spot: 13 case groups, mostly those plus the weapons cases, have only thematic context, and none of the 28 indicators for the fake local-news network (GTG-54002), the 21 for the Malaysian election platform (GTG-84005) or the 10 for the MEK/NCRI network (GTG-84006) was in the corpus.
43
case studies in the report
209
published indicators checked
17
already in Threadlinqs before 09-10
21
cases with prior Threadlinqs coverage
51
Threadlinqs records linked (A–C)
485
detections on those records

Coverage matrix: every case against our corpus

Each row is one case group: the report's 43 case studies, as we count them, fold into 32 GTG groups (GTG-16012 and GTG-16003 share a write-up) plus one policy-level row for the six GTG-labelled weapons cases and one for the five unlabelled biology cases, neither scored on indicators. GTG numbers are Anthropic's own tracking labels (PDF p. 4), not public actor names; case sections add public names where a named source supplies one.

Each cell shows the strongest relation that survived verification:

  • A: an actor-controlled indicator from Anthropic's list in a record created before publication.
  • B: the same actor or campaign, per a named vendor or government source.
  • C: a shared tool or distinctive technique cluster, with no claim about who is behind it.
  • D: related context only (region, sector or trend), never identity.
  • drv: dated September 10, 2026 or later, ours or others'; listed for reference, never prior coverage.

Detections count rules on tier A-C records only.

Coverage matrix: Anthropic cases vs. the Threadlinqs corpus
AA · indicator overlap before 09-10BB · same actor/campaign (named source)CC · shared tool or TTPDD · related coveragedrvdated 09-10 or later·no coverage

Swipe the table sideways to see all seven coverage columns →

CaseIoC overlapActorToolingTTPsDetectionsCovered pre-09-10
Cyber operations
GTG-20006 — Agentic Russian espionage and the CaptiveCrunch (Storm-2945) overlapAACC99yes
GTG-50014 — Suspected ShinyHunters affiliates mining secrets at scaledrv··C99yes
GTG-10007 — A Chinese-speaking exploit foundry run by agent swarms···C54yes
GTG-50029 — A lone French-speaking hacktivist's WordPress breach-and-dox campaign···C18yes
AI supply chain
GTG-50021 — Fake Claude resellers and the stolen-key economy···C122yes
GTG-50020 — A Russian-speaking crew moves from hotel-booking breaches to AI vendor keys··DC27yes
Influence operations
GTG-04001 — Wagner-linked radio hub in Bangui used Claude to run a Russian influence operation in the Central African Republic···D·no
GTG-54002 — Fake local-news network Anthropic traces to LKM Company···C27yes
GTG-84005 — Malaysia election-manipulation platform Anthropic ties to BBS Bilisim···C18yes
GTG-24015 — Claude used as a sub-editing desk for Russian state-media output aimed at Moldova, Latin America, Africa and RT's global audience···D·no
GTG-34001 — Iranian state propaganda bodies use Claude to run 'soft war' influence campaigns···D·no
GTG-54006 — Automated Bengali fake-news pipeline boosting the Awami League for rural Bangladeshi livestream audiences···D·no
GTG-84006 — Activist-impersonating agent platform Anthropic links to MEK/NCRI···C9yes
GTG-54004 — Single-operator Kenyan political astroturfing network using AI-written tweet batches···D·no
GTG-84002 — UAE-linked AI persona drives anti-Muslim Brotherhood influence and UN lobbying campaign over Sudan···D·no
Surveillance
GTG-54009 — Pilot surveillance platform profiling Iranian and Gulf social-media users, built by or for the vendor S2T, per Anthropic···D·no
GTG-14010 — PRC-aligned operator uses Claude for Uyghur surveillance and informant recruitment in Syria···D·no
GTG-14020 — PRC-aligned religious-affairs collection desk uses Claude to build dossiers on faith leaders and diaspora communities···D·no
GTG-14021 — PRC local security organs misuse Claude for "stability maintenance" surveillance and transnational repression···D·no
GTG-14022 — Contractor-run PRC 'public opinion monitoring' pipeline built on Claude to surveil dissidents, diaspora and foreign media···D·no
GTG-34007 — Iranian security units building surveillance tooling···C9yes
GTG-50027 — Claude-built nationwide telecom interception platform ("Lakana 360") for Mali's state security agency···D·no
GTG-30004 — Automated profiling and a modified NanoDump··CC30yes
GTG-30005 — Open-source targeting of US naval forces···C18yes
GTG-30006 — An Iran-only surveillance toolkit built in fragments···C9yes
Conventional weapons
6 cases — Weapons development and procurement···D··
Biological misuse
5 cases — Dual-use research misuse···C27yes
Scams and fraud
GTG-15001 — A dating-app network run mostly by AI personas···C9yes
Illicit distillation
GTG-16005 — Alibaba's forced-reasoning distillation, per Anthropic·B·C27yes
GTG-16002 — Moonshot relays Kimi customers to Claude, per Anthropic·B·D18yes
GTG-16001 — DeepSeek's covert relay and reasoning replay, per Anthropic·B·D18yes
GTG-16006 — Zhipu (Z.ai) cleans harvested reasoning with Claude, per Anthropic·B·D18yes
GTG-16008 — Xiaomi replays real MiMo sessions to Claude, per Anthropic···C18yes
GTG-16012 / GTG-16003 — GTG-16012 and GTG-16003 — SenseTime's bought transcripts and MiniMax's shell-company proxy, per Anthropic·B·C27yes

Each cell shows the strongest verified relation for that dimension. Letters carry the tier, so the matrix reads without colour. "drv" marks coverage dated 2026-09-10 or later, which never counts as prior coverage.

Published indicators per case, by Threadlinqs status
in Threadlinqs before 09-10added after the reportshared / context onlynot in corpusThreadlinqs extras (same records)

Swipe the chart sideways →

0 10 20 30 40 50 60 GTG-20006 GTG-20006 — in Threadlinqs before 09-10: 17 GTG-20006 — added after the report: 3 GTG-20006 — shared / context only: 1 GTG-20006 — not in corpus: 34 55 GTG-50014 GTG-50014 — added after the report: 12 GTG-50014 — not in corpus: 28 40 GTG-54002 GTG-54002 — not in corpus: 28 28 GTG-50029 GTG-50029 — not in corpus: 22 22 GTG-84005 GTG-84005 — not in corpus: 21 21 UNC7005 (Google) UNC7005 (Google) — Threadlinqs extras (same records): 18 18 GTG-84006 GTG-84006 — not in corpus: 10 10 GTG-30006 GTG-30006 — not in corpus: 10 10 GTG-50020 GTG-50020 — not in corpus: 8 8 GTG-15001 GTG-15001 — not in corpus: 8 8 GTG-50021 GTG-50021 — not in corpus: 6 6 Storm-2945 (Microsoft) Storm-2945 (Microsoft) — Threadlinqs extras (same records): 5 5 GTG-24015 GTG-24015 — not in corpus: 1 1

Counts per Anthropic case: the 209 CSV indicators plus Threadlinqs extras pulled only from records whose overlap survived verification. Hatched = present only in records we wrote after 2026-09-10.

Show data table
Casein Threadlinqs before 09-10added after the reportshared / context onlynot in corpusThreadlinqs extras (same records)
GTG-200061731340
GTG-500140120280
GTG-54002000280
GTG-50029000220
GTG-84005000210
UNC7005 (Google)000018
GTG-84006000100
GTG-30006000100
GTG-5002000080
GTG-1500100080
GTG-5002100060
Storm-2945 (Microsoft)00005
GTG-2401500010
Threadlinqs records (tiers A–C and after-report write-ups) on the report timeline
ABCwritten after the reportAnthropic's activity window

Swipe the chart sideways →

Dec '25 Jan '26 Feb Mar Apr May Jun Jul Aug Sep report 09-10 GTG-20006 TL-2026-0245 (A) 2026-03-18 — DarkSword: iOS Exploit Chain Adopted by Multiple Threat… TL-2026-0523 (C) 2026-05-17 — Windows 'MiniPlasma' Zero-Day — Unpatched SYSTEM LPE via… TL-2026-0561 (C) 2026-05-22 — ROADtools Misuse in Cloud Intrusions — Nation-State Abuse… TL-2026-0943 (C) 2026-06-25 — Microsoft Entra ID Device Code Phishing — OAuth 2.0 Device… TL-2026-1808 (A) 2026-07-31 — CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster)… TL-2026-1838 (A) 2026-08-03 — CaptiveCrunch: Storm-2945 (Midnight Blizzard / APT29)… TL-2026-1853 (A) 2026-08-04 — CaptiveCrunch: Russian SVR-Aligned Storm-2945 Hijacks Hotel… TL-2026-1857 (A) 2026-08-04 — CaptiveCrunch Campaign — Storm-2945 Delivers… TL-2026-2091 (A) 2026-08-21 — Russian APT29-linked clusters (UNC6293, UNC7005) and… TL-2026-2170 (C) 2026-08-26 — Russian State-Backed UNC5792/UNC4221 Phish EU Officials… TL-2026-2167 (A) 2026-08-27 — Russian Cyber Espionage Infrastructure Uses Evilginx and… TL-2026-2446 (DER) 2026-09-11 — Midnight Blizzard (GTG-20006) Used Claude AI Agents to… TL-2026-2466 (DER) 2026-09-12 — Nation-State and Financially Motivated Actors Weaponize… TL-2026-2559 (DER) 2026-09-18 — AI-Powered Polymorphic Malware Queries LLMs at Runtime to… TL-2026-2614 (DER) 2026-09-22 — Microsoft-Led Coalition Takes Down EvilTokens AI-Powered… GTG-50014 GTG-50014 — activity window per Anthropic: 2026-02-20 to 2026-05-06 TL-2026-0411 (C) 2026-04-22 — Bissa Scanner — AI-Assisted Mass Exploitation and… TL-2026-0451 (C) 2026-05-04 — Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM… TL-2026-0514 (C) 2026-05-14 — NATS-as-C2: KeyHunter Distributed Worker Botnet Harvests… TL-2026-0527 (C) 2026-05-18 — Grafana Labs Source Code Theft via Stolen GitHub Access… TL-2026-1275 (C) 2026-07-13 — ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against… TL-2026-1288 (C) 2026-07-14 — Microsoft Maps Year-Long ShinyHunters-Linked Salesforce… TL-2026-1705 (C) 2026-07-26 — Instructure Canvas Breach (ShinyHunters) Drives 58% of H1… TL-2026-1711 (C) 2026-07-26 — ShinyHunters (UNC6040) OAuth Abuse & UNC6395… TL-2026-2341 (C) 2026-09-05 — Frontier AI Agents Compress Full Enterprise Intrusion Chain… TL-2026-2339 (C) 2026-09-05 — Coordinated GitHub API Enumeration and Access Token Abuse… TL-2026-2390 (C) 2026-09-08 — Autonomous AI-agent frameworks automating credential theft… TL-2026-2466 (DER) 2026-09-12 — Nation-State and Financially Motivated Actors Weaponize… TL-2026-2531 (DER) 2026-09-16 — PhantomRaven: LLM-Generated npm Information Stealer Used… TL-2026-2564 (DER) 2026-09-18 — France Dark Web Threat Landscape: Ransomware and Hacktivist… TL-2026-2584 (DER) 2026-09-19 — ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via… TL-2026-2620 (DER) 2026-09-22 — ShinyHunters Claims FBI Breach via Unpatched Oracle… TL-2026-2633 (DER) 2026-09-23 — Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals… GTG-10007 TL-2026-0495 (C) 2026-05-11 — GTIG AI Threat Tracker (May 2026) — First AI-Developed… TL-2026-1354 (C) 2026-07-15 — China-Linked Threat Actor Integrates Claude Code and… TL-2026-1885 (C) 2026-08-05 — CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass… TL-2026-1997 (C) 2026-08-12 — China-Linked Actor Uses Autonomous AI Agent Frameworks… TL-2026-2325 (C) 2026-09-04 — Chinese-Speaking Operator Uses SecFlow AI Orchestration… TL-2026-2390 (C) 2026-09-08 — Autonomous AI-agent frameworks automating credential theft… TL-2026-2466 (DER) 2026-09-12 — Nation-State and Financially Motivated Actors Weaponize… TL-2026-2576 (DER) 2026-09-19 — LLM-Driven Reverse Engineering of Palo Alto Cortex XDR… TL-2026-2619 (DER) 2026-09-22 — Chinese-Speaking Actor (Red Heron-Linked) Chains WordPress… TL-2026-2633 (DER) 2026-09-23 — Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals… GTG-50029 GTG-50029 — activity window per Anthropic: 2026-02-06 to 2026-07-04 TL-2026-0817 (C) 2026-06-16 — ErrTraffic: ClickFix Malware-as-a-Service Distribution… TL-2026-1978 (C) 2026-08-10 — BdThemes WordPress Plugin Supply-Chain Attack Poisons API… TL-2026-2466 (DER) 2026-09-12 — Nation-State and Financially Motivated Actors Weaponize… TL-2026-2633 (DER) 2026-09-23 — Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals… TL-2026-2639 (DER) 2026-09-24 — Carbonato botnet: AI-agent-driven worm hijacks… GTG-50021 TL-2026-0012 (C) 2026-02-02 — LLMJacking: 175,000 Exposed Ollama AI Servers Targeted for… TL-2026-0403 (C) 2026-04-21 — Weaponizing Trust Signals: Claude Code Lures and GitHub… TL-2026-0514 (C) 2026-05-14 — NATS-as-C2: KeyHunter Distributed Worker Botnet Harvests… TL-2026-0546 (C) 2026-05-21 — SEO Poisoning Campaign Impersonates Gemini CLI and Claude… TL-2026-0582 (C) 2026-05-25 — Solo operator — Solo Russian-Speaking Actor Operating… TL-2026-1522 (C) 2026-07-19 — MetaChat Brand Impersonation Phishing Campaign Targets AI… TL-2026-1521 (C) 2026-07-19 — Mass Phishing/Fraud Campaign Impersonating Anthropic Claude… TL-2026-1845 (C) 2026-08-03 — Fake AI Developer Tool Installers Delivering Infostealer… TL-2026-1911 (C) 2026-08-06 — Token Jacking: Cybercriminals Steal and Resell AI API… TL-2026-2257 (C) 2026-08-31 — Commodity Infostealers Hijack Authenticated Claude Sessions… TL-2026-2416 (C) 2026-09-09 — Infostealer Logs Expose Replayable AI Session Tokens and… TL-2026-2466 (DER) 2026-09-12 — Nation-State and Financially Motivated Actors Weaponize… TL-2026-2548 (DER) 2026-09-17 — Fake ChatGPT Billing Email Phishing Campaign Abuses Google… TL-2026-2626 (DER) 2026-09-23 — Fake Claude Max Giveaway Phishing Campaign Uses… TL-2026-2639 (DER) 2026-09-24 — Carbonato botnet: AI-agent-driven worm hijacks… GTG-50020 GTG-50020 — activity window per Anthropic: 2026-05-21 to 2026-06-16 TL-2026-0828 (C) 2026-06-16 — BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling… TL-2026-1076 (C) 2026-07-02 — AI Compute Hijacking: Stolen Ollama Server Wired Into… TL-2026-2341 (C) 2026-09-05 — Frontier AI Agents Compress Full Enterprise Intrusion Chain… TL-2026-2550 (DER) 2026-09-17 — Revolut Phishing SMS Campaign Follows Social-Engineering… TL-2026-2633 (DER) 2026-09-23 — Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals… TL-2026-2639 (DER) 2026-09-24 — Carbonato botnet: AI-agent-driven worm hijacks… GTG-04001 TL-2026-2631 (DER) 2026-09-23 — Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot… TL-2026-2638 (DER) 2026-09-24 — UK establishes National Centre for Information Defence to… GTG-54002 TL-2026-0582 (C) 2026-05-25 — Solo operator — Solo Russian-Speaking Actor Operating… TL-2026-0760 (C) 2026-06-10 — Houthi/Yemen-Based Disinformation & Influence Campaign… TL-2026-1356 (C) 2026-07-15 — "Patriot Bait": Solo threat actor Runs 5-Year AI-Automated… TL-2026-2631 (DER) 2026-09-23 — Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot… TL-2026-2638 (DER) 2026-09-24 — UK establishes National Centre for Information Defence to… GTG-84005 TL-2026-0760 (C) 2026-06-10 — Houthi/Yemen-Based Disinformation & Influence Campaign… TL-2026-1356 (C) 2026-07-15 — "Patriot Bait": Solo threat actor Runs 5-Year AI-Automated… TL-2026-2631 (DER) 2026-09-23 — Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot… TL-2026-2638 (DER) 2026-09-24 — UK establishes National Centre for Information Defence to… GTG-24015 TL-2026-2631 (DER) 2026-09-23 — Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot… TL-2026-2638 (DER) 2026-09-24 — UK establishes National Centre for Information Defence to… GTG-34001 TL-2026-2543 (DER) 2026-09-16 — Iranian State Actors Deploy CHOSEN BRICK Windows Malware to… GTG-54006 GTG-54006 — activity window per Anthropic: 2024-07-01 to 2026-09-28 TL-2026-2631 (DER) 2026-09-23 — Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot… TL-2026-2638 (DER) 2026-09-24 — UK establishes National Centre for Information Defence to… GTG-84006 TL-2026-1356 (C) 2026-07-15 — "Patriot Bait": Solo threat actor Runs 5-Year AI-Automated… TL-2026-2526 (DER) 2026-09-15 — Iranian MOIS-Linked Actor Uses Telegram-Controlled… TL-2026-2534 (DER) 2026-09-16 — Chosen Brick: Iranian State-Backed Windows Surveillance… TL-2026-2543 (DER) 2026-09-16 — Iranian State Actors Deploy CHOSEN BRICK Windows Malware to… TL-2026-2638 (DER) 2026-09-24 — UK establishes National Centre for Information Defence to… GTG-54004 TL-2026-2638 (DER) 2026-09-24 — UK establishes National Centre for Information Defence to… GTG-84002 TL-2026-2631 (DER) 2026-09-23 — Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot… TL-2026-2638 (DER) 2026-09-24 — UK establishes National Centre for Information Defence to… GTG-54009 GTG-54009 — activity window per Anthropic: 2026-06-01 to 2026-06-28 TL-2026-2526 (DER) 2026-09-15 — Iranian MOIS-Linked Actor Uses Telegram-Controlled… TL-2026-2534 (DER) 2026-09-16 — Chosen Brick: Iranian State-Backed Windows Surveillance… TL-2026-2543 (DER) 2026-09-16 — Iranian State Actors Deploy CHOSEN BRICK Windows Malware to… GTG-14021 TL-2026-2520 (DER) 2026-09-15 — BambooToken Malware Uses MQTT Protocol for Cross-Platform… TL-2026-2519 (DER) 2026-09-15 — BambooToken: Cross-Platform Windows/Linux Malware Using… GTG-34007 TL-2026-1508 (C) 2026-07-19 — GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time'… TL-2026-2526 (DER) 2026-09-15 — Iranian MOIS-Linked Actor Uses Telegram-Controlled… TL-2026-2543 (DER) 2026-09-16 — Iranian State Actors Deploy CHOSEN BRICK Windows Malware to… TL-2026-2534 (DER) 2026-09-16 — Chosen Brick: Iranian State-Backed Windows Surveillance… GTG-50027 TL-2026-2609 (DER) 2026-09-21 — Iran Exploits SS7 Cellular Interconnect Infrastructure to… TL-2026-2649 (DER) 2026-09-25 — Nation-State Intrusions into Telecom Infrastructure via… GTG-30004 TL-2026-0076 (C) 2026-02-12 — The Gentlemen Ransomware: Emerging Multi-Region Enterprise… TL-2026-0495 (C) 2026-05-11 — GTIG AI Threat Tracker (May 2026) — First AI-Developed… TL-2026-1508 (C) 2026-07-19 — GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time'… GTG-30005 TL-2026-1417 (C) 2026-07-16 — Iran's AI-Enhanced Asymmetric Playbook: State Actors… TL-2026-1508 (C) 2026-07-19 — GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time'… TL-2026-2526 (DER) 2026-09-15 — Iranian MOIS-Linked Actor Uses Telegram-Controlled… TL-2026-2534 (DER) 2026-09-16 — Chosen Brick: Iranian State-Backed Windows Surveillance… TL-2026-2543 (DER) 2026-09-16 — Iranian State Actors Deploy CHOSEN BRICK Windows Malware to… TL-2026-2609 (DER) 2026-09-21 — Iran Exploits SS7 Cellular Interconnect Infrastructure to… GTG-30006 TL-2026-0159 (C) 2026-02-28 — CRESCENTHARVEST — Iranian IRGC-Aligned Cyberespionage… TL-2026-2526 (DER) 2026-09-15 — Iranian MOIS-Linked Actor Uses Telegram-Controlled… TL-2026-2543 (DER) 2026-09-16 — Iranian State Actors Deploy CHOSEN BRICK Windows Malware to… TL-2026-2534 (DER) 2026-09-16 — Chosen Brick: Iranian State-Backed Windows Surveillance… TL-2026-2628 (DER) 2026-09-23 — OAuth Token Theft via Sideloaded AppX Packages Abusing… GTG-15001 GTG-15001 — activity window per Anthropic: 2026-04-01 to 2026-04-28 TL-2026-0395 (C) 2026-04-20 — FakeWallet iOS Crypto Stealer Campaign Delivered Through 26… TL-2026-2591 (DER) 2026-09-20 — FomoPeek iOS App Store Poisoning: Kernel Exploit Framework… TL-2026-2655 (DER) 2026-09-25 — Deceptive Android Apps Exploit Google Play Early Access to… GTG-16005 TL-2026-0085 (C) 2026-02-15 — APT31 Weaponizes Google Gemini AI for Automated Cyberattack… TL-2026-2405 (B) 2026-09-08 — China-Based AI Companies Conducting Industrial-Scale… TL-2026-2413 (B) 2026-09-09 — China-Based AI Companies Conducting Industrial-Scale… GTG-16002 TL-2026-2405 (B) 2026-09-08 — China-Based AI Companies Conducting Industrial-Scale… TL-2026-2413 (B) 2026-09-09 — China-Based AI Companies Conducting Industrial-Scale… GTG-16001 TL-2026-2405 (B) 2026-09-08 — China-Based AI Companies Conducting Industrial-Scale… TL-2026-2413 (B) 2026-09-09 — China-Based AI Companies Conducting Industrial-Scale… GTG-16006 TL-2026-2405 (B) 2026-09-08 — China-Based AI Companies Conducting Industrial-Scale… TL-2026-2413 (B) 2026-09-09 — China-Based AI Companies Conducting Industrial-Scale… TL-2026-2615 (DER) 2026-09-22 — Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated… GTG-16008 TL-2026-2405 (C) 2026-09-08 — China-Based AI Companies Conducting Industrial-Scale… TL-2026-2413 (C) 2026-09-09 — China-Based AI Companies Conducting Industrial-Scale… GTG-16012 TL-2026-1911 (C) 2026-08-06 — Token Jacking: Cybercriminals Steal and Resell AI API… TL-2026-2405 (B) 2026-09-08 — China-Based AI Companies Conducting Industrial-Scale… TL-2026-2413 (B) 2026-09-09 — China-Based AI Companies Conducting Industrial-Scale…

Dots are record creation dates (day granularity); dots on the same day are stacked. The dashed line marks Anthropic's publication on 2026-09-10. Where a vendor published first, the lead belongs to that vendor.

