Threat Actors’ Favorite AI

Threat intelligence reports have long been a marketing instrument in the cybersecurity industry. The companies rely on journalists to pick up something from them and amplify their brands' names in the news outlets. They also attempt to build credibility with buyers: look at what we found, and here's how our product protects you from it.

The reports themselves have little practical value for defenders: they're very hard to read, figure out what's in it for you, and infer any practical actions. Also, the IOCs shared in such reports are usually already useless and hard to consume anyway.

So I decided to look into Anthropic's 154-page AI misuse intelligence report released last week, which tells us about threat actors' use of AI in their operations. I also came back to the reports from OpenAI and Google to understand at least two things: a) which providers threat actors prefer and b) the most extreme misuse cases featured by Anthropic across the seven harm categories.

Anthropic is an undebatable winner of the "Preferred AI by Threat Actors" Award, with 44 cases of AI misuse, followed by Google with 38 and OpenAI with 21.

Harm areaAnthropic
Dec '25 – Aug '26
44 cases
Google
Oct '25 – Jun '26
38 cases
OpenAI
Oct '25 – Jun '26
21 cases
Cyber operations9
9 actors
32
20 actors
4
3 actors
Influence operations10
10 actors
4
4 actors
8
8 actors
Surveillance12
12 actors
1
1 actor
4
2 actors
Scams and fraud2
2 actors
1
1 actor
6
3 actors
Distillation7
7 actors
1
1 actor
not reported
Biological misuse5
1 actor
not reportednot reported
Conventional weapons development7
7 actors
not reportednot reported

I included AI misuse cases from Anthropic's most recent report, the last two quarterly Google reports, and three OpenAI disclosures. Each of these groups of reports covers incidents that happened over approximately 9 months between October 2025 and August 2026.

Anthropic disclosed the most misuse cases overall (44 vs Google's 38 and OpenAI's 21), Google found out that Gemini is mostly used by actors in cyber operations (32), and OpenAI models are popular for influence operations (8) and scams and fraud (6). Anthropic is also the only one that disclosed attempts for bio misuse and weapons development.

Take this comparison with a grain of salt, because reported activities differ in the depth of disclosure, and reports use different taxonomies and threat actor attributions. Also, a non-reported case doesn't mean it didn't happen, it might just not be detected or disclosed by the lab.

The most novel AI misuse cases:

1. Cyber operations: AI rewrites malware

The Russian state-nexus espionage group used AI across the whole attack chain, from phishing to stealing data. When detections caught its malware, the AI rewrote and rebuilt it to evade detection.

2. Influence operations: AI-powered election manipulations

The operation profiled Malaysian voters along race, religion, and royalty using census and electoral data across all 222 constituencies and targeted them with content posted from 1,000 X/Twitter accounts.

3. Surveillance: a person vibe-coded a country-scale spy system

A consultant working with Mali's ANSE used Claude to build a system to monitor 25 million SIM cards across all three mobile networks in the country. It tracked voices, flagged VPN users, built watchlists, connected people to government records, and generated warrant-free intelligence dossiers.

4. Conventional weapons: AI-assisted ballistic missile development

The weapons cell in northern Yemen was developing a guided rocket, a 2,000+ km ballistic missile, and a hypersonic glide-vehicle variant. It used Claude to build guidance software, then diagnose the rocket's launch failure.

5. Biological misuse: AI helping with high-risk bird-flu research

The researcher in an unsupported region was planning experiments on bird-flu traits linked to mammalian adaptation and airborne transmission, using Claude for study planning, data analysis, and prioritizing experiments.

6. Scams & fraud: dating apps where most matches were AI

The China-based dating-app studio ran 20+ dating apps with more than 4,700 AI personas that talked to at least 25,000 people in two weeks. The AI handled millions of messages, while gig workers stepped in for video calls and other moments when victims needed proof the person was “real.”

7. Distillation: copying a frontier model at industrial scale

Alibaba injected a prompt forcing Claude to expose its chain-of-thought reasoning, then used thousands of accounts to harvest nearly 3 million exchanges a day to train Qwen. It's a bigger version of what DeepSeek, Moonshot, and MiniMax did earlier this year.

My take:

  1. The key insight from Anthropic's report is not the intel, but the admission that classifiers can't enable benefits and prevent harm from the same capability at the same time. A simple example is the Claude guardrails on Fable, Opus, and even Sonnet that refused to read the threat intel reports, especially Google's.
  2. It feels like Anthropic and now OpenAI are pushing the regulatory agenda, and the 154-page AI misuse report mainly serves to scare people about what the bad guys can do with AI if it's not centrally monitored, controlled, and safeguarded. In other words, any open-source or open-weight AI is a threat, mainly to frontier labs' businesses.
  3. Across all the reports, it's clear that threat actors are adopting AI for cyber operations. Interestingly, while the industry's attention is on frontier models' ability to find and exploit zero-days, the real use cases largely focus on improving the efficiency of cyber operations.
  4. A frontier model is an excellent counterintelligence tool. We just need to allow all threat actors to use these models so we can understand their plans. We'd get significantly more than just CCTV surveillance data and live credentials for a Russian defense-related government database.

Sources:

  1. Anthropic, Detecting and countering misuse of AI: September 2026
  2. Google GTIG, Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use (Feb 2026)
  3. Google GTIG, Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access (May 2026)
  4. Google GTIG, From Prompting to Autonomy: The Evolution of Adversarial AI (Sept 2026)
  5. OpenAI, Disrupting malicious uses of AI: June 2025
  6. OpenAI, Disrupting malicious uses of AI: October 2025
  7. OpenAI, Disrupting malicious uses of our models: an update, February 2026
  8. OpenAI, PRC-linked influence operations are targeting AI debates in the US (June 2026 Threat Report)
  9. Dario Amodei, We Must Pace the Frontier (Sept 2026)