Show the records as a table
CaseRecordTierCreated
GTG-20006TL-2026-0245A2026-03-18
GTG-20006TL-2026-0523C2026-05-17
GTG-20006TL-2026-0561C2026-05-22
GTG-20006TL-2026-0943C2026-06-25
GTG-20006TL-2026-1808A2026-07-31
GTG-20006TL-2026-1838A2026-08-03
GTG-20006TL-2026-1853A2026-08-04
GTG-20006TL-2026-1857A2026-08-04
GTG-20006TL-2026-2091A2026-08-21
GTG-20006TL-2026-2170C2026-08-26
GTG-20006TL-2026-2167A2026-08-27
GTG-20006TL-2026-2446DER2026-09-11
GTG-20006TL-2026-2466DER2026-09-12
GTG-20006TL-2026-2559DER2026-09-18
GTG-20006TL-2026-2614DER2026-09-22
GTG-50014TL-2026-0411C2026-04-22
GTG-50014TL-2026-0451C2026-05-04
GTG-50014TL-2026-0514C2026-05-14
GTG-50014TL-2026-0527C2026-05-18
GTG-50014TL-2026-1275C2026-07-13
GTG-50014TL-2026-1288C2026-07-14
GTG-50014TL-2026-1705C2026-07-26
GTG-50014TL-2026-1711C2026-07-26
GTG-50014TL-2026-2341C2026-09-05
GTG-50014TL-2026-2339C2026-09-05
GTG-50014TL-2026-2390C2026-09-08
GTG-50014TL-2026-2466DER2026-09-12
GTG-50014TL-2026-2531DER2026-09-16
GTG-50014TL-2026-2564DER2026-09-18
GTG-50014TL-2026-2584DER2026-09-19
GTG-50014TL-2026-2620DER2026-09-22
GTG-50014TL-2026-2633DER2026-09-23
GTG-10007TL-2026-0495C2026-05-11
GTG-10007TL-2026-1354C2026-07-15
GTG-10007TL-2026-1885C2026-08-05
GTG-10007TL-2026-1997C2026-08-12
GTG-10007TL-2026-2325C2026-09-04
GTG-10007TL-2026-2390C2026-09-08
GTG-10007TL-2026-2466DER2026-09-12
GTG-10007TL-2026-2576DER2026-09-19
GTG-10007TL-2026-2619DER2026-09-22
GTG-10007TL-2026-2633DER2026-09-23
GTG-50029TL-2026-0817C2026-06-16
GTG-50029TL-2026-1978C2026-08-10
GTG-50029TL-2026-2466DER2026-09-12
GTG-50029TL-2026-2633DER2026-09-23
GTG-50029TL-2026-2639DER2026-09-24
GTG-50021TL-2026-0012C2026-02-02
GTG-50021TL-2026-0403C2026-04-21
GTG-50021TL-2026-0514C2026-05-14
GTG-50021TL-2026-0546C2026-05-21
GTG-50021TL-2026-0582C2026-05-25
GTG-50021TL-2026-1522C2026-07-19
GTG-50021TL-2026-1521C2026-07-19
GTG-50021TL-2026-1845C2026-08-03
GTG-50021TL-2026-1911C2026-08-06
GTG-50021TL-2026-2257C2026-08-31
GTG-50021TL-2026-2416C2026-09-09
GTG-50021TL-2026-2466DER2026-09-12
GTG-50021TL-2026-2548DER2026-09-17
GTG-50021TL-2026-2626DER2026-09-23
GTG-50021TL-2026-2639DER2026-09-24
GTG-50020TL-2026-0828C2026-06-16
GTG-50020TL-2026-1076C2026-07-02
GTG-50020TL-2026-2341C2026-09-05
GTG-50020TL-2026-2550DER2026-09-17
GTG-50020TL-2026-2633DER2026-09-23
GTG-50020TL-2026-2639DER2026-09-24
GTG-04001TL-2026-2631DER2026-09-23
GTG-04001TL-2026-2638DER2026-09-24
GTG-54002TL-2026-0582C2026-05-25
GTG-54002TL-2026-0760C2026-06-10
GTG-54002TL-2026-1356C2026-07-15
GTG-54002TL-2026-2631DER2026-09-23
GTG-54002TL-2026-2638DER2026-09-24
GTG-84005TL-2026-0760C2026-06-10
GTG-84005TL-2026-1356C2026-07-15
GTG-84005TL-2026-2631DER2026-09-23
GTG-84005TL-2026-2638DER2026-09-24
GTG-24015TL-2026-2631DER2026-09-23
GTG-24015TL-2026-2638DER2026-09-24
GTG-34001TL-2026-2543DER2026-09-16
GTG-54006TL-2026-2631DER2026-09-23
GTG-54006TL-2026-2638DER2026-09-24
GTG-84006TL-2026-1356C2026-07-15
GTG-84006TL-2026-2526DER2026-09-15
GTG-84006TL-2026-2534DER2026-09-16
GTG-84006TL-2026-2543DER2026-09-16
GTG-84006TL-2026-2638DER2026-09-24
GTG-54004TL-2026-2638DER2026-09-24
GTG-84002TL-2026-2631DER2026-09-23
GTG-84002TL-2026-2638DER2026-09-24
GTG-54009TL-2026-2526DER2026-09-15
GTG-54009TL-2026-2534DER2026-09-16
GTG-54009TL-2026-2543DER2026-09-16
GTG-14021TL-2026-2520DER2026-09-15
GTG-14021TL-2026-2519DER2026-09-15
GTG-34007TL-2026-1508C2026-07-19
GTG-34007TL-2026-2526DER2026-09-15
GTG-34007TL-2026-2543DER2026-09-16
GTG-34007TL-2026-2534DER2026-09-16
GTG-50027TL-2026-2609DER2026-09-21
GTG-50027TL-2026-2649DER2026-09-25
GTG-30004TL-2026-0076C2026-02-12
GTG-30004TL-2026-0495C2026-05-11
GTG-30004TL-2026-1508C2026-07-19
GTG-30005TL-2026-1417C2026-07-16
GTG-30005TL-2026-1508C2026-07-19
GTG-30005TL-2026-2526DER2026-09-15
GTG-30005TL-2026-2534DER2026-09-16
GTG-30005TL-2026-2543DER2026-09-16
GTG-30005TL-2026-2609DER2026-09-21
GTG-30006TL-2026-0159C2026-02-28
GTG-30006TL-2026-2526DER2026-09-15
GTG-30006TL-2026-2543DER2026-09-16
GTG-30006TL-2026-2534DER2026-09-16
GTG-30006TL-2026-2628DER2026-09-23
GTG-15001TL-2026-0395C2026-04-20
GTG-15001TL-2026-2591DER2026-09-20
GTG-15001TL-2026-2655DER2026-09-25
GTG-16005TL-2026-0085C2026-02-15
GTG-16005TL-2026-2405B2026-09-08
GTG-16005TL-2026-2413B2026-09-09
GTG-16002TL-2026-2405B2026-09-08
GTG-16002TL-2026-2413B2026-09-09
GTG-16001TL-2026-2405B2026-09-08
GTG-16001TL-2026-2413B2026-09-09
GTG-16006TL-2026-2405B2026-09-08
GTG-16006TL-2026-2413B2026-09-09
GTG-16006TL-2026-2615DER2026-09-22
GTG-16008TL-2026-2405C2026-09-08
GTG-16008TL-2026-2413C2026-09-09
GTG-16012TL-2026-1911C2026-08-06
GTG-16012TL-2026-2405B2026-09-08
GTG-16012TL-2026-2413B2026-09-09

Hunt pack: sweep your telemetry for every published indicator

The hunt pack holds Anthropic's 209 CSV indicators plus 23 more from the pre-report records behind the overlap, tagged to Storm-2945 (Microsoft) or UNC7005 (Google), not GTG-20006. All come refanged in a CSV and a STIX 2.1 bundle; only the two scheduled-task names are CSV-only. Anthropic never defines "hunt", which marks attacker egress (for GTG-50029, commercial VPN and datacentre exits), one VPS and two exfiltration endpoints in hijacked GCP projects. We read it as search, not block, and the bundle types those rows as anomalous, not malicious. We add status, linked records and a stale marker (last seen over 60 days before publication).

The SPL and KQL network sweeps match domains, hostnames, onions and IPs in proxy, DNS and endpoint logs, skipping the context-only row; the host sweep covers hashes, filenames, the file path, scheduled tasks and, in mail logs, sender addresses. URLs, app and package IDs, account handles and Telegram IDs need manual checks. Widen the 120-day look-back for hunt-flagged addresses, last seen between March and mid-June.

SPLindex=proxy OR index=dns OR index=network earliest=-120d
| eval ioc=lower(coalesce(query, url_domain, dest_host, dest_ip, dest))
| lookup threadlinqs_anthropic_ai_misuse_2026_09.csv indicator AS ioc
    OUTPUT gtg role anthropic_handling threadlinqs_status
| where isnotnull(gtg) AND threadlinqs_status!="context-only" AND anthropic_handling!="context"
| stats count min(_time) AS first_seen max(_time) AS last_seen values(src) AS src
    BY ioc gtg role anthropic_handling
| convert ctime(first_seen) ctime(last_seen)
| sort - count
KQL · networklet iocs = externaldata(indicator:string, indicator_defanged:string, type:string, platform:string, gtg:string,
    case_name:string, role:string, anthropic_description:string, anthropic_handling:string, first_seen:string,
    last_seen:string, stale_before_report:string, threadlinqs_status:string, threadlinqs_threats_before:string,
    threadlinqs_threats_after:string, threadlinqs_related:string, role_judgement:string, source:string,
    anthropic_id:string, reference_url:string)
  [@"https://threadlinqs.com/blog/anthropic-claude-misuse-sep2026/iocs.csv"] with (format="csv", ignoreFirstRecord=true)
  | where threadlinqs_status != "context-only" and anthropic_handling != "context";
let hosts = toscalar(iocs | where type in ("domain", "hostname", "onion") | summarize make_set(indicator));
let ips = toscalar(iocs | where type in ("ipv4", "ipv6") | summarize make_set(indicator));
DeviceNetworkEvents
| where Timestamp > ago(120d)
| where RemoteIP in (ips) or RemoteUrl has_any (hosts)
| summarize hits = count(), first = min(Timestamp), last = max(Timestamp), devices = dcount(DeviceId)
    by RemoteIP, RemoteUrl
| order by hits desc
KQL · hostlet iocs = externaldata(indicator:string, indicator_defanged:string, type:string, platform:string, gtg:string,
    case_name:string, role:string, anthropic_description:string, anthropic_handling:string, first_seen:string,
    last_seen:string, stale_before_report:string, threadlinqs_status:string, threadlinqs_threats_before:string,
    threadlinqs_threats_after:string, threadlinqs_related:string, role_judgement:string, source:string,
    anthropic_id:string, reference_url:string)
  [@"https://threadlinqs.com/blog/anthropic-claude-misuse-sep2026/iocs.csv"] with (format="csv", ignoreFirstRecord=true)
  | where threadlinqs_status != "context-only" and anthropic_handling != "context";
let hashes = toscalar(iocs | where type == "sha256" | summarize make_set(indicator));
let files = toscalar(iocs | where type == "filename" | summarize make_set(indicator));
union DeviceFileEvents, DeviceProcessEvents
| where Timestamp > ago(120d)
| where SHA256 in (hashes) or FileName in~ (files)
    or FolderPath has @"\ProgramData\fontdrivehostServicePackages\"
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName;
DeviceEvents
| where Timestamp > ago(120d) and ActionType == "ScheduledTaskCreated"
| where AdditionalFields has_any ("SECOMS64_AdminTask", "Calc_AdminTask");
let senders = toscalar(iocs | where type == "email" | summarize make_set(indicator));
EmailEvents
| where Timestamp > ago(120d)
| where SenderFromAddress in~ (senders) or SenderMailFromAddress in~ (senders)
| project Timestamp, SenderFromAddress, RecipientEmailAddress, Subject, NetworkMessageId

How we cross-referenced the report

We froze the corpus first: every comparison ran against a September 25, 2026 export of the Threadlinqs D1 database (2,473 threats, 62,332 IoCs, 22,696 detections). From Anthropic we took the report PDF and its 209-row indicator CSV, and wrote a paraphrased inventory of each case. TL-2026-NNNN identifiers are Threadlinqs threat records, each with indicators, ATT&CK mapping and detections.

Indicator matching is deterministic string comparison. Each value was refanged, lower-cased and searched across IoC values and context notes, record text, timelines, update logs, detection bodies, DNS enrichment and C2 tables. Domains matched exactly, as subdomains or at registrable-domain level, but shared-hosting, dynamic-DNS and multi-part-suffix parents never count. IPv4 addresses also matched inside CIDR ranges in our records; a registrable-domain or in-range hit alone is a weak signal, and /24 neighbours count for nothing. Indicators printed only in the PDF, mostly media outlets and public accounts, were checked the same way; none matched actor infrastructure in our corpus. Nothing was resolved, fetched or visited.

Case-level links came from AI-assisted finders that pivoted on infrastructure, resolved actor, alias, malware and tool names, and searched tradecraft semantically and by ATT&CK/ATLAS, with a second round on leads a case judge flagged. Every claimed link needed a quote that is an exact substring of the snapshot record, or it was dropped.

Then we tried to break every claim. Role judges classified each overlapping indicator (actor-controlled, public resource, victim infrastructure, leaked code, researcher host or unclear), and only actor-controlled overlaps can make tier A. Three independent skeptics attacked each tier-A claim and each case's tier-B set on presence, timing, role and attribution; where a record and Anthropic name different clusters, we report both and merge neither. A separate judge kept, downgraded or dropped tier C and D candidates, and in doubt the weaker relation won.

A record created on or after September 10, 2026, or one citing Anthropic's report, is marked drv and never counts as prior coverage; nor does an indicator that entered an older record only through a post-publication update. Where we held something early, the lead time belongs to the vendor that published it first.

Cyber operations

In Anthropic's cyber chapter, Claude carries much of each campaign's hands-on work while people still choose targets and review the take (report section, PDF pp. 4–5).

Prior visibility splits the four cases below cleanly (the chapter's AI-supply-chain cases, GTG-50021 and GTG-50020, are in their own section). GTG-20006 is the only case in the report whose published indicators were already in Threadlinqs; the other three existed in our corpus only as technique-level analogues.

GTG-20006 — Agentic Russian espionage and the CaptiveCrunch (Storm-2945) overlap

Anthropic: GTG-20006 · PDF pp. 5–10 · 55 published IoCs · Threadlinqs: 11 prior records, 4 dated 09-10 or later

GTG-20006, the Russian espionage case in Anthropic's September 10, 2026 report, is where Threadlinqs already had signal: 17 of its 55 published indicators sat in 7 of our 11 prior records, the oldest from March 18, 2026, most through CaptiveCrunch and UNC7005 coverage. Anthropic cites public Midnight Blizzard reporting as matching its attribution (PDF p. 6); Claude Code agents automated most of the operation against 20-plus organisations. We add 24 sibling indicators.

What Anthropic reported

Sorted by where a defender would look (PDF pp. 6–9):

  • Identity and mail: Microsoft 365 device-code phishing, attacker devices enrolled in victim tenants, and bulk mailbox exports.
  • Travel and messaging: tampered DNS at hotel guest-WiFi vendors serving ClickFix lures (Microsoft's CaptiveCrunch, PDF p. 8), and WhatsApp accounts quietly paired to headless-browser companions.
  • Endpoints: confirm hosts still pull security updates, since companion payloads froze them; implants were rebuilt whenever a product flagged them, so hash and signature rules age fast.
  • Exposure: Ukrainian and European government, defence and diplomatic personnel, the US foreign-policy community and drone suppliers, reaching into the Middle East, Asia and North Africa (PDF pp. 6–7).

What Threadlinqs already had

Most of the overlap sits in one cluster. The 4 CaptiveCrunch records, TL-2026-1808 (July 31), TL-2026-1838 (August 3), TL-2026-1853 and TL-2026-1857 (August 4), each hold ms365-live[.]com, ms365-device[.]com, m365-owa[.]com, owa-ms365[.]com, the hosts 31.57.243[.]154, 38.146.28[.]75, 38.146.28[.]132 and 213.145.86[.]112, and the CornFlake and ChocoShell hashes. The lead is upstream: ReliaQuest disclosed the hotel-WiFi DNS poisoning, including 38.146.28[.]75, on July 23, 2026; Microsoft named it CaptiveCrunch on July 31, the day it reached Threadlinqs.

TL-2026-2091 (August 21, Google's UNC7005 reporting) overlaps most, adding chamber-ua[.]org, my-invite[.]org, statistic-ms[.]live, wa-connect[.]eu and wa-meeting[.]com; TL-2026-2167 repeats part of that set.

The earliest hit is DarkSword. TL-2026-0245 (March 18, from coordinated Lookout, GTIG and iVerify disclosures of March 17–18) holds cdncounter[.]net and static.cdncounter[.]net, GTIG's UNC6353 delivery hosts for the iOS chain (CVE-2026-20700, CVE-2025-43529, CVE-2025-31277). That leaked kit has several users, so the domain does not settle identity.

37 pre-publication rules already held indicators Anthropic later published; the 11 prior records carry 99 detections. Technique records:

What we add

Rules to run first:

  • TL-2026-1857-SPL-001 flags DNS resolution of the Microsoft 365 lookalikes until they rotate.
  • TL-2026-0943-KQL-003 flags a device-code token used against Microsoft Graph from an IP where the user never approved the code; domain rotation does not blind it.

Sibling infrastructure. The 24 extras come from the same Microsoft and Google cluster reporting: wider footprint, not confirmed GTG-20006 use.

  • C2 and hosting: 107.189.26[.]194 (ChocoShell C2 and rogue DNS resolver), 107.189.18[.]7 (Vidar C2), 104.194.159[.]150 (hosted ms365-live[.]com)
  • ChocoShell paths on 213.145.86[.]112: /t/pixel.gif, /cdn/chunks/polyfill-7e2b.min.js, /t/event
  • lures such as wa-invite[.]com, foc-share[.]com and globsec[.]net
  • hashes for ENGINELIGHT, a CHERRYPIE (ChocoShell) build, two phishing pages and the Vidar and Atomic stealers (commodity malware: leads, not attribution)

Retro-hunt window. IPs from February 2026 (TL-2026-1808 first sees 107.189.26[.]194 on February 27); domains from registration, May 14 for ms365-live[.]com and July 16 for owa-ms365[.]com (TL-2026-1853).

Context-only. Anthropic lists projectnightcrawler[.]dev as actor infrastructure, but TL-2026-0835 and TL-2026-1865 record it as the MiniPlasma researcher's public exploit mirror; a hit likely means a download, so the hunt pack sweeps skip it.

Weak indicators. The generic filenames printed only in the PDF were checked and matched no actor infrastructure in our corpus; never hunt on our extra sync.dat (CornFlake's config file) alone.

Gaps

  • Most other listed indicators match nothing, including the stuseamandesilt[.]org hosts, both mygreatmarket domains, chathamhouse[.]eu, ukrinform-share[.]net, itechx[.]tel and all three listed 104.194.x VPSs.
  • PowerChrome, WUEngine, Shadow C2, CloudSyncSvc, GiftDrop/GiftsExpress, Embassy Kit, the operator handle, the rebuild loop, the drone SDK theft, the North African registry breach, the camera tokens, 104.145.210[.]184, 144.172.114[.]192 and teams.ms365-live[.]com (parent domain held since July 31) appear only in our write-ups of Anthropic's disclosure, TL-2026-2446 and TL-2026-2466. CloudSyncSvc may echo CornFlake's "Cloud Sync Service" in TL-2026-1808; no record ties them.
  • Labels differ: Microsoft files CaptiveCrunch under Storm-2945, a Midnight Blizzard sub-cluster; Google's reporting in TL-2026-2091 puts the same domains and hosts under UNC7005, a moderate-confidence APT29 sub-cluster; TL-2026-2170 conflicts by naming UNC5976. Treat them as cluster names, not settled identities.
  • The April 2026 Microsoft device-code post Anthropic cites covered the EvilTokens crimeware platform, tracked in TL-2026-0943 (June; TL-2026-2614 is later independent coverage): technique background, not Midnight Blizzard reporting.
Related coverage in Threadlinqs (context, not the same activity) — 5

GTG-50014 — Suspected ShinyHunters affiliates mining secrets at scale

Anthropic: GTG-50014 · PDF pp. 11–23 · 40 published IoCs · Threadlinqs: 11 prior records, 6 dated 09-10 or later

GTG-50014 is Anthropic's label for suspected ShinyHunters affiliates who, per its September 10, 2026 report, mined 1.8 million Android apps for secrets, harvested GitHub tokens, used AI agents to dump over 2,100 Azure AD token sets, and extorted victims. None of its 40 indicators were in Threadlinqs before publication; 11 technique records from April 22, 2026 onward carry 99 detections.

What Anthropic reported

Anthropic groups several financially driven clusters into one operation, from secret theft to extortion or resale (PDF pp. 12–20).

  • Where secrets leak: one operator ran TruffleHog over 1.8 million decompiled Android APKs on ten EC2 workers, with verified hits streaming to Telegram; a GitHub organisation-email harvester added stolen access tokens.
  • How fast it moves: given loose goals, agents worked out each victim's APIs and token privileges on their own; one affiliate pulled 2,100-plus Azure AD token sets for 40-plus tenants from a breached SaaS provider in about 34 hours.
  • AI keys as loot: keys lifted from victims' vendors paid for the crew's compute; Anthropic says none came from its own systems.
  • Exits and income: six exfiltration routes, from bulk API pulls to a NAS on a mesh VPN (PDF p. 18); a carding shop branded after the French national police; pay-or-leak extortion; claimed HackerOne payouts from two extortion victims.

What Threadlinqs already had

The corpus holds operations of the same shape, reported about other operators.

  • TL-2026-0411 (April 22, The DFIR Report): the Bissa Scanner, an AI-assisted secret-validation pipeline alerting to Telegram.
  • TL-2026-0514 (May 14, Sysdig): KeyHunter, a worker fleet harvesting and live-validating cloud and AI keys, entering via Langflow CVE-2026-33017.
  • TL-2026-0527 (May 18): CoinbaseCartel stole Grafana source with one GitHub token, then extorted; our record's ShinyHunters and Lapsus$ affiliate label is a collective-level overlap only.
  • TL-2026-2339 (September 5, Datadog): GitHub organisation enumeration with stolen OAuth tokens and PATs.
  • TL-2026-2341 (September 5, Unit 42): agents mined git history for hardcoded tokens, reached root through the secrets manager, then hijacked the victim's cloud AI endpoints.

In TL-2026-1705, ShinyHunters' second Canvas intrusion used stored XSS for administrator access. Anthropic's anonymised XSS-to-privilege-escalation SaaS case looks similar but names no victim, so the two cannot be equated. Our records call the wider collective Scattered LAPSUS$ Hunters.

What we add

Rules to run first:

  • TL-2026-0514-KQL-002 flags one principal calling STS GetCallerIdentity and then Bedrock within five minutes, the test-then-use step behind stolen AI keys, without indicators.
  • TL-2026-2466-SIG-003, from our write-up of Anthropic's disclosure, is the only rule with GTG-50014 indicators and holds just some: the policenationale[.]cc and soraki domains, updatebeacon.duckdns[.]org and five of the 15 egress IPs (162.128.129[.]106, 195.178.110[.]131, 45.148.10[.]242, 185.65.134[.]246, 193.32.249[.]161). Add the other egress IPs, typosquat and crypto-lure domains, Telegram IDs and MEGA S4 paths from Anthropic's tables (PDF pp. 22–24).

Egress IPs: retro-hunt, do not block. Anthropic calls them only attacker egress (February 20 to May 6, 2026); our only context is /24 neighbours of three (45.148.10[.]242, 185.65.134[.]246, 185.65.134[.]199) in other operations' records, so any may now be shared or reassigned.

Public services. For oast[.]fun hunt only Anthropic's subdomain, and for MEGA S4 only its bucket paths. The file host printed only in the PDF was checked and matched no actor infrastructure in our corpus.

GitHub audit logs. Hunt organisation enumeration like TL-2026-2339 from tokens new to those organisations.

Gaps

  • Nothing before publication on the operator aliases, the carding shop, the APK pipeline, the Azure AD token dump or the bounty payouts.
  • Every GTG-50014 indicator we hold arrived with TL-2026-2466, our write-up of Anthropic's disclosure. That write-up also files one GTG-50029 fact, the roughly 140,000 political-platform records, under GTG-50014; it is flagged for correction.
Related coverage in Threadlinqs (context, not the same activity) — 5

GTG-10007 — A Chinese-speaking exploit foundry run by agent swarms

Anthropic: GTG-10007 · PDF pp. 24–28 · 0 published IoCs · Threadlinqs: 6 prior records, 4 dated 09-10 or later

GTG-10007 is a Chinese-speaking espionage cluster that, per Anthropic's September 10, 2026 report, used Claude to run agent swarms with persistent memory, an unattended firmware-reversing loop credited with over a dozen candidate zero-days in a month, and a 13-agent collection fleet. Anthropic published no indicators. Before publication Threadlinqs held 6 technique analogues, the earliest from May 11, 2026, carrying 54 detections.

What Anthropic reported

What Anthropic's account (PDF pp. 24–28) means for defenders:

  • Appliances are the target class. Autonomous research, including a firmware-reversing loop (PDF p. 26), yielded working exploits for several network and security appliance families, plus flaws, validated only in the actor's own lab, in a major endpoint-security product.
  • Scale without fatigue. Parallel agent teams shared campaign memory across sessions, and thirteen scheduled collectors turned public US military and government material into digests.
  • Victims: about 50 organisations targeted, with breaches at an edtech firm (student data), a retailer (production systems) and a Southeast Asian agency (citizen records). Anthropic says hands-on intrusions stayed with domestic Chinese victims (PDF p. 28).

What Threadlinqs already had

The corpus holds analogues only; no source ties any of them to this cluster.

  • TL-2026-2325 (September 4, Hunt.io), the closest: a Chinese-speaking operator's SecFlow framework drives Claude, Qwen and DeepSeek from recon to post-exploitation; victims include a foreign ministry.
  • TL-2026-0495 (May 11, GTIG): UNC2814's AI-assisted research into TP-Link firmware bugs and APT27's AI-built relay-network tooling.
  • TL-2026-1354 (July 15): Claude Code plus DeepSeek behind SQL injection into Thai government databases and Laravel RCE (CVE-2021-43503).
  • TL-2026-1997 (August 12): parallel sub-agents against Taiwanese government targets.
  • TL-2026-1885 (August 5, Unit 42): a Hermes-plus-DeepSeek framework with an asset-search skill; when its autonomous runs failed, the operator hit Tomcat (CVE-2026-34486) and Citrix NetScaler by hand.
  • TL-2026-2390 (September 8, GTIG): PRC-nexus groups routing Claude, Gemini and Codex to write exploits.

What we add

Rule to run first:

  • TL-2026-2390-KQL-001 flags scanner tooling (nmap, nuclei, sqlmap) and LLM API calls from one host within 15 minutes: agent-driven recon from hosts you own, caught without indicators. Use the KQL body; the Splunk body fires on either condition alone.

Harden the target class: patch network and security gear fast and keep management interfaces off the internet.

Gaps

  • Anthropic named no indicators, appliance families, security product or victims to match.
  • TL-2026-2466, our write-up of Anthropic's disclosure, dates this cluster to the December 2025 to August 2026 window Anthropic gives the whole cyber section (PDF p. 4); treat it as an outer bound.
Related coverage in Threadlinqs (context, not the same activity) — 5

GTG-50029 — A lone French-speaking hacktivist's WordPress breach-and-dox campaign

Anthropic: GTG-50029 · PDF pp. 34–37 · 22 published IoCs · Threadlinqs: 2 prior records, 3 dated 09-10 or later

GTG-50029 is a lone French-speaking hacktivist who, per Anthropic's September 10, 2026 report, used a Claude sub-agent framework, stolen API keys and a new WordPress reinstall race to breach at least 14 of 42 European political, media and think-tank targets, then fed the loot into a doxxing engine. None of its 22 indicators were in Threadlinqs; 2 WordPress-persistence records from June 16, 2026 onward carry 18 detections.

What Anthropic reported

Anthropic's account (PDF pp. 34–37), read for WordPress and SaaS defenders:

  • Entry: a WordPress reinstall race new to the public record gave credential-free admin accounts on at least four sites; stolen API keys from public container images, cycled through a proxy, passed as the owners' traffic.
  • Persistence to check: a webshell among font files, a credential-stealing must-use plugin and backups poisoned to reinfect on restore; a BeEF hook on one news site sought editorial staff sessions.
  • Stakes: about 140,000 political-opinion records from one campaign platform, 12 to 26 GB of dumps overall, a Tor leak site and a doxxing search engine.

Anthropic calls it one of the clearest cases we have seen of AI-assisted software engineering applied directly to a mass attack on privacy (Anthropic, PDF p. 36).

What Threadlinqs already had

What we had is the persistence pattern; none of the published indicators match, even at /24.

  • TL-2026-0817 (June 16): ErrTraffic, a ClickFix malware-as-a-service framework, with a must-use plugin backdoor, a login-page credential harvester and a hidden administrator (CVE-2020-25213).
  • TL-2026-1978 (August 10): the BdThemes plugin supply-chain attack, with rogue administrators, a webshell and hidden must-use plugins.

Context, none about this actor: mu-plugin write detections (TL-2026-2057), AI-key harvesting and resale (TL-2026-0514, TL-2026-1911), and a solo operator who rotated stolen AI keys and hijacked WordPress admins (TL-2026-0582).

What we add

Rules to run first:

  • TL-2026-0817-SPL-002 fires on new or changed files under wp-content/mu-plugins or a theme's functions.php (the KQL and Sigma versions also require a PHP or web-server writer); no infrastructure needed.
  • TL-2026-1978-SPL-002 matches known BdThemes backdoor hashes and paths plus rogue-admin creation; use it for the pattern, since those files are not this actor's.

Hardening and hunting:

  • Inventory mu-plugins on every WordPress host; the admin plugin list hides them.
  • Verify backups before restoring; this actor poisoned them.
  • Restrict installer and setup endpoints on live sites, and alert on every new administrator.
  • Retro-hunt the VPN exits only within Anthropic's March 25 to May 20, 2026 window; block the two GCP exfiltration IPs, hijacked projects in shared cloud, only briefly.

Gaps

  • The race condition, BeEF hook, doxxing platform and onion services appear nowhere in the corpus.
  • Among later records, only TL-2026-2466, our write-up of Anthropic's disclosure, touches this case, misfiling its political-platform records under GTG-50014. TL-2026-2633 and TL-2026-2639 are later independent coverage, thematic only.
Related coverage in Threadlinqs (context, not the same activity) — 5

Anthropic's trend pages (PDF pp. 38–39) put GTG-20006 at both ends of their autonomy range: a human approved each target, yet its token refreshes and cloud-storage pulls ran as unattended jobs. Agent teams ran for hours to days in GTG-50014 and GTG-50029, and GTG-10007's collectors on a timer. Autonomy drives scale, not severity. For defenders, the CaptiveCrunch and UNC7005 infrastructure behind all but two of our advance matches will rotate; the device-code, key-validation and mu-plugin rules outlast it.

The AI supply chain as a target

Anthropic's supply-chain section treats AI access as something criminals attack, sell and run on: a stolen key can be resold, pays for attack compute and pins the activity on its owner (report section, PDF pp. 28–30). Its trends chapter sees a marketplace growing around that access (trends chapter, PDF p. 38).

The ground was already well covered: between February and our September 25, 2026 snapshot, 188 Threadlinqs records had AI systems as their main target theme (LLMjacking, exposed model servers, AI-gateway flaws, prompt injection), nearly all before the report. None of the indicators Anthropic published for either group appeared in them; the community had mapped the economy, not these operators.

GTG-50021 — Fake Claude resellers and the stolen-key economy

Anthropic: GTG-50021 · PDF pp. 28–29 · 6 published IoCs · Threadlinqs: 11 prior records, 4 dated 09-10 or later

GTG-50021, a Russian- and Ukrainian-speaking crew, ran what Anthropic's September 10, 2026 report describes as a bogus discount Claude reseller that served another model and stole buyers' Anthropic logins for onward sale. None of its 6 CSV indicators were in Threadlinqs before or after publication, but 11 ecosystem records dating from February 2, 2026 carry 122 detections.

What Anthropic reported

Anthropic (report section, PDF pp. 28–30) treats stolen AI keys and sessions as a traded good that intruders buy as free compute (T1496.004) and fake resellers drain. For defenders:

  • Cheap access is the lure. GTG-50021's discount Claude was neither cheap nor actually Claude (Anthropic, PDF p. 29); installing its client surrendered the buyer's Anthropic logins.
  • Rotating keys on an infected host fails. An unnamed fake multi-model gateway shipped clients, some styled as Claude Code, whose stealer caught sessions opened after a reset.
  • Gateways leak what they hold. Prompt injection (AML.T0051) let several actors pull keys from the LiteLLM layer of AI wrapper products.
  • GTG-50021 infrastructure (Anthropic's CSV labels): storefronts awstore[.]cloud (Claude) and kiro[.]cheap (Kiro), AWS lookalike aws-us-east-3[.]com, malware C2 and platform domains sys-tools[.]cfd and holdboost[.]store, Supabase backend iymkjuzymkapovrntoxy.supabase[.]co.

What Threadlinqs already had

The closest prior record, TL-2026-1911 (Unit 42 token-jacking research, in Threadlinqs since August 6), maps the supply side of the same economy: transfer stations on open-source gateways (new-api, one-api) reselling stolen, leaked or pooled credentials at a discount through merchants and relays. It shares no actor or infrastructure with GTG-50021.

Other strands already in the corpus (dates show entry into Threadlinqs):

  • TL-2026-0012 (Feb 2): LLMjacking reseller proxies selling subscriptions on pooled stolen keys.
  • TL-2026-0403 (Apr 21), TL-2026-0546 (May 21, EclecticIQ) and TL-2026-1845 (Aug 3): fake Claude Code and Gemini CLI installers, spread through fake-leak GitHub repos and SEO poisoning, that steal tokens, cookies and developer secrets.
  • TL-2026-1521 (Jul 19): Claude and Mythos brand abuse, including account-resale storefronts, with registrations on the same cheap TLDs (.cfd, .xyz).
  • TL-2026-1522 (Jul 19): lookalikes of a multi-model aggregator harvesting AI API keys, the nearest analogue to the unnamed gateway impersonator.
  • TL-2026-2257 (Aug 31) and TL-2026-2416 (Sep 9, Okta): replayable Claude and other AI session tokens in stealer logs (T1539), abuse Anthropic's August notice caught through usage refill-and-drain cycles, plus Telegram sellers of discounted Claude access.

The corpus's only independent measurement of silent model swapping is CISPA's, in the distillation advisory TL-2026-2413: close to half of the grey-market proxies it tested substituted a cheaper model. Our LiteLLM records cover flaws and their exploitation, such as the KEV-listed pre-auth SQL injection exposing stored keys (TL-2026-0487), plus a PyPI supply-chain compromise; none shows prompt injection pulling keys from a LiteLLM deployment. Injection that steals secrets does appear, aimed at coding agents: malicious-package campaigns that planted instructions for Claude Code or Cursor to exfiltrate developer secrets (TL-2026-0576, TL-2026-0147), and research such as a Claude Code GitHub Action leak via /proc/self/environ (TL-2026-0660) and cross-agent injection in Google ADK (TL-2026-1897).

What we add

  • TL-2026-0403-KQL-001 flags ClaudeCode_x64.exe and sibling TradeAI.exe running from user, Temp, Downloads or AppData folders. It targets a documented fake Claude Code dropper, not GTG-50021's tooling, but the same delivery vector.
  • TL-2026-0012-SPL-002 groups Bedrock control-plane calls per AWS access key in CloudTrail; two or more action types from one key is the LLMjacking recon pattern Sysdig documented, though a legitimate first-time Bedrock setup can look the same.

Sibling grey-market outlets, none sharing infrastructure with GTG-50021: the account shops claudekyc[.]shop and claudecode-buy[.]com (TL-2026-1521) and the access proxy poison-claude.bitsender[.]top (TL-2026-2416). A proxy-log hit means someone inside is shopping for grey-market model access, the buyers this case preyed on.

What to change:

  • Allow-list official installers and paths for AI coding tools; alert on same-named binaries anywhere else.
  • Baseline AI usage per key and per seat; alert on spikes and on refill-and-drain cycles, the signal behind Anthropic's August notice.
  • After a stealer infection, reimage first and rotate second; as the gateway impersonator's harvester showed, rotating keys on a dirty host just restocks the broker.

Gaps

  • None of Anthropic's 6 CSV indicators for GTG-50021 appear in the corpus, before or after the report, nor does the alias Anthropic gives one member; the indicator printed only in the PDF was checked too and matched no actor infrastructure we hold.
  • No record covers the unnamed operator who posed as a multi-model gateway to push fake clients, or LiteLLM key theft through prompt injection.
Related coverage in Threadlinqs (context, not the same activity) — 5

GTG-50020 — A Russian-speaking crew moves from hotel-booking breaches to AI vendor keys

Anthropic: GTG-50020 · PDF pp. 30–33 · 8 published IoCs · Threadlinqs: 3 prior records, 3 dated 09-10 or later

GTG-50020 is a Russian-speaking extortion crew that, per Anthropic's September 10, 2026 report, prompt-injected an AI vendor's automated evaluation sandbox to take the vendor's production keys, then attacked about 30 AI firms in four days; its bid for pre-release Claude access failed. None of its 8 egress IPs appeared as a Threadlinqs indicator before or after publication (one sits inside a bulletproof-hosting /22 we track); 3 technique records dating from June 16, 2026 carry 27 detections.

What Anthropic reported

Anthropic's conclusion that the AI supply chain has become a deliberate criminal target (Anthropic, PDF p. 31) rests on a former hotel-booking and fintech extortion crew (GTG-50020, PDF pp. 30–33). For defenders:

  • Evaluation sandboxes are credential stores. Prompt injection (AML.T0051) against one vendor's automated evaluation sandbox yielded production keys for several model providers; untrusted prompts and stored secrets should not share a box.
  • Stolen keys fuel the next wave. The crew ran its tooling on the vendor's keys, then hit about 30 AI firms in roughly four days with one proven approach.
  • The rest is fraud tooling: a KYC-relay phishing proxy, a verified-account factory, agent-driven web exploitation. It never reached the pre-release Claude model it sought, and every key traced to a customer, not Anthropic.

What Threadlinqs already had

The closest tradecraft is TL-2026-2341, Unit 42 research in Threadlinqs since September 5, before the report: a human operator steered parallel frontier-model agents in a custom framework that harvested credentials, moved through the secrets manager and CI/CD, then called the victim's own cloud AI endpoints (T1496.004) ahead of an extortion attempt. The actor is unnamed and shares no infrastructure with GTG-50020.

Earlier technique records (dates show entry into Threadlinqs):

  • TL-2026-1076 (Sysdig, Jul 2): a stolen Ollama server powering an autonomous pipeline that fingerprints targets, writes exploits and pulls secrets.
  • TL-2026-0828 (Jun 16): the BlueKit phishing kit, combining AiTM reverse proxying, CapSolver CAPTCHA solving and Octo anti-detect session replay, the building blocks of GTG-50020's KYC relay and account factory. Anthropic names none of GTG-50020's services and BlueKit has many buyers, so this is a shared technique, not shared tooling or actor.

Egress IP 178.16.54[.]141 sits in 178.16.52[.]0/22, OMEGATECH (AS202412) space that Intrinsec's reporting in TL-2026-0617 (May 28) and Spamhaus tie to a bulletproof-hosting provider; it is the only one of Anthropic's 209 CSV indicators that we match at hosting-range level alone. Its /24 also holds a TonRAT C2 from a Microsoft-tracked hotel-sector phishing campaign (TL-2026-0946) and a Konni RemcosRAT C2 (TL-2026-1529). Hotel targeting aside, that tenant mix marks a rented block; the match identifies a hoster, not an operator.

What we add

Anthropic flags the 8 egress IPs for hunting, not blocking, and no rule names them; the OMEGATECH prefix rules on TL-2026-0617 match 178.16.54[.]0/24 only as a destination for outbound script-interpreter traffic. Retro-hunt WAF, API gateway, identity and model-provider logs for May 21 to June 16, 2026; a later hit on these rented addresses is a lead, not proof. The technique rules do the rest:

  • TL-2026-1076-KQL-001 matches the VAPT pipeline's markers (VAPTb3gin, VAPTfin, __VAPTCMD__) in process command lines, with near-zero false positives. It hunts another operator's framework, but a hit means an agent pipeline is confirming code execution on your host.
  • TL-2026-1076-SPL-003 flags more than 60 requests in five minutes from one source to self-hosted model endpoints (/api/generate, /api/chat, /v1/completions). It catches a pipeline borrowing a model server you run, whatever the source IP, but not stolen keys used at a hosted API; batch inference can trip it.

AI vendors: keep provider keys out of anything an evaluated model or agent can read, use separate low-limit evaluation keys that alert when used outside the sandbox, and restrict sandbox egress. KYC providers: flag a verified session replayed from a different device or IP than the one that passed the check, especially from hosting ranges.

Gaps

  • No record names GTG-50020 or covers the sandbox injection, the four-day sweep of AI firms, the pre-release Claude attempts or the hotel and fintech extortion.
  • Seven of the eight egress IPs have no match, not even at /24; the eighth has only the hosting-level neighbours described above.
  • No record joins the KYC relay and the account factory into one operation; we hold only commercial parts.
Related coverage in Threadlinqs (context, not the same activity) — 5

Together, the two cases show stolen keys flowing both ways: keys lifted from developers stock cheap resale, and keys lifted from an AI vendor funded further intrusion attempts against that vendor and others. Detection starts with how a key is used, not where the traffic comes from.

Influence operations

Nine influence operations sit under this heading, aimed at audiences on six continents and scored for reach on the Breakout Scale (report section, PDF pp. 41–43). Claude scrubbed state sourcing from recycled copy, sub-edited for existing newsrooms, and ran back-office work: manuals, target lists, doctrine held in memory files.

We hold analogues, not the operations: Trend Micro's solo 'Patriot Bait' operator, whose jailbroken LLM rewrote news for Telegram (TL-2026-0582, TL-2026-1356), ClearSky's Houthi fake-outlet network (TL-2026-0760) and Recorded Future on Iranian state AI propaganda (TL-2026-1417). Later independent coverage: Pravda-network LLM grooming (TL-2026-2631) and a new UK information-defence centre (TL-2026-2638).

GTG-54002 — Fake local-news network Anthropic traces to LKM Company

Anthropic: GTG-54002 · PDF pp. 47–52 · 28 published IoCs · Threadlinqs: 3 prior records, 2 dated 09-10 or later

GTG-54002 is an influence-for-hire network that Anthropic's September 10, 2026 report traces to the France-based digital ad agency LKM Company: Claude wrote slanted copy for about 70 fake local-news sites, heavy on DRC-Rwanda. None of its 28 indicators were in Threadlinqs; 3 technique records from May 25, 2026 onward carry 27 detections.

What Anthropic reported

Claude wrote originals and re-slanted real reporting per country in a fixed format, so posting ran unattended, mainly for the DRC, France, Brazil and the US.

  • At least 8,913 articles in roughly 20 languages.
  • One X account per outlet, boosted by 250-plus commenter accounts, many with AI-generated faces.
  • All domains registered from France within about ten weeks in mid-2025, behind one shared deployment.
  • Coordination tell: near-duplicate DRC-Rwanda pieces across the network within three minutes on 2025-09-11.

Rated Breakout Category Two, the network backed opposing sides based on whoever was paying at the time (Anthropic, PDF p. 47).

What Threadlinqs already had

Analogues only, all created before the report:

  • TL-2026-0760: ClearSky's Houthi-aligned network of several dozen fake outlets, fed recycled copy and pushed by fake personas (public since 2019; in Threadlinqs since June 10, 2026). Hunting pivots: overlapping WHOIS, passive DNS on a small hosting cluster, shared nameservers, brand-hyphen-'news' or 'press' names.
  • TL-2026-0582, TL-2026-1356: Trend Micro's 'Patriot Bait' case, a solo operator's scripts feeding mainstream news to a jailbroken Gemini for slanted rewrites (public May 22, 2026; in Threadlinqs since May 25). Different actor, model and channel.

What we add

Anthropic printed 14 of the roughly 70 outlets and their X accounts (PDF pp. 52–53); all are in the indicator table, none in our corpus. The durable signals are behavioural:

  • many news-branded domains registered from one country within ten weeks;
  • one hosting deployment behind supposedly independent outlets;
  • templated articles (a fixed three or four internal links each);
  • one story across sites within minutes, then a link push from matched accounts.

Of the 27 analogue detections, the passive-DNS hosting-cluster rule (TL-2026-0760-SPL-003) and persona posting-burst rule (TL-2026-0760-SPL-002) carry over once their Houthi name pattern and hard-coded hosts are swapped for this network's domains.

Gaps

  • No record of LKM Company, its outlets or X accounts, and no DRC-Rwanda or Congo influence reporting at all.
  • The full domain list and shared deployment identifier are not in the public PDF or CSV, so the best infrastructure pivot is out of reach.
Related coverage in Threadlinqs (context, not the same activity) — 1

GTG-84005 — Malaysia election-manipulation platform Anthropic ties to BBS Bilisim

Anthropic: GTG-84005 · PDF pp. 53–57 · 21 published IoCs · Threadlinqs: 2 prior records, 2 dated 09-10 or later

GTG-84005 is a for-hire election-manipulation platform aimed at Malaysia, tied in Anthropic's September 10, 2026 report to Istanbul's BBS Bilisim Teknolojileri. Claude and Claude Code built its farm of about 1,000 X accounts and 222-constituency voter profiling, and rewrote copy for the laundering outlet Malaysia Pulse. None of its 21 indicators were in Threadlinqs; 2 technique records from June 10, 2026 onward carry 18 detections.

What Anthropic reported

Read it as a product (PDF pp. 53–55):

  • Sold as defence: badged as counter-disinformation software and offered, with no sign of a deal, to Malaysia's communications regulator; the vendor's own pitch promised a military-grade, AI-driven, real-time political operations ecosystem (Anthropic, PDF p. 54).
  • Laundering is the tell: Malaysia Pulse (registered 2026-05-10) ran rewritten local stories and Chinese and Russian state copy, credits removed, as Malaysian news; separately, operators forged smear dossiers.
  • Open questions: reach figures come only from the actor's dashboards, and the report does not say who else bought access. Breakout Category Two.

What Threadlinqs already had

Two technique analogues predate the report:

  • TL-2026-0760: ClearSky's Houthi-aligned outlets lightly edited Arabic RT and Sputnik copy while sockpuppets pushed the links. That network also used Hetzner, but not the six GTG-84005 addresses.
  • TL-2026-1356: Trend Micro's 'Patriot Bait' scripts rewrote mainstream news through a Gemini instance jailbroken under an 'authorized penetration tester' pretext.

What we add

Block or hunt, all in the indicator table (PDF pp. 57–58): malaysiapulse[.]com, bbsteknoloji[.]com, the Malaysia Pulse YouTube channel, 12 sample sockpuppet X accounts created on one day (May 17, 2026) and six Hetzner IPs behind the XPanel panel, NEOS, a renderer and Voxta. Hetzner addresses get reassigned, so time-bound any IP block.

The stronger cue is content: uncredited CGTN, Sputnik/RIA, Xinhua or TV BRICS copy posing as local news, caught by a cheap diff against those feeds. Of the 18 analogue detections, adapt the RT/Sputnik content-mirroring rule (TL-2026-0760-KQL-002) and the hosting-cluster rule (TL-2026-0760-SPL-003).

Gaps

  • No record of BBS Bilisim, Malaysia Pulse, Southeast Asian influence activity or any Turkish influence-for-hire vendor.
  • Nothing on account-farm warm-up, cookie and IP rotation or constituency-level targeting.
Related coverage in Threadlinqs (context, not the same activity) — 1

GTG-84006 — Activist-impersonating agent platform Anthropic links to MEK/NCRI

Anthropic: GTG-84006 · PDF pp. 70–74 · 10 published IoCs · Threadlinqs: 1 prior record, 4 dated 09-10 or later

GTG-84006 is an influence operation that Anthropic's September 10, 2026 report links to the MEK (PMOI) and NCRI, run on 'Viktor', a shared Claude agent platform with memory files. One agent cloned a real activist's Telegram voice and chatted live as him. None of its 10 indicators were in Threadlinqs; we held 1 earlier technique record, with 9 detections.

What Anthropic reported

What matters for the targeted communities (PDF pp. 70–73):

  • A clone is hard to spot: built from roughly 8,400 of the activist's posts, it apparently fooled his contacts; the impersonation accounts also fired one invented news alert at 30-plus contacts at once.
  • The profiling data endangers people: scrapes of 500-plus channels sorted people inside Iran by traits including arrest history.
  • Doctrine sat in memory files: standing instructions per Viktor workspace, evasion rules included, kept agents publishing unprompted, with one playbook across separate operators.

Output spread via synchronised Instagram pages and undisclosed Persian-speaking AI avatars. Breakout Category Two.

What Threadlinqs already had

  • TL-2026-1356 (July 15, 2026): Trend Micro's 'Patriot Bait' case, where an auto-loaded GEMINI.md memory file kept a jailbroken Gemini on task for a Telegram influence operation. Trend Micro published it on May 22, over three months before Anthropic's report; the same research reached us on May 25 as TL-2026-0582, counted as related context rather than a second technique record.

Later independent coverage from the regime side, not about this operation: the FBI/NCSC/AIVD advisory on CHOSEN BRICK spyware aimed at dissidents (TL-2026-2526, TL-2026-2534).

What we add

Activist and diaspora communities should assume an agent can drive a trusted account:

  • verify out of band when a contact's style, tempo or urgency shifts;
  • treat identical 'breaking news' from one contact to several people at once as a clone signal;
  • review Telegram sessions and linked devices often.

All 10 indicators are Instagram and Telegram accounts, better suited to platform reports than blocklists, though Anthropic marks them detect-or-block. Warn communities about the three it calls sockpuppet or surveillance funnels: instagram[.]com/fwr[.]ir, t[.]me/FWR_ir, t[.]me/anti_silent. PDF-only entries were checked; none matched actor infrastructure in our corpus.

TL-2026-1356-SIG-003 (one of 9 detections on TL-2026-1356) flags bypass wording in GEMINI.md, CLAUDE.md or AGENT_MEMORY.md on agent hosts; for this network, add SKILL.md, LEARNINGS.md (PDF p. 75) and evasion-rule wording.

Gaps

  • No MEK/NCRI actor entry and nothing on Viktor or any shared influence-agent platform; none of the Telegram or Instagram accounts are in the corpus.
Related coverage in Threadlinqs (context, not the same activity) — 4

These six have only thematic context in our corpus, nothing a hunter could act on.

CaseWhat Anthropic reportedClosest Threadlinqs coverageGap
GTG-04001 A Russian-speaking Bangui operator, assessed by Anthropic as local media coordinator for Politology (itself assessed as SVR-run since late 2023), had Claude write news for a Wagner-founded station and forge gendarmerie and defence papers. Breakout Category Four (PDF p. 44). TL-2026-0495, TL-2026-1356, TL-2026-1417 No Central African Republic, Wagner or Politology coverage anywhere; our 3 context records are general AI-misuse reporting, and our SVR records (APT29) are unrelated cyber-espionage.
GTG-24015 Four accounts used Claude to sub-edit copy for RT English and Sputnik's Moldovan (with RIA Novosti), Spanish-language and African outlets, including smears of Moldova's president before its September 2025 election (PDF p. 58). TL-2026-0495, TL-2026-0760, TL-2026-1356 No record of Russian state outlets using LLMs; the report's indicators were checked, and none matches actor infrastructure in our corpus. TL-2026-2173, an APT28 lure built on a Spanish-Moldovan diplomatic meeting, is context only.
GTG-34001 Actors inside or working for three Iranian state propaganda bodies had Claude draft target lists, persona kits and manuals, and pin invented claims on Western think tanks. Breakout Category Three (PDF p. 62). TL-2026-0159, TL-2026-1309, TL-2026-1417 None of these institutions or their Eitaa, Bale and Rubika channels appear. Closest context: Recorded Future on Iranian wartime AI propaganda (TL-2026-1417).
GTG-54006 One Gaibandha-based operator, spread across 29 Claude accounts, scripted fake Bengali headlines and stories in fixed batches to feed pro-Awami League livestreams. Breakout Category Three (PDF p. 67). TL-2026-0495, TL-2026-0582, TL-2026-1356 No Bangladesh or Bengali-language influence reporting; the closest analogue is the stolen API-key rotation in TL-2026-0582.
GTG-54004 A Kenyan operator had Claude turn talking points into 50-post batches of organic-looking chatter before the 2027 election, reusing the template for retail brands. Found via an OpenAI tip; Breakout Category One (PDF p. 75). TL-2026-0582, TL-2026-1356, TL-2026-1417 No Kenyan or East African influence coverage. Analogue only: a solo operator's LLM posting pipeline in TL-2026-1356.
GTG-84002 Anthropic ties a 'Deadshot' persona operation to UAE officials with high confidence: about 300 fake accounts, a cloned NGO identity, ghost-written UN testimony and dossiers on MEPs. Breakout Category Three (PDF p. 78). TL-2026-0760, TL-2026-1356, TL-2026-1417 No UAE-directed influence reporting. The closest is the mirror image: Houthi influence aimed at Saudi Arabia and the UAE (TL-2026-0760).

Route these cues to registrars, hosting providers, platform trust-and-safety teams and targeted communities, not a SOC blocklist.

Surveillance operations

Anthropic's surveillance block covers operations by Chinese, Iranian and West African operators and one commercial vendor, disrupted from January to July 2026 (surv-intro, PDF pp. 81–82). Its three lessons: a lone engineer with a model now replaces a development team, models are fed bulk-collected data to choose targets, and state security bureaucracies are wiring AI into routine work.

Our corpus splits along national lines. The Iranian cases have technique-level analogues, led by CRESCENTHARVEST (TL-2026-0159) and APT42's phone-number data agent (TL-2026-1508). The PRC cases have almost none: PlugX and ShadowPad appear, but we hold no dedicated records of the long-running campaigns against Tibetan, Uyghur and Falun Gong communities, an ingestion gap rather than a search miss.

GTG-34007 — Iranian security units building surveillance tooling

Anthropic: GTG-34007 · PDF pp. 101–103 · 0 published IoCs · Threadlinqs: 1 prior record, 3 dated 09-10 or later

GTG-34007, in Anthropic's September 10, 2026 report, is two linked Iranian units that Anthropic, with high confidence, associates with paramilitary domestic-security bodies. On 16 now-banned accounts they extended a case system called Arman, picked 39 opposition accounts from 155,216 tweets and shipped a prayer-times Firefox extension harvesting social-media identities. Before publication Threadlinqs held 1 technique record (July 19, 2026) with 9 detections.

What Anthropic reported

Sorted by what reaches victims (PDF pp. 101–103):

  • User-facing tooling: the Qom-based unit's Firefox add-on went into production. Its other builds (a Telegram mass-reporting bot, a fake national-ID login page, identity lookups for messenger users and phone numbers) aim at individual Iranians, not enterprise networks.
  • Back-office work: a seven-department body with provincial offices used Claude for analysis and for a browser interface to Arman, the case system both units feed.
  • Refusals: profiling asks were declined, yet our safeguards did not refuse many of the surveillance software tooling requests (Anthropic, PDF p. 102).

What Threadlinqs already had

Prior coverage is thematic: TL-2026-1508 (GTIG, public November 5, 2025; in Threadlinqs since July 19, 2026) shows APT42 prototyping a Gemini data agent that matches phone numbers to owners, the nearest analogue to the Qom unit's lookups.

Context only: TL-2026-0159 (CRESCENTHARVEST, Acronis TRU; since February 28, 2026) stole Telegram and browser data from Farsi-speaking protest supporters, a population overlapping the units' targets, with other tooling.

Later independent coverage, not prior coverage: the US, UK and Dutch CHOSEN BRICK advisory (TL-2026-2526, TL-2026-2534, TL-2026-2543, September 15-16) on Telegram-controlled malware against Iranian dissidents; no source ties it to these units.

What we add

  • Inventory browser extensions against an allow-list (T1176). Anthropic gives only the extension's name, which we checked and found nowhere in our corpus, so unexpected extensions requesting broad site access are the better signal.
  • Watch for pages imitating national-ID services and bursts of coordinated abuse reports against activist or media channels.
  • The 9 detections on TL-2026-1508 target runtime-LLM malware, not this toolset: adjacent coverage only.

Gaps

No record covers Arman, the Qom unit, the extension's ID or hash, or the identity-lookup tools. Anthropic published no network indicators.

Related coverage in Threadlinqs (context, not the same activity) — 3

GTG-30004 — Automated profiling and a modified NanoDump

Anthropic: GTG-30004 · PDF p. 105 · 0 published IoCs · Threadlinqs: 3 prior records, 0 dated 09-10 or later

Anthropic's September 10, 2026 report puts two Claude projects under GTG-30004, an Iran-nexus operator: an OSINT profiling tool aimed at Israeli and Jewish-diaspora targets, and a NanoDump build made harder to analyse. No indicators were published. Before publication Threadlinqs held 3 technique records, the earliest from February 12, 2026, carrying 30 detections.

What Anthropic reported

One strand gives defenders something to act on; the other does not (PDF p. 105).

  • Credential dumping: the operator's NanoDump variant goes through a Python-driven C++ build step that renames symbols and adds filler functions. Assume hash, string and symbol signatures for the public tool miss it; the point was to make it harder to tell that its malware was malware (Anthropic, PDF p. 105).
  • Profiling: a Claude-built OSINT tool enriched an existing list of Israeli government and civil-society figures and diaspora organisations. Open sources only, so targets' networks would show nothing.

What Threadlinqs already had

Three technique-level matches, all before the report:

  • TL-2026-0076 (February 12, 2026): The Gentlemen affiliates also use the public NanoDump; nothing connects the operators. Its Sigma rule keys NanoDump on the file name nanodump.exe, which any renamed binary evades.
  • TL-2026-0495 (May 11, 2026): GTIG on AI-inserted decoy logic in CANFAIL and LONGSTREAM, an analogue for the filler functions.
  • TL-2026-1508: APT42's data agent, covered under GTG-34007.

What we add

  • Renamed files and identifiers beat name and string rules, so detect LSASS access by behaviour: access rights on the lsass.exe handle, the caller's path, lineage and signer, and any dump written afterwards (T1003.001).
  • Threadlinqs held such a rule before the report: KQL-002 in record TL-2026-0504 (May 12, 2026) flags dump-grade access masks on lsass.exe handles from processes outside a name-based allow-list. A renamed NanoDump opening LSASS itself trips it unless it borrows an allow-listed name such as svchost.exe; add path and signer checks, and cover NanoDump's handle-duplication and seclogon modes separately.
  • Enable RunAsPPL and Credential Guard.

Gaps

No record covers the profiling tool, the reworked NanoDump or the build pipeline, and with no named group or indicators there is nothing to pivot on.

Related coverage in Threadlinqs (context, not the same activity) — 5

GTG-30005 — Open-source targeting of US naval forces

Anthropic: GTG-30005 · PDF p. 106 · 0 published IoCs · Threadlinqs: 2 prior records, 4 dated 09-10 or later

GTG-30005, an Iran-nexus operator in Anthropic's September 10, 2026 report, used Claude to turn public data into targeting handbooks on US naval forces and to research flaws in VSAT terminals, Cisco gear and industrial controllers. Before publication Threadlinqs held 2 technique records from July 2026 with 18 detections, none aimed at VSAT.

What Anthropic reported

Three takeaways for defenders (PDF pp. 106–107):

  • No intrusion needed: the naval handbooks came out of a Claude-assisted Python pipeline run over public data only (see the OPSEC point below).
  • Patch check: the account researched seven known flaws across maritime satellite terminals, Cisco voice and industrial-wireless gear, and one Schneider Electric management product (PDF p. 107). If you run that estate, confirm these are closed: CVE-2018-19052, CVE-2019-11072, CVE-2022-22707, CVE-2024-2658, CVE-2024-20354, CVE-2024-20418 and CVE-2025-20309. Anthropic describes research, not exploitation.
  • Also on the account: components for a domestic Iranian surveillance platform and analysis of a private Telegram group's membership, neither with a defender-side artefact.

What Threadlinqs already had

Two technique-level matches, both before the report: TL-2026-1417 (July 16, 2026), Recorded Future on Iranian military LLM use and AI-assisted ICS reconnaissance reaching maritime and shipping; and TL-2026-1508 (July 19, 2026), GTIG on Iranian Gemini misuse for reconnaissance.

Context only, none showing this operator: APT35 reconnaissance feeding kinetic targeting in Gulf states (TL-2026-0339); SS7 and ad-tech tracking of US personnel in the Gulf (TL-2026-2411, TL-2026-1458); and record TL-2026-1053 (June 26, 2026) on CVE-2024-2658.

What we add

  • Maritime operators: inventory VSAT terminals, check firmware against the Cobham advisories, and keep terminal management off the internet and crew networks.
  • Cisco and Schneider owners: patch the listed CVEs plus CVE-2026-20230, a Unified CM sibling exploited from late June 2026 (TL-2026-1070); TL-2026-1053 has hunting rules for CVE-2024-2658. Restrict admin access to management networks.
  • OPSEC: public photo captions and live transponder feeds are targeting inputs. Review caption policy for deployed units.

Gaps

The Cobham CVEs and CVE-2024-20354 are absent from our corpus; CVE-2024-20418 appears only in passing in an unrelated Cisco record. Nothing covers the domestic surveillance platform; there is no named group or indicator.

Related coverage in Threadlinqs (context, not the same activity) — 5

GTG-30006 — An Iran-only surveillance toolkit built in fragments

Anthropic: GTG-30006 · PDF pp. 107–110 · 10 published IoCs · Threadlinqs: 1 prior record, 4 dated 09-10 or later

GTG-30006, an Iranian operator in Anthropic's September 10, 2026 report, spread its work over 16 free Claude.ai organisations to build surveillance tooling aimed at people inside Iran, including the SECOMS64 implant. None of its 10 published indicators was in Threadlinqs before publication; we held 1 technique record with 9 detections.

What Anthropic reported

Anthropic's view stops at build and test, so the artefacts are what defenders get (PDF pp. 107–110):

  • Windows: SECOMS64, a modular implant aimed at Telegram Desktop users (keylogging, a disguised screenshot tool, Chrome credential theft past App-Bound Encryption, USB spread), and a Telegram-bot-driven VBScript dropper.
  • Microsoft 365: scripts replaying Outlook's cached tokens to pull whole mailboxes while posing as the genuine client, so detection must start on the endpoint.
  • Delivery and Android: Iran-only geo-gated pages, separate lures such as a fake ESET login, and an Android app that quietly ships off the phone's contacts, texts and media.

Claude refused nine out of ten direct requests that were facially malicious (Anthropic, PDF p. 107); small, split-up web-development tasks got further.

What Threadlinqs already had

Prior, technique-level only: TL-2026-0159, CRESCENTHARVEST (Acronis TRU; in Threadlinqs since February 28, 2026), targets the same Farsi-speaking population and shares keylogging, Chrome App-Bound Encryption bypass and security-product discovery with SECOMS64. No source connects the operators.

Later independent coverage, not prior coverage: CHOSEN BRICK (TL-2026-2526, from September 15) is the closest technical match (Telegram-bot C2, Run-key persistence, cloud-storage exfiltration), but no source joins the operators. TL-2026-2628 (September 23) covers first-party client-ID abuse against mailboxes.

What we add

The hunt pack carries the 10 CSV artefacts (file names and path, task names, Android package, Telegram chat IDs). Behaviour hunts from the PDF (PDF pp. 109–110):

  • wscript.exe or cscript.exe talking to api.telegram[.]org.
  • A script killing olk.exe or olkexthost.exe, or a non-Outlook process reading the new Outlook token cache, then Outlook web API mailbox downloads.
  • An HKCU Run value Whost.

Techniques: T1528, T1114.002, T1480. We checked the PDF-only network entries; none matched actor infrastructure in our corpus, so pair process with destination rather than block. TL-2026-0159's App-Bound Encryption rule may catch SECOMS64 only if both abuse the same elevation broker; Anthropic does not say.

Gaps

No dedicated record covers comparable Iranian domestic Android spyware (DCHSpy is only named in a MuddyWater arsenal list, TL-2026-1530), and the operator is unattributed.

Related coverage in Threadlinqs (context, not the same activity) — 5

The six remaining cases sit where our corpus is thinnest.

CaseWhat Anthropic reportedClosest Threadlinqs coverageGap
GTG-54009 Anthropic associates a pilot-stage account, banned in June 2026, with the vendor S2T. It sorted posts by location and politics, wrote for fake personas and stocked 255-plus synthetic accounts, matching 2023 Forbidden Stories reporting (PDF pp. 82–83). TL-2026-0159, TL-2026-0333, TL-2026-0728 No S2T record. Vendor context among 8 related records: TL-2026-0333 (Intellexa), TL-2026-0728 (NSO), TL-2026-1726 (FinFisher).
GTG-14010 A PRC-aligned operator (possibly a contractor, Anthropic judges at low confidence) turned chatter from monitored WhatsApp and Telegram groups into profiles of Uyghurs in Syria and ran paid informant recruitment (PDF pp. 86–87). TL-2026-0085, TL-2026-0986, TL-2026-1239 One passing Uyghur mention (TL-2026-1889); no PRC diaspora-surveillance tooling.
GTG-14020 A lone operator ran a probable religious-affairs intelligence desk, in Anthropic's reading, with Claude writing Chinese-language dossiers on Tibetan, Falun Gong, Catholic and Taiwanese church figures (PDF pp. 89–90). TL-2026-0085, TL-2026-0334, TL-2026-0637 No record. Context: TL-2026-0986, whose 2022 targets included a Catholic charity.
GTG-14021 PRC police and state-security bureaus ran dissent monitoring on Claude, up to reconnaissance of protest sites abroad; rewording after a refusal, one got ten private citizens named as targets (PDF pp. 93–94). TL-2026-0085, TL-2026-0334, TL-2026-0495 No record. Context: TL-2026-1889 and Signal backup-key phishing against anti-CCP activists (TL-2026-0637).
GTG-14022 A contractor (Anthropic: medium confidence) ran a near-autonomous pipeline in Claude's code-execution environment, turning 15 to 30-plus foreign articles a day into restricted briefings in mandated Party wording (PDF p. 98). TL-2026-0085, TL-2026-0334, TL-2026-0495 No record of LLM public-opinion pipelines; 5 context records only.
GTG-50027 Probably a Bamako consultant serving Mali's intelligence agency, one subscriber used Claude to engineer Lakana 360: about 25 million SIMs, bulk call, SMS and voice capture, warrant check off by default (PDF pp. 103–104). TL-2026-0144, TL-2026-0143, TL-2026-0195 No Mali coverage. Context: GRIDTIDE telecom intrusions with potential reach into call records, texts and lawful intercept (TL-2026-0195). The ban does not reach the on-premises platform.

Start with the GTG-30006 host artefacts, then behaviour-based LSASS-access detection and browser-extension inventory. Blocklists add little: the network destinations published for these cases are public services.

Conventional weapons

Six disrupted cases make up the weapons section (report section, PDF pp. 111–128): four in which Claude helped write weapons software or design documents, and two on procurement and open-source collection. The table below maps each one. The actors broke their work into fragments so that no single session exposed the programme, and at least one reached Claude over VPNs from a blocked region (PDF p. 124). Anthropic banned the accounts, shared findings with partners and added classifiers aimed at weapons-development traffic.

Our corpus has nothing on these cases, by design. For defence-industrial defenders the nearest context is Russian cyber pressure on drone makers: intrusions into Ukrainian FPV drone workshops (TL-2026-0377) and APT28 targeting of the European drone supply chain (TL-2026-2031).

CaseWhat Anthropic reportedClosest Threadlinqs coverageGap
Six weapons cases Six cases, accounts banned: GTG-87001, Yemen-based, guidance software (PDF p. 112); GTG-17001, China-based, undersea fire-control specification (PDF p. 115); GTG-27005, Russia-based, autonomous drone swarm (PDF p. 117); GTG-17002, China-based, electronic-warfare and air-defence-suppression software (PDF p. 119); GTG-27006, Russia-based, dual-use procurement (PDF p. 123); GTG-17003, China-based, directed-energy collection (PDF p. 126). TL-2026-0377, TL-2026-0622, TL-2026-0891 None at case level, by design. The 8 context records are thematic and share no actor with any case.

Biological misuse

Like the weapons section, the biology section falls outside our corpus's subject matter and publishes no indicators to sweep. What it does document is how the researchers reached the models. That access layer we track, in 10 records, all created before the report. Read what follows as access-control material, not a hunt.

Five dual-use biology cases: the access-evasion layer

Anthropic: · PDF pp. 129–138 · 0 published IoCs · Threadlinqs: 3 prior records, 0 dated 09-10 or later

Anthropic's September 10, 2026 report describes five anonymised dual-use biology cases (biological misuse, PDF pp. 129–138) whose researchers reached Claude via reseller relays, purpose-made accounts and a zero-data-retention channel, with refused prompts routed to a rival model. No indicators were published. Threadlinqs already held 3 technique records on that access layer (earliest May 11, 2026), with 27 detections.

What Anthropic reported

  • One apparent researcher account was a resale relay for a dozen-plus unconnected clients.
  • Bans mostly date from May 2026; partners helped take down the first case's relays.
  • A 30-day review found some 35 efforts tied to states of concern, mostly routine.
  • Anthropic's remedy: trusted-access programmes with account and institutional vetting plus data retention (PDF pp. 137–138).

What Threadlinqs already had

  • TL-2026-0495 (May 11, 2026, Google GTIG): relay middleware pooling accounts across providers, plus scripted sign-ups.
  • TL-2026-1911 (August 6, Unit 42): transfer stations reselling model access, fed by stolen keys.
  • TL-2026-2413 (AA26-251A, public September 8; in Threadlinqs September 9): geo-restriction relays, fraudulent account pools, automated failover.

What we add

  • Alert on outbound TLS to relay middleware (TL-2026-0495-SIG-003); the shipped rule exempts AI-research and ML-lab hosts, so drop that filter if research subnets are in scope.
  • Hunt for one key serving many client fingerprints, or many accounts behind one egress address (T1090.003, T1078).

Gaps

None of the three covers these five cases, and Anthropic withheld institutions, countries and agents. The decisive signals, from refusals to model switching, are provider-side; network defenders see only a TLS session to a relay.

Related coverage in Threadlinqs (context, not the same activity) — 5

For a SOC, the practical output is a procurement rule, not a SIEM rule: staff and contractors reach frontier models only through accounts you own and can audit, and use of a discount reseller counts as a data-governance incident whatever the work.

Scams and fraud

The report's one scams case is consumer fraud at industrial volume: AI personas do most of the deceiving, with paid humans mixed in mainly where a video call or follow-back must look real (PDF pp. 139–142). Little of it crosses a corporate network, so the levers sit with app stores, MDM owners and AI providers.

GTG-15001 — A dating-app network run mostly by AI personas

Anthropic: GTG-15001 · PDF pp. 139–142 · 8 published IoCs · Threadlinqs: 1 prior record, 2 dated 09-10 or later

GTG-15001, per Anthropic's September 10, 2026 report, is a China-based app studio that ran 20-plus look-alike US dating apps sold as human-only; over two weeks of April 2026, more than 4,700 Claude personas exchanged about 2.36 million messages with 25,000-plus people. None of its 8 indicators were in Threadlinqs before publication. The corpus held 1 technique-level record beforehand (FakeWallet, April 20, 2026), with 9 detections built for a different operation; we add package blocks and review-evasion hunts.

What Anthropic reported

Mechanics are at PDF pp. 139–142; what follows is what they mean for defenders.

  • Hunt surface. Limited to the 8 published indicators below. Model access ran through PRC reseller and proxy networks (PDF p. 139).
  • Code similarity will not link the apps. They were built to look different under store review and renamed variant by variant to slip similarity checks (PDF p. 140).
  • Human checks prove little. A live call or follow-back comes from the paid quarter of profiles and says nothing about the rest.
  • Not public. Publisher identities and review-evasion details went to Apple and Google only; Anthropic banned the operator's accounts and throwaway orgs and briefed the other labs (PDF pp. 141–142).

What Threadlinqs already had

One record carries the case's distinctive tradecraft, and it describes a different operation.

  • TL-2026-0395: FakeWallet, public April 20, 2026 via Kaspersky and in Threadlinqs the same day. A Chinese-speaking operator placed stub apps in the App Store whose real job was to open a browser link on launch, and parked dormant apps awaiting an update to switch on phishing. The payload is a wallet stealer and no indicator overlaps: a review-evasion precedent, nothing more.

Context only: INTERPOL's Asia and South Pacific assessment (TL-2026-0897, in Threadlinqs since June 22, 2026) notes scam compounds pairing AI personas with romance baiting, though GTG-15001 sold coin-metered chat, not fake investments. The transfer-station relays and stolen-key resale in TL-2026-2413 and TL-2026-1911 are the kind of channel Anthropic says the operator used.

Later independent coverage, not prior:

  • TL-2026-2591: FomoPeek (SlowMist; in Threadlinqs since September 20, 2026). Hidden modules arrived in post-approval updates, and an activation gate plausibly screened out review and emulator environments.
  • TL-2026-2655: deceptive Android apps parked in Google Play Early Access, which hides public ratings and reviews (Bitdefender, public September 10; in Threadlinqs since September 25).

What we add

The value here is the indicator set and two behavioural hunts, not a match.

  • Indicators. Filter the indicator table to GTG-15001 for all 8: five hostnames across the operator's company, marketing, web-app and cloud-backend domains, one US egress address and two Android package IDs. The brand names printed only in the report were checked too; none matched the operator in our corpus.
  • MDM. Block the two package IDs on managed devices and match on package ID, not display name: the brand names are generic and can collide with unrelated legitimate apps.
  • Egress window. Search April 2026 proxy and firewall logs for 38.129.138[.]244, the US egress proxy Anthropic flags for hunting rather than blocking; a hit is a lead, not attribution.
  • Store and trust teams. Diff the remote config served to reviewer-like environments against what ordinary US devices receive, and cluster apps on shared backend, CDN and payment endpoints rather than code similarity. The review-only controller maps to T1627 and T1633.
  • Detections. The 9 FakeWallet rules target that malware's wallet hooking and C2 and will not fire on these apps. The nearest behavioural logic is TL-2026-2591-SIG-001, an anti-emulator activation-gate rule written for later, unrelated reporting; it is hard-scoped to FomoPeek's bundle ID and reward events, so swap in your own app IDs and events first.

Gaps

  • No dating-app or AI-companion fraud record exists in the corpus, and none of the 8 published indicators, the ASN or the brand names matched.
  • Nothing covers the sitin gig-worker app or the server-toggled payment browser.
Related coverage in Threadlinqs (context, not the same activity) — 4

Illicit distillation

Anthropic's September 10, 2026 report names seven China-based labs that ran distillation campaigns against Claude after its February disclosure (distill-intro, PDF pp. 143–146): Alibaba, Moonshot AI, DeepSeek, Zhipu (Z.ai), Xiaomi, SenseTime and MiniMax. A distilled copy keeps Claude's capabilities but not its safeguards, Anthropic warns, and it says DeepSeek, Moonshot and Xiaomi fed their own users' conversations, some of them sensitive, into Claude.

Apart from GTG-20006, distillation is the only area where Threadlinqs held actor-level coverage before the report. CISA/NSA/FBI advisory AA26-251A, public since September 8, 2026 and in Threadlinqs since September 8-9 (TL-2026-2405, TL-2026-2413), names Alibaba, Moonshot AI, DeepSeek, Z.ai and MiniMax, but not Xiaomi or SenseTime. The match is at company level, not campaign level. Anthropic adds covert relaying of customers' prompts, thinking-signature replay, replay of real user sessions, a named buyer of harvested transcripts and a shell-company proxy.

GTG-16005 — Alibaba's forced-reasoning distillation, per Anthropic

Anthropic: GTG-16005 · PDF pp. 147–148 · 0 published IoCs · Threadlinqs: 3 prior records, 0 dated 09-10 or later

Anthropic ties GTG-16005 to Alibaba-affiliated operators (Qwen/Tongyi Lab) and calls it the largest distillation attack we have ever measured (Anthropic, PDF p. 147): an injected instruction made Opus 4.6 and 4.7 show their working, with traffic peaking near 3 million exchanges a day. No indicators were published. Before the report, Threadlinqs held 3 related records, including AA26-251A naming Alibaba, with 27 detections.

What Anthropic reported

  • Hunt for: one fixed instruction injected into every request, telling the model to write tagged reasoning before answering; a constant string across thousands of accounts stands out more than the varied tasks (PDF p. 147).
  • Account signals: the first pool, close to 5,000 accounts, used residential proxies, throwaway mailboxes and virtual cards; banned, the traffic moved to a second pool, parts of which also carried DeepSeek and Xiaomi requests (PDF p. 148).
  • Stakes: 151 million-plus exchanges from May to July 2026, weighted to agentic, coding, kernel and long-horizon work. Anthropic says the output trained Qwen 3.5-3.7 and that Claude also aided Alibaba's RL-environment and architecture work. ATLAS: AML.T0024.002, AML.T0021.

What Threadlinqs already had

  • AA26-251A (TL-2026-2405, TL-2026-2413) names Alibaba as distilling Claude for Qwen, dating it to 2025. TL-2026-2405 also holds a separate, earlier Anthropic count (April to June 2026, from a Senate Banking Committee letter).
  • TL-2026-0085 (GTIG, in Threadlinqs since February 15, 2026): reasoning-trace coercion against Gemini, a technique precedent without actor overlap.

What we add

Gaps

Nothing in the corpus on the injected-tag prompt, the account pools, the report's volumes, Tongyi Lab or Qwen 3.5-3.7.

Related coverage in Threadlinqs (context, not the same activity) — 5

GTG-16002 — Moonshot relays Kimi customers to Claude, per Anthropic

Anthropic: GTG-16002 · PDF pp. 148–149 · 0 published IoCs · Threadlinqs: 2 prior records, 0 dated 09-10 or later

Moonshot AI, maker of Kimi, is GTG-16002. Anthropic says it quietly answered its own customers with Claude, relaying almost 300,000 requests in ten days through 5,380 fraudulent accounts, and mined saved exchanges for reasoning. No indicators were published. Before the report, Threadlinqs held 2 AA26-251A records naming Moonshot, with 18 detections, but nothing on the relay.

What Anthropic reported

  • Hidden substitution: Kimi users could not tell Claude was answering. Exposures Anthropic cites: CCTV analysis of one tracked person from hundreds of Chengdu cameras, by a user it judges likely PLA-affiliated, and an SOE engineer whose prompts unwittingly carried source code and working logins of several major PRC firms (PDF p. 149).
  • Traffic profile: relay accounts mostly appeared to sit in Singapore and Japan and routed nearly all traffic to Opus (PDF p. 148); Anthropic counts over 23 million Moonshot exchanges from May to July 2026.
  • Signature replay: a thinking signature kept from one answer and resubmitted in a fresh session got Claude to rebuild the reasoning behind it; Anthropic says fixes are coming (PDF pp. 148–149).

What Threadlinqs already had

  • AA26-251A (TL-2026-2405, TL-2026-2413) names Moonshot AI as distilling Claude for its Kimi models; TL-2026-2405 adds that relay services are often hosted outside China, Singapore included.

What we add

  • For the relay pattern, pair TL-2026-2413-SIG-003 (requested-versus-served model mismatch, our closest rule to silent substitution) with TL-2026-2413-SPL-002 (non-human 24/7 API throughput) and TL-2026-2405-SPL-003 (bursts of accounts sharing one payment token).
  • Ask AI vendors to disclose sub-processors and upstream model routing.

Gaps

The customer relay, the 5,380-account pool, the signature bypass, the volumes and the exposed customer data are all new to the corpus.

Related coverage in Threadlinqs (context, not the same activity) — 5

GTG-16001 — DeepSeek's covert relay and reasoning replay, per Anthropic

Anthropic: GTG-16001 · PDF pp. 149–150 · 0 published IoCs · Threadlinqs: 2 prior records, 0 dated 09-10 or later

Anthropic says DeepSeek (GTG-16001) secretly routed selected customers' requests to Claude Opus, served the answers as its own and replayed reasoning signatures to harvest chain-of-thought: more than 12.1 million exchanges in 14 days of July 2026. No indicators were published. Before the report, Threadlinqs held 2 AA26-251A records on DeepSeek's Claude distillation, with 18 detections.

What Anthropic reported

  • Who was exposed: per Anthropic, DeepSeek used client-identifying strings to single out customers reaching its models through OpenCode, Claude Code or the Claude Agent SDK, who probably never knew (PDF pp. 149–150). Code, documents and secrets in those sessions reached a second provider.
  • Stakes: Anthropic's examples run from a PRC tech firm's internal plans for a flagship AI programme to working credentials for a Russian government database and a city police bureau's tracking tool (PDF p. 150).
  • Reasoning capture: Moonshot's saved-signature replay, reused to obtain the full chain of thought instead of Claude's summary.

What Threadlinqs already had

  • AA26-251A (TL-2026-2405, TL-2026-2413) names DeepSeek as distilling Claude and other US models since at least late 2024, with a focus on reasoning. TL-2026-2405 also records an April 2026 State Department warning naming DeepSeek.

What we add

  • TL-2026-2413-KQL-002 flags chain-of-thought extraction phrasing in request bodies; TL-2026-2413-SIG-003 flags answers from a model other than the one requested.
  • Inventory coding clients pointed at third-party model endpoints (for example ANTHROPIC_BASE_URL overrides) and vet each provider.

Gaps

No record of the relay, the coding-client tagging, the replay attack, the July volume or the exposed data; our DeepSeek coverage describes earlier activity.

Related coverage in Threadlinqs (context, not the same activity) — 4

GTG-16006 — Zhipu (Z.ai) cleans harvested reasoning with Claude, per Anthropic

Anthropic: GTG-16006 · PDF pp. 150–151 · 0 published IoCs · Threadlinqs: 2 prior records, 1 dated 09-10 or later

Zhipu, trading abroad as Z.ai, is GTG-16006. Anthropic says it spent ten days pulling chain-of-thought from Opus 4.8 through 273 fraudulent accounts, had Claude scrub the traces into GLM training data, and later went after US models' cyber skills. No indicators were published. Before the report, Threadlinqs held 2 AA26-251A records naming Z.ai, with 18 detections.

What Anthropic reported

  • Traffic shape: most of the 3 million-plus exchanges Anthropic ties to Zhipu over ten June days were a cleaning pass, Claude's reasoning sent back to be rewritten as training text (770,609 through the cleaner itself); 17 days of June and July top 3.4 million (PDF pp. 150–151).
  • Safeguards steered targeting: per Anthropic, Zhipu staff dropped Fable for Opus 4.6 and a rival US lab's flagship, judged weaker, while seeking cyber capability to distil before GLM 5.3 with CTF tasks built on public vulnerability data; Opus 4.6 mostly graded (PDF p. 151).
  • Beyond extraction: Claude also served as grader and data preparer in Zhipu's post-training.

What Threadlinqs already had

  • AA26-251A (TL-2026-2405, TL-2026-2413) names Z.ai as extracting Claude Opus 4.8 data for chain-of-thought reasoning.
  • Not prior coverage and not about distillation: TL-2026-2615 (Cisco Talos CAIRN, added September 22, 2026) has hunting filters for malware calling Chinese-provider model APIs, BigModel among them.

What we add

  • Start with TL-2026-2413-KQL-002 (CoT extraction prompt patterns) and TL-2026-2405-SIG-003 (high prompt-repeat ratios at extraction volume).
  • Hunt hypothesis for gateway owners, not an existing rule: large batches of model-written reasoning resubmitted with rewrite or normalise instructions, the shape of the cleaning pass.

Gaps

The cleaning step, the 273-account pool, the volumes, Claude's post-training role and the pre-GLM 5.3 cyber campaign are all absent from the corpus.

Related coverage in Threadlinqs (context, not the same activity) — 5

GTG-16008 — Xiaomi replays real MiMo sessions to Claude, per Anthropic

Anthropic: GTG-16008 · PDF pp. 151–152 · 0 published IoCs · Threadlinqs: 2 prior records, 0 dated 09-10 or later

Xiaomi is GTG-16008. Per Anthropic, it resent its own MiMo users' past conversations, many of them coding work, to Claude as training material: over 400,000 requests through 1,500-plus proxy accounts in 20 days of March and April 2026. No indicators were published. Threadlinqs had no Xiaomi record before the report, only 2 AA26-251A technique records on proxy-based distillation, with 18 detections.

What Anthropic reported

  • Your data may be in it: many replayed sessions had reached MiMo through model routers popular in the US and Europe, so they carried personal and corporate details of hundreds of users writing in a dozen or more languages. Anthropic has no indication US persons' data was exposed (PDF pp. 151–152).
  • Timing: Anthropic suggests Xiaomi may have used a MiMo-V2-Pro free trial, later extended, to attract developer traffic worth distilling; most of the Claude traffic started as the trial wound down (PDF p. 152).
  • Claude's role: making training data (rebuilt developer environments, synthetic developer exchanges, grading); Anthropic saw no sign its answers reached MiMo users.

What Threadlinqs already had

  • AA26-251A describes proxy and aggregator paths into US models (TL-2026-2405) and says transfer-station operators treat harvested logs as their main product (TL-2026-2413). Xiaomi is not named: a shared technique, not an actor link.

What we add

  • Routing-layer detections: TL-2026-2413-SPL-002 (non-human 24/7 API throughput) and TL-2026-2405-KQL-003 (one account across many endpoints and source IPs in an hour).
  • Check whether the routers and coding agents your developers use keep or resell prompts; Anthropic's account shows a prompt sent to one lab can be replayed to another and trained on.

Gaps

Xiaomi and MiMo are absent: Xiaomi hits are incidental (phone-maker, app-store and researcher-credit mentions); the one "Mimo" match is unrelated crimeware. No OpenClaw or OpenCode record treats those tools as a source of replayed sessions.

Related coverage in Threadlinqs (context, not the same activity) — 3

GTG-16012 and GTG-16003 — SenseTime's bought transcripts and MiniMax's shell-company proxy, per Anthropic

Anthropic: GTG-16012 · PDF pp. 152–154 · 0 published IoCs · Threadlinqs: 3 prior records, 0 dated 09-10 or later

GTG-16012 and GTG-16003 cover SenseTime and MiniMax; the report does not say which label is which. Anthropic says SenseTime trained on Claude transcripts bought from data vendors and that MiniMax runs a US-models-only proxy through an undisclosed shell company, likely to harvest exchanges. No indicators were published. Before the report, Threadlinqs held 3 records on MiniMax and the relay economy, with 27 detections; none on SenseTime.

What Anthropic reported

  • Assume resale: Anthropic describes a secondary market in which some access resellers double as transcript sellers, passing relayed chats to other labs (PDF p. 152). Any app, router or reseller between your users and a model is a potential transcript source.
  • SenseTime as buyer: its training data included Claude transcripts bought from data vendors, sourced from apps and routers; Claude also helped build and run that training (PDF pp. 152–153).
  • MiniMax as collector: a front company with no disclosed MiniMax tie runs a relay limited to Anthropic and OpenAI models (not even MiniMax's own); Anthropic reads it as harvesting (PDF p. 153).

What Threadlinqs already had

  • AA26-251A (TL-2026-2405, TL-2026-2413) names MiniMax as a Claude distiller using fraudulent accounts, a different method from a shell-company proxy.
  • TL-2026-1911 (Unit 42, in Threadlinqs since August 6, 2026): relayed traffic arrives as ready-labelled training data. A comparable mechanism; neither lab appears.

What we add

  • Treat browser extensions and third-party AI apps as exfiltration paths (TL-2026-1246 lists extensions that intercepted AI chats) and keep AI use on contracted endpoints.
  • Detections include TL-2026-2405-SPL-001 (new accounts used outside their registered region at volume) and TL-2026-1911-KQL-003 (known transfer-station IPs and domains; will age).

Gaps

SenseTime returns nothing in the corpus, and the transcript trade appears only generically (TL-2026-2413 on proxy log harvesting, TL-2026-1911 on relayed traffic as training data), naming no buyer or vendor. MiniMax's shell-company proxy is absent too.

Related coverage in Threadlinqs (context, not the same activity) — 5

None of these cases came with indicators to block. Providers and LLM gateway owners with prompt-level logs can hunt behaviour: reasoning-forcing instructions repeated across accounts, round-the-clock throughput with no human rhythm, many accounts sharing one payment or routing fingerprint. Seed pattern lists with Anthropic's sample extraction prompts, such as a request to "translate" earlier reasoning (PDF pp. 145–146), and borrow from its playbook (PDF pp. 153–154): tie proxy accounts to the organisation behind them, and demand identity checks on resale signals. Everyone else owns the data path: know which routers, resellers, extensions and assistants see your prompts, and vet them like any processor of company data.

The unusual part: pre-burned infrastructure, public tooling and a server we read differently

Only one case has actor-controlled indicator overlap that predates publication, and other vendors got there first. Of the 55 GTG-20006 rows, 17 actor-controlled ones were already in our corpus, most via ReliaQuest's and Microsoft's CaptiveCrunch reporting (lookalike domains, rogue DNS resolver, ChocoShell C2, both malware hashes; held since July 31, 2026, TL-2026-1808) or Google's UNC7005 reporting (since August 21, 2026, TL-2026-2091). Anthropic cites Microsoft's July write-up. So the operator used infrastructure Microsoft and Google already tracked as Storm-2945 and UNC7005. That does not put every GTG-20006 workstream in the cluster: most of the case's rows match nothing, and no pre-publication record mentions PowerChrome, WUEngine, Shadow C2, GiftDrop or Embassy Kit.

The oldest overlap is the weakest. cdncounter[.]net and its static host have sat in our DarkSword record since March 18, 2026 (TL-2026-0245) as delivery domains Google ties to UNC6353. DarkSword has several users and its source leaked, so whether GTG-20006 and UNC6353 are one operator stays open.

Public tools recur. MiniPlasma, listed with the operator's Windows malware, shares its name with a privilege-escalation proof of concept an independent researcher released on GitHub on May 15, 2026 (TL-2026-0523); that researcher's server is also on Anthropic's list, so the same code is likely. The operator used the open-source WPPConnect library for some of its WhatsApp hijacks, and the library already appears in a Brazilian banking-trojan campaign (TL-2026-1785). GTG-30004 modified NanoDump, also seen in The Gentlemen ransomware tradecraft (TL-2026-0076); GTG-50014 ran TruffleHog and GTG-50029 BeEF. Tool names make poor pivots.

Anthropic labels projectnightcrawler[.]dev operator or lure infrastructure. Our records from June and August 2026 (TL-2026-0835, TL-2026-1865) describe it as the platform that same researcher self-hosted after GitHub and GitLab takedowns, mirroring other proofs of concept (RoguePlanet, GreatXML, LegacyHive). Most likely the operator fetched public exploit code there, though Anthropic may have seen a lure use we cannot. We mark it context-only and keep it out of the sweeps.

Naive /24 pivots mislead too. GTG-20006 addresses sit in /24s beside servers our corpus records as North Korean C2 and BlueNoroff infrastructure, a GTG-50014 egress address neighbours a host from our TeamPCP reporting, and GTG-50020's 178.16.54[.]141 falls in a /22 that Intrinsec and Spamhaus tie to bulletproof hosting (TL-2026-0617). None of this is evidence: cheap VPS and VPN space is shared by design.

Between February and the September 25, 2026 snapshot, 455 of the 2,462 threat records we created involve AI. A keyword classifier, which misses some, files each in one bucket: AI used by attackers (234), AI systems as targets (188) and AI brands as lures (33). Volume dipped in spring after 28 in February, peaked at 154 in July, then eased; September is partial. Part of that peak is ingestion: in July we logged Check Point's annual AI security report (TL-2026-1286) and, late, GTIG's November 2025 write-up of AI-enabled malware (TL-2026-1508).

The report's core argument, that the techniques are old and only the labour got cheaper, matches what vendors documented before September 10, 2026: a financially motivated cluster working Mexican government targets through a Claude-backed agentic CLI (Trend Micro, TL-2026-0498), a Russian-speaking operator breaking into FortiGate appliances with commercial models and a custom MCP server (Amazon, TL-2026-0131), a ransomware crew running Cursor Agent on a Claude model inside victim networks (Gambit Security, TL-2026-2243) and a suspected China-linked operator driving the Hermes and OpenClaw frameworks near-autonomously against Taiwan under a pentest cover story (Israeli firm Dream, TL-2026-2063). Anthropic adds the operator's side: prompts, agent configurations and how much of the loop the model ran.

The targets bucket describes the same key-theft economy as Anthropic's supply-chain cases: Langflow exploitation feeding a key-harvesting botnet (TL-2026-0514), the LiteLLM SQL injection (TL-2026-0487), scanning for MCP servers and agent credentials (TL-2026-1278) and transfer-station resale (TL-2026-1911). None of these records involves GTG-50014, GTG-50020 or GTG-50021. Lures are the smallest bucket but the likeliest to reach a developer laptop (TL-2026-0403, TL-2026-1845).

Two blind spots show. Distillation barely registers until the AA26-251A records in September, filed under targets. Influence and surveillance, the two largest groups in Anthropic's case list, hardly appear: our vendor and government sources follow intrusions and malware far more closely than content operations or domestic surveillance. That collection bias explains most empty cells in the coverage matrix.

AI-related threats in the Threadlinqs corpus, Feb–Sep 2026
AI used by attackersAI systems as targetsAI brands as lures

Swipe the chart sideways →

0 50 100 150 200 2026-02: AI used by attackers — 15 2026-02: AI systems as targets — 12 2026-02: AI brands as lures — 1 28 2026-02 2026-03: AI used by attackers — 13 2026-03: AI systems as targets — 11 24 2026-03 2026-04: AI used by attackers — 7 2026-04: AI systems as targets — 12 2026-04: AI brands as lures — 4 23 2026-04 2026-05: AI used by attackers — 13 2026-05: AI systems as targets — 14 2026-05: AI brands as lures — 7 34 2026-05 2026-06: AI used by attackers — 22 2026-06: AI systems as targets — 31 2026-06: AI brands as lures — 2 55 2026-06 2026-07: AI used by attackers — 86 2026-07: AI systems as targets — 60 2026-07: AI brands as lures — 8 154 2026-07 2026-08: AI used by attackers — 49 2026-08: AI systems as targets — 35 2026-08: AI brands as lures — 5 89 2026-08 2026-09: AI used by attackers — 29 2026-09: AI systems as targets — 13 2026-09: AI brands as lures — 6 48 2026-09

Primary category per threat (first match in order offense > lure > target > distill); tag OR title/summary keyword match; created_at month; Sept is partial (to 2026-09-25).

Show data table
MonthAI used by attackersAI systems as targetsAI brands as lures
2026-0215121
2026-0313110
2026-047124
2026-0513147
2026-0622312
2026-0786608
2026-0849355
2026-0929136

ATT&CK and ATLAS mapping

Most top-cited techniques on the strip sit before compromise: gathering victim identity information (T1589), acquiring domains (T1583.001), creating social media accounts (T1585.001) and obtaining AI capabilities (T1588.007). Apart from domains, visible in passive DNS and certificate logs, their bars are short: that work happens on the provider's platform and the operator's kit, beyond any SOC sensor. Coverage runs deep where cases touch your estate: public-facing exploits (T1190), valid accounts (T1078), token theft (T1528) and exfiltration over C2 (T1041). In ATLAS terms, most cases use AI model inference API access (AML.T0040); jailbreaks (AML.T0054) recur across groups, distillation adds model extraction (AML.T0024.002), and key theft adds unsecured credentials (AML.T0055) and cost harvesting (AML.T0034). The full map below lists every id from our case extractions. ATLAS is reporting vocabulary; the ATT&CK bars show where detection engineering pays.

Techniques cited most across the cases vs. Threadlinqs detection coverage

Swipe the chart sideways →

1 10 100 1000 10000 T1589 Gather Victim Identity Info… T1589 Gather Victim Identity Information — cited in 12 cases; 91 Threadlinqs detections map to it 91 T1090 Proxy T1090 Proxy — cited in 9 cases; 319 Threadlinqs detections map to it 319 T1583.001 Acquire Infrastructure: Dom… T1583.001 Acquire Infrastructure: Domains — cited in 9 cases; 425 Threadlinqs detections map to it 425 T1585.001 Establish Accounts: Social… T1585.001 Establish Accounts: Social Media Accounts — cited in 7 cases; 52 Threadlinqs detections map to it 52 T1190 Exploit Public-Facing Appli… T1190 Exploit Public-Facing Application — cited in 6 cases; 2218 Threadlinqs detections map to it 2218 T1585 Establish Accounts T1585 Establish Accounts — cited in 6 cases; 69 Threadlinqs detections map to it 69 T1591 Gather Victim Org Informati… T1591 Gather Victim Org Information — cited in 6 cases; 49 Threadlinqs detections map to it 49 T1593.001 Search Open Websites/Domain… T1593.001 Search Open Websites/Domains: Social Media — cited in 6 cases; 14 Threadlinqs detections map to it 14 T1078 Valid Accounts T1078 Valid Accounts — cited in 5 cases; 902 Threadlinqs detections map to it 902 T1587.001 Develop Capabilities: Malwa… T1587.001 Develop Capabilities: Malware — cited in 5 cases; 76 Threadlinqs detections map to it 76 T1588.007 Obtain Capabilities: Artifi… T1588.007 Obtain Capabilities: Artificial Intelligence — cited in 5 cases; 26 Threadlinqs detections map to it 26 T1593 Search Open Websites/Domains T1593 Search Open Websites/Domains — cited in 5 cases; 26 Threadlinqs detections map to it 26 T1656 Impersonation T1656 Impersonation — cited in 5 cases; 424 Threadlinqs detections map to it 424 T1528 Steal Application Access To… T1528 Steal Application Access Token — cited in 4 cases; 617 Threadlinqs detections map to it 617 T1552 Unsecured Credentials T1552 Unsecured Credentials — cited in 4 cases; 341 Threadlinqs detections map to it 341 T1566 Phishing T1566 Phishing — cited in 4 cases; 300 Threadlinqs detections map to it 300 T1027 Obfuscated Files or Informa… T1027 Obfuscated Files or Information — cited in 3 cases; 1278 Threadlinqs detections map to it 1278 T1036 Masquerading T1036 Masquerading — cited in 3 cases; 659 Threadlinqs detections map to it 659 T1041 Exfiltration Over C2 Channel T1041 Exfiltration Over C2 Channel — cited in 3 cases; 1224 Threadlinqs detections map to it 1224 T1539 Steal Web Session Cookie T1539 Steal Web Session Cookie — cited in 3 cases; 533 Threadlinqs detections map to it 533 T1550.001 Use Alternate Authenticatio… T1550.001 Use Alternate Authentication Material: Application Access Token — cited in 3 cases; 308 Threadlinqs detections map to it 308 T1021 Remote Services / lateral m… T1021 Remote Services / lateral movement — cited in 2 cases; 203 Threadlinqs detections map to it 203

Top techniques by number of cases citing them (explicit or inferred in our extraction), with the count of Threadlinqs detections mapped to each technique across the whole corpus (log scale).

Show data table
TechniqueCases citingThreadlinqs detections
T1589 Gather Victim Identity Information1291
T1090 Proxy9319
T1583.001 Acquire Infrastructure: Domains9425
T1585.001 Establish Accounts: Social Media Accounts752
T1190 Exploit Public-Facing Application62218
T1585 Establish Accounts669
T1591 Gather Victim Org Information649
T1593.001 Search Open Websites/Domains: Social Media614
T1078 Valid Accounts5902
T1587.001 Develop Capabilities: Malware576
T1588.007 Obtain Capabilities: Artificial Intelligence526
T1593 Search Open Websites/Domains526
T1656 Impersonation5424
T1528 Steal Application Access Token4617
T1552 Unsecured Credentials4341
T1566 Phishing4300
T1027 Obfuscated Files or Information31278
T1036 Masquerading3659
T1041 Exfiltration Over C2 Channel31224
T1539 Steal Web Session Cookie3533
T1550.001 Use Alternate Authentication Material: Application Access Token3308
T1021 Remote Services / lateral movement2203
Full technique map: 118 ATT&CK techniques and 18 ATLAS techniques across the cases
ATT&CKTechniqueCasesIn the reportThreadlinqs detections
T1589Gather Victim Identity InformationGTG-04001, GTG-14010, GTG-14020, GTG-14021, GTG-30004, GTG-30005, GTG-34001, GTG-34007, GTG-50027, GTG-54009, GTG-84002, GTG-84006explicit91
T1090ProxyGTG-10007, GTG-14021, GTG-15001, GTG-16002, GTG-16012, GTG-30006, GTG-34001, GTG-50020, GTG-50029explicit319
T1583.001Acquire Infrastructure: DomainsGTG-15001, GTG-20006, GTG-50014, GTG-50020, GTG-50029, GTG-54002, GTG-84002, GTG-84005, GTG-50021explicit425
T1585.001Establish Accounts: Social Media AccountsGTG-14010, GTG-34001, GTG-54002, GTG-54009, GTG-84002, GTG-84005, GTG-84006explicit52
T1190Exploit Public-Facing ApplicationGTG-10007, GTG-20006, GTG-50014, GTG-50020, GTG-50029, GTG-50021explicit2218
T1585Establish AccountsGTG-15001, GTG-16002, GTG-16005, GTG-34001, GTG-50020, GTG-54006explicit69
T1591Gather Victim Org InformationGTG-14010, GTG-14020, GTG-14021, GTG-30004, GTG-30005, GTG-84002explicit49
T1593.001Search Open Websites/Domains: Social MediaGTG-14010, GTG-14020, GTG-14022, GTG-34007, GTG-54009, GTG-84006explicit14
T1078Valid AccountsGTG-10007, GTG-20006, GTG-50014, GTG-50020, GTG-50029explicit902
T1587.001Develop Capabilities: MalwareGTG-10007, GTG-20006, GTG-30004, GTG-30006, GTG-50029explicit76
T1588.007Obtain Capabilities: Artificial IntelligenceGTG-14010, GTG-20006, GTG-50020, GTG-54002, GTG-54006explicit26
T1593Search Open Websites/DomainsGTG-10007, GTG-14021, GTG-20006, GTG-30004, GTG-30005explicit26
T1656ImpersonationGTG-14010, GTG-15001, GTG-54009, GTG-84002, GTG-84006explicit424
T1528Steal Application Access TokenGTG-20006, GTG-30006, GTG-50014, GTG-50021explicit617
T1552Unsecured CredentialsGTG-10007, GTG-50020, GTG-50029, GTG-50021explicit341
T1566PhishingGTG-20006, GTG-30006, GTG-50014, GTG-54009explicit300
T1027Obfuscated Files or InformationGTG-15001, GTG-30004, GTG-30006explicit1278
T1036MasqueradingGTG-20006, GTG-34007, GTG-50021explicit659
T1041Exfiltration Over C2 ChannelGTG-10007, GTG-50014, GTG-50021explicit1224
T1539Steal Web Session CookieGTG-50014, GTG-50020, GTG-50021explicit533
T1550.001Use Alternate Authentication Material: Application Access ToGTG-20006, GTG-30006, GTG-50014explicit308
T1021Remote Services / lateral movementGTG-10007, GTG-20006inferred203
T1036.005Masquerading: Match Legitimate Name or LocationGTG-30006, GTG-50029inferred1449
T1074Data StagedGTG-10007, GTG-50029explicit32
T1114.002Email Collection: Remote Email CollectionGTG-20006, GTG-30006explicit97
T1119Automated CollectionGTG-14021, GTG-50029inferred314
T1133External Remote ServicesGTG-10007, GTG-20006explicit383
T1204.004User Execution: Malicious Copy and PasteGTG-20006, GTG-30006explicit155
T1496Resource HijackingGTG-50014, GTG-50020explicit178
T1530Data from Cloud StorageGTG-10007, GTG-50014inferred170
T1552.001Unsecured Credentials: Credentials In FilesGTG-50014, GTG-50021explicit805
T1555.003Credentials from Password Stores: Credentials from Web BrowsGTG-20006, GTG-30006explicit488
T1557Adversary-in-the-MiddleGTG-20006, GTG-50020explicit293
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud StorageGTG-30006, GTG-50014explicit352
T1587Develop CapabilitiesGTG-34007, GTG-50027explicit22
T1587.004Develop Capabilities: ExploitsGTG-10007, GTG-50029explicit72
T1588.002Obtain Capabilities: ToolGTG-30004, GTG-50020explicit106
T1591.001Gather Victim Org Information: Determine Physical LocationsGTG-14010, GTG-14020inferred9
T1592Gather Victim Host InformationGTG-30005, GTG-50029explicit57
T1595Active ScanningGTG-20006, GTG-50014explicit190
T1595.002Active Scanning: Vulnerability ScanningGTG-10007, GTG-50020explicit436
T1598Phishing for InformationGTG-14010, GTG-34007explicit58
T1608.001Stage Capabilities: Upload MalwareGTG-30006, GTG-50021inferred150
T1657Financial TheftGTG-50014, GTG-50020explicit499
T0007DISARM: Create Inauthentic Social Media Pages and GroupsGTG-54002explicit3
T0013DISARM: Create Inauthentic WebsitesGTG-54002explicit0
T0049DISARM: Flooding the Information SpaceGTG-54002explicit3
T0084DISARM: Reuse Existing ContentGTG-54002explicit0
T0085AI-assisted production of text-based propaganda and news conGTG-04001inferred0
T0085.001DISARM: Develop AI-Generated TextGTG-54002explicit2
T0085.004Forged official government documentsGTG-04001inferred0
T0086.002DISARM: Develop AI-Generated ImagesGTG-54002explicit0
T1003.001OS Credential Dumping: LSASS MemoryGTG-30004explicit173
T1018Remote System DiscoveryGTG-10007inferred149
T1027.005Obfuscated Files or Information: Indicator Removal from ToolGTG-20006inferred1
T1036.004Masquerading: Masquerade Task or ServiceGTG-30006inferred54
T1040Network SniffingGTG-50027inferred51
T1053.005Scheduled TaskGTG-30006inferred529
T1056.001Input Capture: KeyloggingGTG-30006inferred158
T1056.002Input Capture: GUI Input CaptureGTG-30006inferred71
T1056.003Input Capture: Web Portal CaptureGTG-50029explicit166
T1059.001Command and Scripting Interpreter: PowerShellGTG-30006inferred1004
T1059.005Command and Scripting Interpreter: Visual BasicGTG-30006inferred178
T1068Privilege escalation to cloud administratorGTG-50014explicit1065
T1070.004Indicator Removal: File DeletionGTG-30006inferred257
T1078.004Valid Accounts: Cloud AccountsGTG-50021inferred453
T1091Replication Through Removable MediaGTG-30006inferred54
T1098.001Account Manipulation: Additional Cloud CredentialsGTG-50014explicit86
T1098.005Account Manipulation: Device RegistrationGTG-20006explicit99
T1102Web ServiceGTG-50014explicit428
T1102.002Web Service: Bidirectional CommunicationGTG-30006inferred414
T1110.002Brute Force: Password CrackingGTG-50014explicit33
T1113Screen CaptureGTG-30006inferred188
T1136Create AccountGTG-50029explicit91
T1176Browser ExtensionsGTG-34007explicit116
T1185Browser Session HijackingGTG-50029explicit111
T1189Drive-by CompromiseGTG-50029explicit381
T1195Supply Chain CompromiseGTG-50014inferred201
T1199Trusted RelationshipGTG-50014explicit360
T1204.002User Execution: Malicious FileGTG-50021explicit1307
T1213Data from Information RepositoriesGTG-50014inferred495
T1480Execution GuardrailsGTG-30006inferred34
T1485Data DestructionGTG-30006inferred216
T1496.004Resource Hijacking: Cloud Service HijackingGTG-50021inferred5
T1505Server Software ComponentGTG-50029explicit122
T1505.003Server Software Component: Web ShellGTG-50029explicit522
T1518.001Security Software DiscoveryGTG-30006inferred171
T1537Transfer Data to Cloud AccountGTG-50014explicit78
T1547.001Boot or Logon Autostart: Registry Run KeysGTG-30006inferred778
T1550.004Use Alternate Authentication Material: Web Session CookieGTG-50020explicit130
T1552.005Unsecured Credentials: Cloud Instance Metadata APIGTG-50014explicit96
T1553.005Subvert Trust Controls: Mark-of-the-Web BypassGTG-30006inferred51
T1555Credentials from Password StoresGTG-50021inferred224
T1555.004Credentials from Password Stores: Windows Credential ManagerGTG-30006inferred16
T1560Archive Collected DataGTG-50029explicit109
T1561Disk WipeGTG-30006inferred20
T1562.001Impair Defenses: Disable or Modify ToolsGTG-20006inferred236
T1564.003Hide Artifacts: Hidden WindowGTG-30006inferred85
T1566.002Phishing: Spearphishing LinkGTG-50020inferred773
T1566.004Phishing: Spearphishing VoiceGTG-50014explicit126
T1567Exfiltration Over Web ServiceGTG-50029inferred609
T1572Protocol TunnelingGTG-30006inferred376
T1583Acquire InfrastructureGTG-16012inferred103
T1583.003Acquire Infrastructure: Virtual Private ServerGTG-84005inferred59
T1583.004Acquire Infrastructure: ServerGTG-20006inferred43
T1583.006Acquire Infrastructure: Web ServicesGTG-15001inferred213
T1584Compromise InfrastructureGTG-50029explicit63
T1584.002Compromise Infrastructure: DNS ServerGTG-20006explicit10
T1588.006Obtain Capabilities: VulnerabilitiesGTG-30005explicit79
T1596Search Open Technical DatabasesGTG-30005explicit37
T1596.005Search Open Technical Databases: Scan DatabasesGTG-10007inferred24
T1597.002Search Closed Sources: Purchase Technical DataGTG-16012inferred5
T1606Forge Web CredentialsGTG-50014explicit65
T1627Execution GuardrailsGTG-15001inferred4
T1633Virtualization/Sandbox EvasionGTG-15001inferred2
T1636.003Protected User Data: Contact ListGTG-30006inferred28
T1636.004Protected User Data: SMS MessagesGTG-30006inferred35
T1650Acquire AccessGTG-50021explicit14
ATLASTechniqueCases
AML.T0040AI Model Inference API AccessGTG-04001, GTG-10007, GTG-14010, GTG-14021, GTG-14022, GTG-15001, GTG-16001, GTG-16002, GTG-16005, GTG-16008, GTG-16012, GTG-20006, GTG-24015, GTG-30005, GTG-30006, GTG-34001, GTG-50014, GTG-50020, GTG-50029, GTG-54002, GTG-54004, GTG-54006, GTG-54009, GTG-84002, GTG-84005, GTG-50021
AML.T0024.002GTG-16001, GTG-16002, GTG-16005, GTG-16006, GTG-16008, GTG-16012
AML.T0054LLM Jailbreak (task decomposition / fragmentation across sesGTG-14021, GTG-14022, GTG-16002, GTG-30006, GTG-84005
AML.T0034Cost HarvestingGTG-50014, GTG-50020, GTG-50029, GTG-50021
AML.T0055Unsecured CredentialsGTG-50014, GTG-50020, GTG-50029, GTG-50021
AML.T0017Develop CapabilitiesGTG-30004, GTG-30006, GTG-50027
AML.T0048External Harms: Financial HarmGTG-15001, GTG-54009, GTG-84005
AML.T0048.002External Harms: Societal HarmGTG-54002, GTG-84002, GTG-84006
AML.T0051LLM Prompt InjectionGTG-50014, GTG-50020, GTG-50021
AML.T0005GTG-16005, GTG-16006
AML.T0010AI Supply Chain CompromiseGTG-50020, GTG-50021
AML.T0012Valid AccountsGTG-50020, GTG-50021
AML.T0088Generate Deepfakes (AI-generated avatar imagery)GTG-15001, GTG-84006
AML.T0021GTG-16005
AML.T0047AI-Enabled Product or ServiceGTG-10007
AML.T0049Exploit Public-Facing ApplicationGTG-50020
AML.T0052Phishing (LLM-driven social engineering personas)GTG-15001
AML.T0057LLM Data LeakageGTG-50021

Entity graph: cases, actors, records and shared indicators

Rectangles are Anthropic's cases; circles are Threadlinqs records, shaded from pale violet (tier A) through B to deep violet (C), grey for records dated September 10, 2026 or later. Orange nodes are actors named in those records; small green nodes are indicators held before the report, linked only to pre-publication records. Tier D is left out. Grey nodes say nothing about lead time. An actor reached through a tier-C record is that record's actor, not the case's: the GTG-50014 path to ShinyHunters runs through technique parallels. Several distillation cases sharing the AA26-251A records (TL-2026-2405, TL-2026-2413) reflect one advisory naming several labs.

GTG-20006 GTG-20006 — Agentic Russian espionage and the CaptiveCrunch (Storm-2945) overlap TL-2026-0245 [A] DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors… UNC6353 actor: UNC6353 TL-2026-1808 [A] CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks… Storm-2945 actor: Storm-2945 TL-2026-1838 [A] CaptiveCrunch: Storm-2945 (Midnight Blizzard / APT29) compromises… Midnight Blizzard actor: Midnight Blizzard TL-2026-1853 [A] CaptiveCrunch: Russian SVR-Aligned Storm-2945 Hijacks Hotel Wi-Fi… UNC2452 actor: UNC2452 TL-2026-1857 [A] CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake… TL-2026-2091 [A] Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth… APT29 actor: APT29 TL-2026-2167 [A] Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth… TL-2026-0523 [C] Windows 'MiniPlasma' Zero-Day — Unpatched SYSTEM LPE via cldflt.sys… TL-2026-0561 [C] ROADtools Misuse in Cloud Intrusions — Nation-State Abuse of the… TL-2026-0943 [C] Microsoft Entra ID Device Code Phishing — OAuth 2.0 Device… Storm-2372 actor: Storm-2372 TL-2026-2170 [C] Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats… UNC5792 actor: UNC5792 TL-2026-2446 [DER] Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate… TL-2026-2466 [DER] Nation-State and Financially Motivated Actors Weaponize Claude AI… TL-2026-2559 [DER] AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade… TL-2026-2614 [DER] Microsoft-Led Coalition Takes Down EvilTokens AI-Powered… GTG-50014 GTG-50014 — Suspected ShinyHunters affiliates mining secrets at scale TL-2026-0411 [C] Bissa Scanner — AI-Assisted Mass Exploitation and Credential… TL-2026-0451 [C] Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM Access… TL-2026-0514 [C] NATS-as-C2: KeyHunter Distributed Worker Botnet Harvests Cloud… TL-2026-0527 [C] Grafana Labs Source Code Theft via Stolen GitHub Access Token… CoinbaseCartel actor: CoinbaseCartel TL-2026-1275 [C] ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce… ShinyHunters actor: ShinyHunters TL-2026-1288 [C] Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft… TL-2026-1705 [C] Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 2026 Data… TL-2026-1711 [C] ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift… TL-2026-2341 [C] Frontier AI Agents Compress Full Enterprise Intrusion Chain into… TL-2026-2339 [C] Coordinated GitHub API Enumeration and Access Token Abuse Campaign TL-2026-2390 [C] Autonomous AI-agent frameworks automating credential theft and cyber… TL-2026-2531 [DER] PhantomRaven: LLM-Generated npm Information Stealer Used for Bug… TL-2026-2564 [DER] France Dark Web Threat Landscape: Ransomware and Hacktivist Activity… TL-2026-2584 [DER] ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS… TL-2026-2620 [DER] ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft… TL-2026-2633 [DER] Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+… GTG-10007 GTG-10007 — A Chinese-speaking exploit foundry run by agent swarms TL-2026-0495 [C] GTIG AI Threat Tracker (May 2026) — First AI-Developed Zero-Day… APT27 actor: APT27 TL-2026-1354 [C] China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro… TL-2026-1885 [C] CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively… UNC5174 actor: UNC5174 TL-2026-1997 [C] China-Linked Actor Uses Autonomous AI Agent Frameworks (Hermes… TL-2026-2325 [C] Chinese-Speaking Operator Uses SecFlow AI Orchestration Framework… TL-2026-2576 [DER] LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working… TL-2026-2619 [DER] Chinese-Speaking Actor (Red Heron-Linked) Chains WordPress wp2shell… GTG-50029 GTG-50029 — A lone French-speaking hacktivist's WordPress breach-and-dox campaign TL-2026-0817 [C] ErrTraffic: ClickFix Malware-as-a-Service Distribution Framework… TL-2026-1978 [C] BdThemes WordPress Plugin Supply-Chain Attack Poisons API to Create… TL-2026-2639 [DER] Carbonato botnet: AI-agent-driven worm hijacks unauthenticated Docker… GTG-50021 GTG-50021 — Fake Claude resellers and the stolen-key economy TL-2026-0012 [C] LLMJacking: 175,000 Exposed Ollama AI Servers Targeted for Abuse TL-2026-0403 [C] Weaponizing Trust Signals: Claude Code Lures and GitHub Release… TL-2026-0546 [C] SEO Poisoning Campaign Impersonates Gemini CLI and Claude Code to… TL-2026-0582 [C] Solo operator — Solo Russian-Speaking Actor Operating Persistent… TL-2026-1522 [C] MetaChat Brand Impersonation Phishing Campaign Targets AI API Keys… TL-2026-1521 [C] Mass Phishing/Fraud Campaign Impersonating Anthropic Claude and… TL-2026-1845 [C] Fake AI Developer Tool Installers Delivering Infostealer via SEO… TL-2026-1911 [C] Token Jacking: Cybercriminals Steal and Resell AI API Keys/Tokens via… TL-2026-2257 [C] Commodity Infostealers Hijack Authenticated Claude Sessions to Drain… TL-2026-2416 [C] Infostealer Logs Expose Replayable AI Session Tokens and API Keys… TL-2026-2548 [DER] Fake ChatGPT Billing Email Phishing Campaign Abuses Google API… TL-2026-2626 [DER] Fake Claude Max Giveaway Phishing Campaign Uses… GTG-50020 GTG-50020 — A Russian-speaking crew moves from hotel-booking breaches to AI vendor keys TL-2026-0828 [C] BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling Large-Scale… TL-2026-1076 [C] AI Compute Hijacking: Stolen Ollama Server Wired Into Autonomous… TL-2026-2550 [DER] Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach… GTG-04001 GTG-04001 — Wagner-linked radio hub in Bangui used Claude to run a Russian influence… TL-2026-2631 [DER] Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI… TL-2026-2638 [DER] UK establishes National Centre for Information Defence to counter… GTG-54002 GTG-54002 — Fake local-news network Anthropic traces to LKM Company TL-2026-0760 [C] Houthi/Yemen-Based Disinformation & Influence Campaign Targeting… TL-2026-1356 [C] "Patriot Bait": Solo threat actor Runs 5-Year AI-Automated Telegram… GTG-84005 GTG-84005 — Malaysia election-manipulation platform Anthropic ties to BBS Bilisim GTG-24015 GTG-24015 — Claude used as a sub-editing desk for Russian state-media output aimed at… GTG-34001 GTG-34001 — Iranian state propaganda bodies use Claude to run 'soft war' influence campaigns TL-2026-2543 [DER] Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on… GTG-54006 GTG-54006 — Automated Bengali fake-news pipeline boosting the Awami League for rural… GTG-84006 GTG-84006 — Activist-impersonating agent platform Anthropic links to MEK/NCRI TL-2026-2526 [DER] Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN… TL-2026-2534 [DER] Chosen Brick: Iranian State-Backed Windows Surveillance Malware… GTG-54004 GTG-54004 — Single-operator Kenyan political astroturfing network using AI-written tweet… GTG-84002 GTG-84002 — UAE-linked AI persona drives anti-Muslim Brotherhood influence and UN lobbying… GTG-54009 GTG-54009 — Pilot surveillance platform profiling Iranian and Gulf social-media users… GTG-14021 GTG-14021 — PRC local security organs misuse Claude for "stability maintenance"… TL-2026-2520 [DER] BambooToken Malware Uses MQTT Protocol for Cross-Platform… TL-2026-2519 [DER] BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2… GTG-34007 GTG-34007 — Iranian security units building surveillance tooling TL-2026-1508 [C] GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled… APT28 actor: APT28 GTG-50027 GTG-50027 — Claude-built nationwide telecom interception platform ("Lakana 360") for Mali's… TL-2026-2609 [DER] Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US… TL-2026-2649 [DER] Nation-State Intrusions into Telecom Infrastructure via SS7, BGP… GTG-30004 GTG-30004 — Automated profiling and a modified NanoDump TL-2026-0076 [C] The Gentlemen Ransomware: Emerging Multi-Region Enterprise Threat… The Gentlemen actor: The Gentlemen GTG-30005 GTG-30005 — Open-source targeting of US naval forces TL-2026-1417 [C] Iran's AI-Enhanced Asymmetric Playbook: State Actors Integrate AI… APT42 actor: APT42 GTG-30006 GTG-30006 — An Iran-only surveillance toolkit built in fragments TL-2026-0159 [C] CRESCENTHARVEST — Iranian IRGC-Aligned Cyberespionage Campaign… TL-2026-2628 [DER] OAuth Token Theft via Sideloaded AppX Packages Abusing… GTG-15001 GTG-15001 — A dating-app network run mostly by AI personas TL-2026-0395 [C] FakeWallet iOS Crypto Stealer Campaign Delivered Through 26 Apple App… TL-2026-2591 [DER] FomoPeek iOS App Store Poisoning: Kernel Exploit Framework Steals… TL-2026-2655 [DER] Deceptive Android Apps Exploit Google Play Early Access to Reach… GTG-16005 GTG-16005 — Alibaba's forced-reasoning distillation, per Anthropic TL-2026-2405 [B] China-Based AI Companies Conducting Industrial-Scale Knowledge… TL-2026-2413 [B] China-Based AI Companies Conducting Industrial-Scale Distillation… TL-2026-0085 [C] APT31 Weaponizes Google Gemini AI for Automated Cyberattack Planning GTG-16002 GTG-16002 — Moonshot relays Kimi customers to Claude, per Anthropic GTG-16001 GTG-16001 — DeepSeek's covert relay and reasoning replay, per Anthropic GTG-16006 GTG-16006 — Zhipu (Z.ai) cleans harvested reasoning with Claude, per Anthropic TL-2026-2615 [DER] Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware… GTG-16008 GTG-16008 — Xiaomi replays real MiMo sessions to Claude, per Anthropic GTG-16012 GTG-16012 — GTG-16012 and GTG-16003 — SenseTime's bought transcripts and MiniMax's… cdncounter[.]net (domain) — GTG-20006 chamber-ua[.]org (domain) — GTG-20006 m365-owa[.]com (domain) — GTG-20006 ms365-device[.]com (domain) — GTG-20006 ms365-live[.]com (domain) — GTG-20006 my-invite[.]org (domain) — GTG-20006 owa-ms365[.]com (domain) — GTG-20006 statistic-ms[.]live (domain) — GTG-20006 wa-connect[.]eu (domain) — GTG-20006 wa-meeting[.]com (domain) — GTG-20006 static.cdncounter[.]net (hostname) — GTG-20006 213.145.86[.]112 (ipv4) — GTG-20006 31.57.243[.]154 (ipv4) — GTG-20006 38.146.28[.]132 (ipv4) — GTG-20006 38.146.28[.]75 (ipv4) — GTG-20006 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593 (sha256) — GTG-20006 be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c (sha256) — GTG-20006
Hover or tab to a node to highlight its links · drag to pan · Ctrl/⌘+scroll to zoom · click a record to open it
Anthropic caseThreadlinqs record (colour = tier)threat actorshared indicator

139 nodes, 238 links. The same case-to-record links are listed as text under each case section, and the shared indicators are in the indicator master table.

Defender playbook

  • Sweep the actor-controlled GTG-20006 rows first. Run the hunt pack sweeps over DNS, proxy and EDR logs: the 17 indicators public before the report, then the 23 Storm-2945 and UNC7005 indicators Anthropic did not list, such as wa-connect[.]net, globsec[.]net and 107.189.26[.]194 (TL-2026-2091, TL-2026-1838).
  • Retro-hunt the stale egress; don't block it. Search each "hunt" row within its own first- and last-seen dates (late February to mid-June); a match is a lead, not a verdict.
  • Hunt device-code phishing by behaviour. TL-2026-0943-KQL-003 (TL-2026-0943) flags Graph tokens used from an IP that never approved the code; limit the device-code flow with Conditional Access. Check new Entra device registrations for ROADtools defaults such as DESKTOP- plus an eight-character random suffix (TL-2026-0561).
  • Check travellers' laptops for the hotel Wi-Fi chain. Look for WPAD auto-proxy use on guest networks (DNS wpad lookups or DHCP option 252), ChocoShell's beacon path /t/pixel.gif and exfiltration path /t/event, and a CornFlake service named "Cloud Sync Service" (TL-2026-1808, TL-2026-1857).
  • Re-label projectnightcrawler[.]dev. A hit is not GTG-20006 C2, so keep it off espionage block lists (web filtering is a separate call); pair any unexpected hit with a hunt for MiniPlasma artefacts such as %LOCALAPPDATA%\MiniPlasma\placeholder.dat (TL-2026-0523).
  • Treat AI keys as credentials with a blast radius. Scan your apps, images and repos for secrets first: GTG-50014 ran TruffleHog over 1.8 million APKs, GTG-50029 a custom scanner over public containers. Alert on STS GetCallerIdentity then Bedrock use by one principal (TL-2026-0514-KQL-002, TL-2026-0514) and on Bedrock logging checks plus model enablement by one key (TL-2026-0012-SPL-002, TL-2026-0012).
  • Watch developer endpoints for fake AI clients. Hunt ClaudeCode_x64.exe and look-alike installers in user folders (TL-2026-0403, TL-2026-1845). If an infostealer hits a developer host, reimage it, then revoke AI sessions, rotate keys and check billing (TL-2026-2257, TL-2026-2416).
  • Close the WordPress persistence GTG-50029 used. Alert on new or changed files in wp-content/mu-plugins (TL-2026-0817-SPL-002; its KQL twin in TL-2026-0817 also requires a web-server process) and audit for hidden admin accounts (TL-2026-1978).
  • Trim our derivative rule. TL-2026-2466-SIG-003, from TL-2026-2466, our write-up of Anthropic's disclosure, rates five hunt-flagged GTG-50014 addresses (162.128.129[.]106, 185.65.134[.]246, 193.32.249[.]161, 45.148.10[.]242 and the VPS 195.178.110[.]131) critical with no expected false positives. If you copy it, keep its domains and three detect-or-block GTG-20006 addresses and move those five to a scheduled hunt.
  • Catch agentic recon on your hosts. TL-2026-2390-KQL-001 (TL-2026-2390) joins scanner processes and LLM API calls from one host within 15 minutes, no indicators needed.

SPL: DNS lookups of CaptiveCrunch Microsoft 365 lookalike domains

TL-2026-1857-SPL-001 · from TL-2026-1857 · Flags DNS resolution of Microsoft 365 lookalike names published for this case. ReliaQuest disclosed the activity on July 23, 2026 and Microsoft named it CaptiveCrunch on July 31; the rule dates from our August 4 record.

SPLindex=dns sourcetype=dns query IN ("ms365-device.com","ms365-live.com","m365-owa.com","owa-ms365.com") answer!="NXDOMAIN" answer!="0.0.0.0"
| stats count min(_time) as firstTime max(_time) as lastTime by src_ip,query,answer
| eval threat_name="CaptiveCrunch_Doppelganger_DNS",technique="T1557"
| convert ctime(firstTime) ctime(lastTime)
| table src_ip,query,answer,count,firstTime,lastTime
| sort - count

KQL: device-code token replayed to Microsoft Graph from a new IP

TL-2026-0943-KQL-003 · from TL-2026-0943 · Device-code phishing was the case's main access route. Flags Graph/Office token use from IPs where the user never approved the code; technique-level rule, independent of burned infrastructure.

KQLlet interactive = SigninLogs
    | where TimeGenerated > ago(24h)
    | where AuthenticationProtocol =~ "deviceCode" and ResultType == 0
    | summarize ApprovalIPs = make_set(IPAddress, 50) by UserPrincipalName;
union AADNonInteractiveUserSignInLogs, SigninLogs
| where TimeGenerated > ago(24h)
| where ResourceDisplayName == "Microsoft Graph" or AppId in ("04b07795-8ddb-461a-bbee-02f9e1bf7b46","d3590ed6-52b3-4102-aeff-aad2292ab01c")
| where ResultType == 0
| join kind=inner interactive on UserPrincipalName
| where ApprovalIPs !has IPAddress
| project TimeGenerated, UserPrincipalName, AppId, ResourceDisplayName, IPAddress, ApprovalIPs, AutonomousSystemNumber, Location
| order by TimeGenerated asc

KQL: SecFlow Claude/DeepSeek relay and SecBox C2 infrastructure hits

TL-2026-2325-KQL-003 · from TL-2026-2325 · Anthropic published no GTG-10007 indicators. This uses the closest analog instead: a Chinese-speaking operator driving Claude through niestools[.]com relays. It flags that operator's ten hosts, relay domain and C2 ports.

KQLlet KnownC2IPs = dynamic(["81.70.240.170","43.99.61.170","152.42.200.25","129.211.184.149","159.223.64.67","158.247.234.124","207.148.109.245","211.159.155.240","103.45.65.93","43.162.217.10"]);
DeviceNetworkEvents
| where Timestamp > ago(24h)
| where RemoteIP in (KnownC2IPs)
    or RemoteUrl has "niestools.com"
    or RemoteUrl has "trycloudflare.com"
    or RemotePort in (18000, 64288, 35888)
| extend C2Indicator = case(
    RemoteUrl has "niestools.com", "SecFlow-AI-Proxy-Relay",
    RemoteUrl has "trycloudflare.com", "SecBox-DeadDropResolver-Fallback",
    RemotePort == 35888, "SOCKS5-Exfil-Relay",
    "SecBox-Known-C2-Infra")
| summarize count(), Devices=make_set(DeviceName) by RemoteIP, RemoteUrl, RemotePort, C2Indicator

KQL: scanner tooling and LLM API calls from one host within 15 min

TL-2026-2390-KQL-001 · from TL-2026-2390 · Catches the continuous-recon loop on hosts you own: nmap, nuclei or sqlmap runs plus Claude, DeepSeek, OpenAI or Gemini API calls within 15 minutes. Still works after infrastructure is burned.

KQLlet scanner_procs = DeviceProcessEvents
| where TimeGenerated > ago(24h)
| where ProcessCommandLine has_any ("nmap", "masscan", "nuclei", "sqlmap", "rustscan", "zmap", "gobuster", "ffuf")
| project DeviceId, DeviceName, ProcTime = TimeGenerated, ProcessCommandLine, AccountName;
let llm_api_calls = DeviceNetworkEvents
| where TimeGenerated > ago(24h)
| where RemoteUrl has_any ("generativelanguage.googleapis.com", "api.anthropic.com", "api.openai.com", "api.deepseek.com")
| project DeviceId, DeviceName, NetTime = TimeGenerated, RemoteUrl;
scanner_procs
| join kind=inner llm_api_calls on DeviceId, DeviceName
| where abs(datetime_diff("second", NetTime, ProcTime)) <= 900
| project ProcTime, DeviceName, AccountName, ProcessCommandLine, RemoteUrl
| sort by ProcTime desc

Sigma: GTG-20006 and GTG-50014 domains, carding shop and addresses (after-report rule)

TL-2026-2466-SIG-003 · from TL-2026-2466 · The only Threadlinqs rule holding any GTG-50014 indicators, and it holds only some of them. It comes from our write-up of Anthropic's disclosure, so it adds nothing Anthropic did not publish.

Sigmatitle: Beacon to Known GTG-20006/GTG-50014 C2 and Carding Infrastructure
id: 4c3b2a1f-0e9d-4c7b-9a8f-6e5d4c3b2a10
status: experimental
description: Detects DNS/network connections to confirmed GTG-20006 and GTG-50014 attacker-controlled infrastructure.
references:
    - https://www.anthropic.com/threat-intelligence-report-september-2026
author: AII-Detector — ThreadLinqs Intelligence
date: 2026-09-12
tags:
    - attack.command-and-control
    - attack.exfiltration
    - attack.t1567
    - attack.t1584.002
    - attack.t1583.001
    - attack.tool.soraki
logsource:
    category: network_connection
detection:
    selection_domain:
        DestinationHostname|contains:
            - 'ms365-live.com'
            - 'owa-ms365.com'
            - 'teams.ms365-live.com'
            - 'updatebeacon.duckdns.org'
            - 'soraki.cc'
            - 'soraki.work'
            - 'policenationale.cc'
            - 'autoshop.policenationale.cc'
    selection_ip:
        DestinationIp:
            - '104.145.210.184'
            - '31.57.243.154'
            - '144.172.114.192'
            - '162.128.129.106'
            - '195.178.110.131'
            - '45.148.10.242'
            - '185.65.134.246'
            - '193.32.249.161'
    condition: selection_domain or selection_ip
falsepositives:
    - None expected — these are attacker-registered/attacker-controlled domains and egress IPs
level: critical

KQL: LLMjacking key check — STS GetCallerIdentity then Bedrock use

TL-2026-0514-KQL-002 · from TL-2026-0514 · Indicator-free: one principal calling STS GetCallerIdentity then Bedrock within five minutes, the test-then-use step behind the case's theft of AI keys. Prefer the SPL body; KQL needs UserIdentityArn.

KQL// KeyHunter / LLMjacking AWS validation chain: STS GetCallerIdentity -> Bedrock list/invoke within 5 min
let sts = AWSCloudTrail
  | where TimeGenerated > ago(24h)
  | where EventName == "GetCallerIdentity" and EventSource == "sts.amazonaws.com"
  | project sts_t=TimeGenerated, principal=tostring(parse_json(UserIdentity).arn), src_ip=SourceIpAddress, sts_region=AwsRegion;
let bedrock = AWSCloudTrail
  | where TimeGenerated > ago(24h)
  | where EventSource == "bedrock.amazonaws.com"
  | where EventName in ("ListFoundationModels","InvokeModel","InvokeModelWithResponseStream")
  | project br_t=TimeGenerated, principal=tostring(parse_json(UserIdentity).arn), br_src=SourceIpAddress, br_event=EventName, br_region=AwsRegion;
sts
| join kind=inner (bedrock) on principal
| where br_t between (sts_t .. sts_t + 5m)
| extend severity="High", threat="KeyHunter LLMjacking validation chain", mitre="T1526,T1580,T1496"
| project sts_t, principal, src_ip, br_src, br_event, br_region, severity, threat, mitre

KQL: fake Claude Code dropper ClaudeCode_x64.exe run from user folders

TL-2026-0403-KQL-001 · from TL-2026-0403 · No rule contains Anthropic's seven GTG-50021 indicators. This one matches a documented fake Claude Code binary that installs Vidar, the same fake-AI-client credential-theft vector the case describes.

KQLlet DropperNames = dynamic(["TradeAI.exe","ClaudeCode_x64.exe"]);
let UserPaths = dynamic([@"\Users\", @"\Temp\", @"\Downloads\", @"\AppData\"]);
DeviceProcessEvents
| where Timestamp > ago(24h)
| where FileName in~ (DropperNames)
| where FolderPath has_any (UserPaths)
| project Timestamp, DeviceName, AccountName, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256, MD5
| extend LureVariant = case(
    FileName =~ "TradeAI.exe", "TradeAI-rust-dropper",
    FileName =~ "ClaudeCode_x64.exe", "ClaudeCode_x64-rust-dropper",
    "unknown")
| order by Timestamp desc

SPL: Bedrock logging check and model enablement by one AWS key

TL-2026-0012-SPL-002 · from TL-2026-0012 · LLMjackers test stolen AWS keys by checking Bedrock invocation logging and switching models on. The rule groups those calls per key and flags multi-step chains, independent of reseller infrastructure.

SPLindex=aws sourcetype=aws:cloudtrail
| where eventSource="bedrock.amazonaws.com"
| where eventName IN ("GetModelInvocationLoggingConfiguration", "PutFoundationModelEntitlement", "PutUseCaseForModelAccess", "ListFoundationModels", "GetFoundationModelAvailability")
| eval action_type=case(
    eventName="GetModelInvocationLoggingConfiguration", "LOGGING_EVASION_CHECK",
    eventName="PutFoundationModelEntitlement", "MODEL_ACTIVATION",
    eventName="PutUseCaseForModelAccess", "USE_CASE_REGISTRATION",
    eventName="ListFoundationModels", "MODEL_ENUMERATION",
    eventName="GetFoundationModelAvailability", "AVAILABILITY_CHECK",
    1==1, "OTHER"
)
| eval severity=case(
    action_type="MODEL_ACTIVATION", "CRITICAL",
    action_type="LOGGING_EVASION_CHECK", "HIGH",
    action_type="USE_CASE_REGISTRATION", "HIGH",
    1==1, "MEDIUM"
)
| stats count as api_calls, values(action_type) as actions, values(eventName) as events, values(sourceIPAddress) as source_ips, values(awsRegion) as regions, earliest(_time) as first_call, latest(_time) as last_call by userIdentity.arn, userIdentity.accessKeyId
| where api_calls > 0
| eval recon_chain=if(mvcount(actions) >= 2, "MULTI-STEP RECON CHAIN", "SINGLE ACTION")
| table first_call, last_call, userIdentity.arn, userIdentity.accessKeyId, actions, events, source_ips, regions, api_calls, recon_chain, severity

KQL: VAPT exploit-pipeline marker strings in process command lines

TL-2026-1076-KQL-001 · from TL-2026-1076 · No rule holds this case's egress IPs. Near-zero-FP marker match for an autonomous exploit pipeline run on stolen AI inference, as GTG-50020 did; different operator (Sysdig VAPT).

KQLDeviceProcessEvents
| where Timestamp > ago(24h)
| where ProcessCommandLine has_any ("VAPTb3gin", "VAPTfin", "__VAPTCMD__")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName

SPL: machine-speed inference bursts against self-hosted LLM endpoints

TL-2026-1076-SPL-003 · from TL-2026-1076 · Catches machine-speed inference bursts from one source against your own self-hosted model endpoints: the footprint of an agent platform driving stolen or exposed compute.

SPLindex=web sourcetype="access_combined" uri_path="*/api/generate*" OR uri_path="*/api/chat*" OR uri_path="*/v1/completions*"
| bin _time span=5m
| stats count as request_count dc(uri_path) as endpoint_diversity by src_ip, _time
| where request_count > 60
| sort -request_count

SPL: known mu-plugin backdoor hashes, filenames and rogue WP admins

TL-2026-1978-SPL-002 · from TL-2026-1978 · No Threadlinqs rule contains Anthropic's 22 published indicators. This is the closest artifact match: known mu-plugin backdoor hashes and filenames plus rogue-admin creation, mirroring GTG-50029's WordPress persistence.

SPL(index=web sourcetype=access_combined uri_path="/wp-json/wp/v2/users" method=POST status=201)
OR (index=wordpress_audit sourcetype=wp_user_created (new_user_login="bd_*" OR new_user_email="*@wordpress.org" OR new_user_email="*@developer.wordpress.org"))
OR ((index=fim OR index=edr) md5 IN ("1024732009983dd5e54b4cf5593f04d4","7719cd98a35ffad2771f26d1ceab7d27","9aadc3e5c5242b273bd17c5bdc358845","e450ae5bc4bfc0d960dded06a76bb8e9"))
OR ((index=fim OR index=edr) (file_name="emer-run.php" OR file_path="*/wp-content/plugins/wp-smart-thumbnails/*" OR file_path="*/wp-content/mu-plugins/class-wp-token-validate.php" OR file_path="*/wp-content/mu-plugins/class-wp-query-*.php" OR file_path="*/wp-content/mu-plugins/wp-cache-optimizer.php"))
| eval detection_reason=case(
    match(uri_path, "wp-json/wp/v2/users"), "rest_api_user_creation",
    isnotnull(new_user_login), "rogue_admin_username_bd_prefix_or_spoofed_email",
    isnotnull(md5), "known_ioc_file_hash_match",
    1=1, "known_backdoor_filename_or_path")
| table _time, host, src_ip, new_user_login, new_user_email, uri_path, file_name, file_path, md5, detection_reason
| sort - _time

SPL: new or changed files in WordPress mu-plugins and theme functions.php (FIM)

TL-2026-0817-SPL-002 · from TL-2026-0817 · Fires on file-integrity create or modify events in wp-content/mu-plugins or a theme's functions.php, plus theme-editor POSTs. Its KQL twin adds the web-server-process check. That is where a credential-harvesting mu-plugin would land.

SPL(index=web sourcetype=access_combined uri_path="/wp-admin/theme-editor.php" (method=POST OR uri_query="*functions.php*"))
OR (index=linux sourcetype="fim:filechange" (object_path="*/wp-content/mu-plugins/*" OR object_path="*/themes/*/functions.php" OR object_path="*styIe.php*" OR object_path="*session-manager.php*") action IN ("created","modified"))
OR (index=web sourcetype=access_combined (header_x_wp_session=* OR uri_query="*key=*" header_user_agent IN ("*WPScan*","*Nikto*")))
| stats count values(uri_path) as uris values(object_path) as files values(action) as fileactions min(_time) as firstSeen by host src_ip
| where count > 0
| `ctime(firstSeen)`
| table host src_ip count uris files fileactions firstSeen

Indicator master table

The master table lists every hunt pack row, defanged; the CSV is refanged. For Anthropic's 209 rows, status says what we held and when: 17 were in the corpus before September 10, 2026, 15 appear only in our write-ups of the disclosure, 1 is a researcher's server we mark context-only, 1 sits only inside a hosting range we documented, and 175 match nothing. Our 23 added rows name their vendor cluster, not GTG-20006. Role carries Anthropic's handling flag and our stale marker. Account rows are Anthropic's attribution: accounts get bought, hijacked or reassigned, and a name-like handle does not identify a real person. We also checked the 33 indicators printed only in the PDF; none matched actor infrastructure in our corpus.

232 of 232 rows shown
GTG-20006 domain ad-g[.]org not in corpus c2 · detect-or-block
GTG-20006 domain cdncounter[.]net held before 09-10 TL-2026-0245 infrastructure · detect-or-block
GTG-20006 domain chamber-ua[.]org held before 09-10 TL-2026-2091 TL-2026-2167 phishing · detect-or-block
GTG-20006 domain chathamhouse[.]eu not in corpus phishing · detect-or-block
GTG-20006 domain docs-viewer[.]org not in corpus c2 · detect-or-block
GTG-20006 domain itechx[.]tel not in corpus infrastructure · detect-or-block
GTG-20006 domain m365-owa[.]com held before 09-10 TL-2026-1808 TL-2026-1838 TL-2026-1853 +4 phishing · detect-or-block
GTG-20006 domain meridian-protocol[.]org not in corpus infrastructure · detect-or-block
GTG-20006 domain meridiangroup-corp[.]com not in corpus infrastructure · detect-or-block
GTG-20006 domain metricwave[.]org not in corpus infrastructure · detect-or-block
GTG-20006 domain mgsend[.]org not in corpus infrastructure · detect-or-block
GTG-20006 domain ms365-device[.]com held before 09-10 TL-2026-1808 TL-2026-1838 TL-2026-1853 +4 phishing · detect-or-block
GTG-20006 domain ms365-live[.]com held before 09-10 TL-2026-1808 TL-2026-1838 TL-2026-1853 +4 phishing · detect-or-block
GTG-20006 domain my-invite[.]org held before 09-10 TL-2026-2091 TL-2026-2167 phishing · detect-or-block
GTG-20006 domain mygreatmarket[.]com not in corpus c2 · detect-or-block
GTG-20006 domain mygreatmarket[.]org not in corpus c2 · detect-or-block
GTG-20006 domain owa-ms365[.]com held before 09-10 TL-2026-1808 TL-2026-1838 TL-2026-1853 +5 phishing · detect-or-block
GTG-20006 domain projectnightcrawler[.]dev context only TL-2026-0835 TL-2026-1339 TL-2026-1351 +8 infrastructure · detect-or-block
GTG-20006 domain russianearabroad[.]com not in corpus phishing · detect-or-block
GTG-20006 domain russianearabroad[.]org not in corpus infrastructure · detect-or-block
GTG-20006 domain static-ms[.]live not in corpus infrastructure · detect-or-block
GTG-20006 domain statistic-ms[.]live held before 09-10 TL-2026-2091 TL-2026-2167 c2 · detect-or-block
GTG-20006 domain stuseamandesilt[.]org not in corpus infrastructure · detect-or-block
GTG-20006 domain ukrinform-share[.]net not in corpus phishing · detect-or-block
GTG-20006 domain wa-connect[.]eu held before 09-10 TL-2026-2091 c2 · detect-or-block
GTG-20006 domain wa-meeting[.]com held before 09-10 TL-2026-2091 phishing · detect-or-block
GTG-20006 email anna.manager@russianearabroad[.]net not in corpus phishing · detect-or-block
GTG-20006 email events@embassy-protocol[.]int not in corpus phishing · detect-or-block
GTG-20006 filename WUEngine.exe not in corpus malware · detect-or-block
GTG-20006 filename client_20260507093021_4286d211_x64.exe not in corpus malware · detect-or-block
GTG-20006 filename fix_network.apk not in corpus malware · detect-or-block
GTG-20006 filename msedgeupdate_v3.exe not in corpus malware · detect-or-block
GTG-20006 hostname api.stuseamandesilt[.]org not in corpus c2 · detect-or-block
GTG-20006 hostname cdn.stuseamandesilt[.]org not in corpus malware_delivery · detect-or-block
GTG-20006 hostname mslivetest.duckdns[.]org not in corpus c2 · detect-or-block
GTG-20006 hostname pdfviewer2024.b-cdn[.]net not in corpus malware_delivery · detect-or-block
GTG-20006 hostname static.cdncounter[.]net held before 09-10 TL-2026-0245 malware_delivery · detect-or-block
GTG-20006 hostname teams.ms365-live[.]com added after report TL-2026-2446 TL-2026-2466 phishing · detect-or-block
GTG-20006 hostname update.stuseamandesilt[.]org not in corpus malware_delivery · detect-or-block
GTG-20006 ipv4 104.145.210[.]184 added after report TL-2026-2446 TL-2026-2466 phishing · detect-or-block
GTG-20006 ipv4 104.194.149[.]228 not in corpus phishing · detect-or-block
GTG-20006 ipv4 104.194.151[.]133 not in corpus c2 · detect-or-block
GTG-20006 ipv4 104.194.159[.]55 not in corpus c2 · detect-or-block
GTG-20006 ipv4 144.172.114[.]192 added after report TL-2026-2466 c2 · detect-or-block
GTG-20006 ipv4 148.135.195[.]111 not in corpus c2 · detect-or-block
GTG-20006 ipv4 149.54.42[.]106 not in corpus infrastructure · detect-or-block
GTG-20006 ipv4 185.198.234[.]101 not in corpus c2 · detect-or-block
GTG-20006 ipv4 185.198.234[.]26 not in corpus infrastructure · detect-or-block
GTG-20006 ipv4 2.26.53[.]194 not in corpus infrastructure · detect-or-block
GTG-20006 ipv4 213.145.86[.]112 held before 09-10 TL-2026-1808 TL-2026-1838 TL-2026-1853 +3 infrastructure · detect-or-block
GTG-20006 ipv4 31.57.243[.]154 held before 09-10 TL-2026-1808 TL-2026-1838 TL-2026-1853 +4 phishing · detect-or-block
GTG-20006 ipv4 38.146.28[.]132 held before 09-10 TL-2026-1808 TL-2026-1838 TL-2026-1853 +3 infrastructure · detect-or-block
GTG-20006 ipv4 38.146.28[.]75 held before 09-10 TL-2026-1808 TL-2026-1838 TL-2026-1853 +3 infrastructure · detect-or-block
GTG-20006 sha256 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593 held before 09-10 TL-2026-1808 TL-2026-1838 TL-2026-1853 +4 malware · detect-or-block
GTG-20006 sha256 be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c held before 09-10 TL-2026-1808 TL-2026-1838 TL-2026-1853 +5 malware · detect-or-block
GTG-50014 account https[:]//t[.]me/Soraki_Bot not in corpus monetization · detect-or-block
GTG-50014 domain ari-chain[.]com not in corpus phishing · detect-or-block
GTG-50014 domain arichain[.]network not in corpus phishing · detect-or-block
GTG-50014 domain bitmart-mystery[.]com not in corpus phishing · detect-or-block
GTG-50014 domain defi-claim[.]xyz not in corpus phishing · detect-or-block
GTG-50014 domain emailsecure[.]email not in corpus phishing · detect-or-block
GTG-50014 domain mozilla[.]ws not in corpus phishing · detect-or-block
GTG-50014 domain on-pssword[.]com not in corpus phishing · detect-or-block
GTG-50014 domain policenationale[.]cc added after report TL-2026-2466 monetization · detect-or-block
GTG-50014 domain service-infos[.]info not in corpus phishing · detect-or-block
GTG-50014 domain signin-1psswoord[.]com not in corpus phishing · detect-or-block
GTG-50014 domain soraki[.]cc added after report TL-2026-2466 monetization · detect-or-block
GTG-50014 domain soraki[.]work added after report TL-2026-2466 infrastructure · detect-or-block
GTG-50014 hostname autoshop.policenationale[.]cc added after report TL-2026-2466 monetization · detect-or-block
GTG-50014 hostname esvfecawvjmchjslqyemho2fiduc59wzn.oast[.]fun not in corpus infrastructure · detect-or-block
GTG-50014 hostname soraki-proxy.20245aad98d27b1b1a2f0f103e1d7ee0.workers[.]dev not in corpus infrastructure · detect-or-block
GTG-50014 hostname updatebeacon.duckdns[.]org added after report TL-2026-2466 c2 · detect-or-block
GTG-50014 ipv4 104.193.135[.]207 not in corpus egress · hunt · stale 2026-04-05 → 2026-04-05
GTG-50014 ipv4 104.36.50[.]54 not in corpus egress · hunt · stale 2026-04-24 → 2026-04-24
GTG-50014 ipv4 162.128.129[.]106 added after report TL-2026-2466 egress · hunt · stale 2026-02-20 → 2026-03-10
GTG-50014 ipv4 176.177.12[.]62 not in corpus egress · hunt · stale 2026-04-19 → 2026-04-20
GTG-50014 ipv4 185.65.134[.]199 not in corpus egress · hunt · stale 2026-04-19 → 2026-04-28
GTG-50014 ipv4 185.65.134[.]246 added after report TL-2026-2466 egress · hunt · stale 2026-04-19 → 2026-05-04
GTG-50014 ipv4 193.32.249[.]161 added after report TL-2026-2466 egress · hunt · stale 2026-03-21 → 2026-04-18
GTG-50014 ipv4 193.32.249[.]164 not in corpus egress · hunt · stale 2026-04-18 → 2026-05-06
GTG-50014 ipv4 193.32.249[.]170 not in corpus egress · hunt · stale 2026-03-20 → 2026-04-06
GTG-50014 ipv4 195.178.110[.]131 added after report TL-2026-2466 infrastructure · hunt · stale 2026-03-12 → 2026-04-30
GTG-50014 ipv4 45.148.10[.]242 added after report TL-2026-2466 egress · hunt · stale 2026-04-06 → 2026-04-27
GTG-50014 ipv4 91.171.138[.]169 not in corpus egress · hunt · stale 2026-04-19 → 2026-04-21
GTG-50014 ipv4 92.118.39[.]3 not in corpus egress · hunt · stale 2026-04-10 → 2026-04-19
GTG-50014 ipv6 2a01:e0a:2e2:aa40:b15d:5d28:6f4a[:]8d53 not in corpus egress · hunt · stale 2026-04-20 → 2026-04-21
GTG-50014 ipv6 2a04:cec0:1185:34f2:a150:7081:caed[:]448e not in corpus egress · hunt · stale 2026-04-06 → 2026-04-07
GTG-50014 telegram_bot_id 8628746407 not in corpus infrastructure · detect-or-block
GTG-50014 telegram_bot_id 8632748474 not in corpus exfiltration · detect-or-block
GTG-50014 telegram_bot_id 8664033117 not in corpus exfiltration · detect-or-block
GTG-50014 telegram_bot_id 8709258476 not in corpus infrastructure · detect-or-block
GTG-50014 telegram_chat_id -1003311614569 added after report TL-2026-2466 exfiltration · detect-or-block
GTG-50014 telegram_chat_id -1003893854338 added after report TL-2026-2466 exfiltration · detect-or-block
GTG-50014 telegram_user_id 8179098353 not in corpus infrastructure · detect-or-block
GTG-50014 url https[:]//s3.eu-central-1.s4.mega[.]io/fuckyoubasil/ not in corpus exfiltration · detect-or-block
GTG-50020 ipv4 141.133.125[.]208 not in corpus egress · hunt · stale 2026-05-21 → 2026-05-23
GTG-50020 ipv4 146.103.101[.]253 not in corpus egress · hunt · stale 2026-05-21 → 2026-06-13
GTG-50020 ipv4 146.103.97[.]169 not in corpus egress · hunt · stale 2026-05-21 → 2026-05-25
GTG-50020 ipv4 167.250.111[.]136 not in corpus egress · hunt · stale 2026-05-23 → 2026-06-03
GTG-50020 ipv4 178.16.54[.]141 related only related: TL-2026-0617 egress · hunt · stale 2026-05-21 → 2026-06-16
GTG-50020 ipv4 194.163.183[.]216 not in corpus egress · hunt · stale 2026-05-23 → 2026-05-24
GTG-50020 ipv4 202.66.167[.]230 not in corpus egress · hunt · stale 2026-05-21 → 2026-06-04
GTG-50020 ipv4 37.27.103[.]22 not in corpus egress · hunt · stale 2026-05-26 → 2026-06-13
GTG-50021 domain aws-us-east-3[.]com not in corpus infrastructure · detect-or-block
GTG-50021 domain awstore[.]cloud not in corpus monetization · detect-or-block
GTG-50021 domain holdboost[.]store not in corpus c2 · detect-or-block
GTG-50021 domain kiro[.]cheap not in corpus monetization · detect-or-block
GTG-50021 domain sys-tools[.]cfd not in corpus c2 · detect-or-block
GTG-50021 hostname iymkjuzymkapovrntoxy.supabase[.]co not in corpus c2 · detect-or-block
GTG-50029 domain fafwatch[.]xyz not in corpus infrastructure · detect-or-block 2026-04
GTG-50029 domain prod-artfkt[.]com not in corpus infrastructure · detect-or-block 2026-04
GTG-50029 hostname frntrs-analytics-863060591218.europe-west1.run[.]app not in corpus c2 · detect-or-block · stale 2026-05-13 → 2026-06
GTG-50029 hostname frntrs-analytics.dedyn[.]io not in corpus c2 · detect-or-block · stale 2026-05-13 → 2026-06
GTG-50029 ipv4 103.124.165[.]199 not in corpus egress · hunt · stale 2026-03-25 → 2026-05-20
GTG-50029 ipv4 103.141.60[.]144 not in corpus egress · hunt · stale 2026-03-25 → 2026-05-20
GTG-50029 ipv4 103.216.220[.]19 not in corpus egress · hunt · stale 2026-03-25 → 2026-05-20
GTG-50029 ipv4 136.144.242[.]56 not in corpus staging · detect-or-block · stale 2026-05-17 → 2026-05-21
GTG-50029 ipv4 138.199.6[.]208 not in corpus egress · hunt · stale 2026-03-25 → 2026-05-20
GTG-50029 ipv4 138.199.60[.]29 not in corpus egress · hunt · stale 2026-03-25 → 2026-05-20
GTG-50029 ipv4 139.59.2[.]243 not in corpus key_validation · detect-or-block · stale 2026-02-06 → 2026-06-12
GTG-50029 ipv4 146.70.116[.]131 not in corpus egress · hunt · stale 2026-03-25 → 2026-05-20
GTG-50029 ipv4 149.22.83[.]6 not in corpus egress · hunt · stale 2026-03-25 → 2026-05-20
GTG-50029 ipv4 158.173.46[.]118 not in corpus egress · hunt · stale 2026-03-25 → 2026-05-20
GTG-50029 ipv4 163.172.157[.]53 not in corpus dedicated_server · detect-or-block · stale 2026-06-26 → 2026-07-04
GTG-50029 ipv4 34.156.199[.]132 not in corpus exfiltration · hunt · stale 2026-04 → 2026-05
GTG-50029 ipv4 34.156.95[.]176 not in corpus exfiltration · hunt · stale 2026-04 → 2026-05
GTG-50029 ipv6 2001:ac8:27[:]89::a02d not in corpus egress · hunt · stale 2026-03-25 → 2026-05-20
GTG-50029 ipv6 2001:ac8:29[:]84::a01d not in corpus egress · hunt · stale 2026-03-25 → 2026-05-20
GTG-50029 ipv6 2001:bc8:711:5854:dc00:1ff:fe18[:]ba53 not in corpus dedicated_server · detect-or-block · stale 2026-06-26 → 2026-07-04
GTG-50029 onion 3ell6n47y3ct4a3x67fbuz62q2mk2l4vo6eacho2suzftdshsnrfopyd[.]onion not in corpus infrastructure · detect-or-block · stale 2026-05 → 2026-07
GTG-50029 onion 6mshbvhvzhdgumwwazf4jcep2xx4kdk6n4wgffc46msu2gc3j3t2fpad[.]onion not in corpus infrastructure · detect-or-block · stale 2026-06 → 2026-06
GTG-24015 account https[:]//t[.]me/ATodaPotencia not in corpus amplification · detect-or-block
GTG-54002 account https[:]//x[.]com/AxumVoices not in corpus fabricated_outlet · detect-or-block
GTG-54002 account https[:]//x[.]com/Civicpulsemedia not in corpus fabricated_outlet · detect-or-block
GTG-54002 account https[:]//x[.]com/Fiftystatesnews not in corpus fabricated_outlet · detect-or-block
GTG-54002 account https[:]//x[.]com/Naijapulse_ not in corpus fabricated_outlet · detect-or-block
GTG-54002 account https[:]//x[.]com/PSarzameeninfo not in corpus fabricated_outlet · detect-or-block
GTG-54002 account https[:]//x[.]com/RussianWayMedia not in corpus fabricated_outlet · detect-or-block
GTG-54002 account https[:]//x[.]com/berlin_echo not in corpus fabricated_outlet · detect-or-block
GTG-54002 account https[:]//x[.]com/britishdaily_ not in corpus fabricated_outlet · detect-or-block
GTG-54002 account https[:]//x[.]com/cmwthpost not in corpus fabricated_outlet · detect-or-block
GTG-54002 account https[:]//x[.]com/elpulsopopular not in corpus fabricated_outlet · detect-or-block
GTG-54002 account https[:]//x[.]com/fuxingmedia not in corpus fabricated_outlet · detect-or-block
GTG-54002 account https[:]//x[.]com/journaljambo not in corpus fabricated_outlet · detect-or-block
GTG-54002 account https[:]//x[.]com/saudinews966 not in corpus fabricated_outlet · detect-or-block
GTG-54002 account https[:]//x[.]com/zionpulse not in corpus fabricated_outlet · detect-or-block
GTG-54002 domain alwatanalakbar[.]com not in corpus fabricated_outlet · detect-or-block
GTG-54002 domain axumvoices[.]org not in corpus fabricated_outlet · detect-or-block
GTG-54002 domain british-daily[.]com not in corpus fabricated_outlet · detect-or-block
GTG-54002 domain civicpulse[.]info not in corpus fabricated_outlet · detect-or-block
GTG-54002 domain commonwealth-post[.]com not in corpus fabricated_outlet · detect-or-block
GTG-54002 domain echoberlin[.]info not in corpus fabricated_outlet · detect-or-block
GTG-54002 domain elpulsopopular[.]com not in corpus fabricated_outlet · detect-or-block
GTG-54002 domain fiftystates[.]news not in corpus fabricated_outlet · detect-or-block
GTG-54002 domain jambojournal[.]org not in corpus fabricated_outlet · detect-or-block
GTG-54002 domain naijapulse[.]org not in corpus fabricated_outlet · detect-or-block
GTG-54002 domain pakssarzameen[.]org not in corpus fabricated_outlet · detect-or-block
GTG-54002 domain russianway[.]info not in corpus fabricated_outlet · detect-or-block
GTG-54002 domain voiceoftherejuvenation[.]com not in corpus fabricated_outlet · detect-or-block
GTG-54002 domain zion-pulse[.]com not in corpus fabricated_outlet · detect-or-block
GTG-84005 account https[:]//www.youtube[.]com/@malaysiapulseof not in corpus fabricated_outlet · detect-or-block
GTG-84005 account https[:]//x[.]com/Chikmore not in corpus persona · detect-or-block 2026-05-17
GTG-84005 account https[:]//x[.]com/SHIHAN1947 not in corpus persona · detect-or-block 2026-05-17
GTG-84005 account https[:]//x[.]com/adriansantodo not in corpus persona · detect-or-block 2026-05-17
GTG-84005 account https[:]//x[.]com/armsam1209 not in corpus persona · detect-or-block 2026-05-17
GTG-84005 account https[:]//x[.]com/avihoue not in corpus persona · detect-or-block 2026-05-17
GTG-84005 account https[:]//x[.]com/bmmyangels not in corpus persona · detect-or-block 2026-05-17
GTG-84005 account https[:]//x[.]com/exceiivier not in corpus persona · detect-or-block 2026-05-17
GTG-84005 account https[:]//x[.]com/garyponce not in corpus persona · detect-or-block 2026-05-17
GTG-84005 account https[:]//x[.]com/goldsteve1 not in corpus persona · detect-or-block 2026-05-17
GTG-84005 account https[:]//x[.]com/hugolaurent not in corpus persona · detect-or-block 2026-05-17
GTG-84005 account https[:]//x[.]com/kioskou not in corpus persona · detect-or-block 2026-05-17
GTG-84005 account https[:]//x[.]com/telkisoszoba not in corpus persona · detect-or-block 2026-05-17
GTG-84005 domain malaysiapulse[.]com not in corpus fabricated_outlet · detect-or-block 2026-05-10
GTG-84005 domain bbsteknoloji[.]com not in corpus infrastructure · detect-or-block
GTG-84005 ipv4 157.180.93[.]7 not in corpus infrastructure · detect-or-block
GTG-84005 ipv4 167.235.157[.]100 not in corpus infrastructure · detect-or-block
GTG-84005 ipv4 23.88.118[.]216 not in corpus infrastructure · detect-or-block
GTG-84005 ipv4 46.225.91[.]180 not in corpus infrastructure · detect-or-block
GTG-84005 ipv4 46.62.214[.]3 not in corpus infrastructure · detect-or-block
GTG-84005 ipv4 91.99.117[.]166 not in corpus infrastructure · detect-or-block
GTG-84006 account https[:]//www.instagram[.]com/fwr.ir not in corpus persona · detect-or-block
GTG-84006 account https[:]//t[.]me/FWR_ir not in corpus persona · detect-or-block
GTG-84006 account https[:]//t[.]me/anti_silent not in corpus persona · detect-or-block
GTG-84006 account https[:]//www.instagram[.]com/faryade_mamnoo not in corpus amplification · detect-or-block
GTG-84006 account https[:]//www.instagram[.]com/iranpayam_tehran5 not in corpus amplification · detect-or-block
GTG-84006 account https[:]//www.instagram[.]com/javanane_shargt not in corpus amplification · detect-or-block
GTG-84006 account https[:]//www.instagram[.]com/khabar_fouri_mardom not in corpus amplification · detect-or-block
GTG-84006 account https[:]//www.instagram[.]com/tehranchekhabar19 not in corpus fabricated_outlet · detect-or-block
GTG-84006 account https[:]//www.instagram[.]com/jomhouri_democratic not in corpus amplification · detect-or-block
GTG-84006 account https[:]//t[.]me/jomhouri_democratic not in corpus amplification · detect-or-block
GTG-30006 android_package com.app.safeguard not in corpus malware · detect-or-block
GTG-30006 filename fontdrivehost.exe not in corpus persistence · detect-or-block
GTG-30006 filename telegram_listener_v12_2.vbs not in corpus malware · detect-or-block
GTG-30006 filepath C:\ProgramData\fontdrivehostServicePackages\drv3060nt10-69s64mmm\fontdrivehost.exe not in corpus persistence · detect-or-block
GTG-30006 scheduled_task Calc_AdminTask not in corpus persistence · detect-or-block
GTG-30006 scheduled_task SECOMS64_AdminTask not in corpus persistence · detect-or-block
GTG-30006 telegram_chat_id -1003197249446 not in corpus c2 · detect-or-block
GTG-30006 telegram_chat_id -1003233252 not in corpus c2 · detect-or-block
GTG-30006 telegram_chat_id -10078223223323 not in corpus c2 · detect-or-block
GTG-30006 telegram_chat_id 7828288328 not in corpus c2 · detect-or-block
GTG-15001 app_id com.cavalier.nalo not in corpus scam_app · detect-or-block
GTG-15001 app_id com.qiga.vio not in corpus scam_app · detect-or-block
GTG-15001 domain archat[.]us not in corpus infrastructure · detect-or-block
GTG-15001 domain heyhru[.]com not in corpus infrastructure · detect-or-block
GTG-15001 domain sitin[.]ai not in corpus infrastructure · detect-or-block
GTG-15001 hostname file.archat[.]us not in corpus infrastructure · detect-or-block
GTG-15001 hostname managedkafka.heyhru-server.cloud[.]goog not in corpus infrastructure · detect-or-block
GTG-15001 ipv4 38.129.138[.]244 not in corpus egress · hunt · stale 2026-04 → 2026-04
Storm-2945 (Microsoft) ipv4 104.194.159[.]150 Threadlinqs extra TL-2026-1808 2026-07-31
Storm-2945 (Microsoft) ipv4 107.189.26[.]194 Threadlinqs extra TL-2026-1838 2026-08-03
Storm-2945 (Microsoft) url hxxps://213.145.86[.]112/t/pixel.gif?m= Threadlinqs extra TL-2026-1857 2026-08-04
Storm-2945 (Microsoft) url hxxps://213.145.86[.]112/cdn/chunks/polyfill-7e2b.min.js Threadlinqs extra TL-2026-1857 2026-08-04
Storm-2945 (Microsoft) url hxxps://213.145.86[.]112/t/event Threadlinqs extra TL-2026-1857 2026-08-04
UNC7005 (Google) domain wa-connect[.]net Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) domain wa-invite[.]com Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) domain wa-device[.]com Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) domain shopinvite[.]org Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) domain globsec[.]net Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) domain finishoperations[.]com Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) domain finishoperations[.]org Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) domain foc-share[.]com Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) domain share-foc[.]com Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) domain internal-share[.]com Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) domain foc-share[.]org Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) ipv4 107.189.18[.]7 Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) sha256 1d9299799a7b8da67c44ebec064d64542c27645f8e84de4a22ca3f6cbc843e3c Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) sha256 c5826032207d623a7f6caec8465af7364eccc355f9a48897da2a54f3e4420265 Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) sha256 125752ad7c20d715920a3b2fb0fdde660f07b3f2b053665cf38c2d6d9de86e1e Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) sha256 403b624e35777cbc07dbe66398b21bba70396a20b859c880732338ce1dd1f41f Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) sha256 a06a8fd1b6fa1924199a4540cf16d089217ce8f78c617739946f145fd1fc88c1 Threadlinqs extra TL-2026-2091 2026-08-21
UNC7005 (Google) sha256 5b8d50c2e8cc3038b7c6e6dbf1219f6e814930a1e3c0053143a1191ae67f8ffc Threadlinqs extra TL-2026-2091 2026-08-21

Indicators are shown defanged. "Stale" means Anthropic's last-seen date is more than 60 days before publication, so expect rotation. The role and handling columns are Anthropic's labels; "hunt" is the handling flag Anthropic puts on 36 rows, mostly attacker egress addresses, so search logs for them rather than blocking. The CSV holds the refanged values plus every column shown here.

Frequently asked questions

What did Anthropic's September 2026 AI misuse report find, and how much was already known?

Anthropic's "Detecting and countering misuse of AI: September 2026", published September 10, 2026, covers 43 case studies with 209 indicators in a CSV. Threadlinqs held 17 of them beforehand, all from GTG-20006, while 175 match nothing in our corpus. Of the 32 GTG case groups plus the weapons and biology rows, 21 had technique-level or stronger prior coverage and the other 13 only related context.

What is GTG-20006, and how does it relate to CaptiveCrunch and Storm-2945?

GTG-20006, a Russian-nexus espionage cluster in Anthropic's September 10, 2026 report, used Claude Code agents to automate much of its operation, even rebuilding malware that security products caught PDF pp. 6–7. Anthropic's attribution points to Midnight Blizzard. For hunters, what matters is infrastructure: its lookalike Microsoft domains, addresses and malware hashes match ReliaQuest's and Microsoft's CaptiveCrunch reporting on Storm-2945 (TL-2026-1808) and Google's UNC7005 reporting (TL-2026-2091). Overlap does not put every workstream in those clusters.

Which Anthropic indicators were already in Threadlinqs before the report?

Of Anthropic's 209 CSV indicators, 17 sat in 7 earlier Threadlinqs records, all from GTG-20006: CaptiveCrunch domains, addresses and hashes (via ReliaQuest and Microsoft, held since July 31, 2026), UNC7005 domains such as chamber-ua[.]org (via Google, since August 21, 2026) and cdncounter[.]net with its static host (Google's DarkSword reporting, since March 18, 2026, TL-2026-0245). Earlier records also held projectnightcrawler[.]dev, a researcher's server we mark context-only. Another 15 appear only in our write-ups of the report.

Is ShinyHunters behind GTG-50014?

Anthropic's September 2026 AI misuse report calls GTG-50014 suspected ShinyHunters affiliates and cites no outside source. Threadlinqs can neither confirm nor refute that: no record written before September 10, 2026 holds an actor-controlled GTG-50014 indicator, and the exact matches sit only in our write-up of the disclosure (TL-2026-2466). Beyond that we hold only collective-level parallels, such as ShinyHunters' abuse of SaaS integration tokens for data theft and extortion, reported under UNC6040 (TL-2026-1275).

How do I hunt for the report's indicators in Splunk or Sentinel?

Threadlinqs publishes the 209 indicators from Anthropic's September 2026 AI misuse report as a refanged CSV and a STIX 2.1 bundle in the hunt pack. In Splunk, upload the CSV as lookup file threadlinqs_anthropic_ai_misuse_2026_09.csv and run the SPL over proxy, DNS and network logs; in Sentinel, the KQL pulls it with externaldata, and a host sweep covers files, tasks and senders. Treat detect-or-block hits as urgent and hunt hits as leads.

Should I block the egress IPs in Anthropic's CSV?

No. Anthropic's September 2026 CSV flags its egress addresses as hunt, not detect-or-block. It gives no reason, but where it describes them, as for GTG-50029, they are commercial VPN or datacentre exits other people share, and every hunt-flagged row was last seen over 60 days before publication. Search old logs in each row's date window instead. Our derivative Sigma rule in TL-2026-2466 rates five such addresses critical; demote them to a hunt.

Is projectnightcrawler[.]dev attacker infrastructure?

Probably not. Anthropic's September 2026 CSV lists it under GTG-20006 as operator or lure infrastructure, but earlier Threadlinqs records (TL-2026-0835, TL-2026-1865) describe a researcher's self-hosted platform for exploit proofs of concept, set up after GitHub and GitLab takedowns. The same researcher published MiniPlasma, which the report places in the operator's toolkit (TL-2026-0523). A hit most likely means a public exploit download: investigate the host, but don't treat the domain as espionage C2.

What is illicit distillation, and were the labs already named?

Training a small model on a bigger one's answers is routine; Anthropic calls it illicit when done without permission, covertly and at industrial scale, usually via fraudulent accounts and proxy resellers. Its September 10, 2026 report names seven China-based labs: Alibaba's Qwen team, Moonshot AI, DeepSeek, Zhipu (Z.ai), Xiaomi, SenseTime and MiniMax. Five were already public: Anthropic's February 2026 disclosure named DeepSeek, Moonshot and MiniMax, and US advisory AA26-251A of September 8 also named Alibaba and Z.ai (TL-2026-2405, TL-2026-2413).

Methodology, limitations and data freshness

Every Threadlinqs number reflects the September 25, 2026 snapshot. Linked live records change with nightly ingest, which can turn a "not in corpus" row into a match but cannot change what we held before September 10, 2026.

"Not in corpus" means only that the string appears nowhere in our records; the indicator could still be live, malicious and well known elsewhere. We do not ingest every feed, and many of Anthropic's indicators are egress addresses and VPN exits operators used to reach Claude, which few outside sources ever see.

Our created_at field stores a date, not a time, so a same-day vendor post cannot be ordered against a record, and anything dated September 10, 2026 counts as derivative even if written before the report went live.

Staleness rests on Anthropic's own first-seen and last-seen dates, not re-checked against our telemetry; hosting-type judgements rest on the context notes in our records.

Drafting was AI-assisted and reviewed by the Threadlinqs Team. Claims about our records rest on quote-checked evidence in the snapshot; where our paraphrase differs from Anthropic's text, Anthropic's text governs.

How to cite this analysis

Threadlinqs Team. "Anthropic's September 2026 AI misuse report, mapped against the Threadlinqs corpus." Threadlinqs Intelligence, September 26, 2026. https://threadlinqs.com/blog/anthropic-claude-misuse-sep2026/

Sources

Take the CSV, the bundle and the rules quoted here. The CSV carries our status for every indicator (the bundle for all but two scheduled-task names), so you can see what was known and when. Linked records carry indicators, ATT&CK mappings and detection logic, and we update them. If a sweep hits, start from the linked record.

[ explore_the_platform ]

Threadlinqs Intelligence — live cyber-threat intelligence. Threats, detections, IoCs and actor attribution, cross-linked and updated nightly.

[ explore_the_platform ]

Published by the Threadlinqs Team under our editorial standards and corrections policy.