Anthropic's Claude Code large language model has been abused by threat actors who used it in data extortion campaigns and to develop ransomware packages. The company says that its tool has also been used in fraudulent North Korean IT worker schemes and to distribute lures for Contagious Interview campaigns, in Chinese APT campaigns, and by a Russian-speaking developer to create malware with advanced evasion capabilities. In another instance, tracked as ‘GTG-5004,’ a UK-based threat actor used Claude Code to develop and commercialize a ransomware-as-a-service (RaaS) operation. The AI utility helped create all the required tools for the RaaS platform, implementing ChaCha20 stream cipher with RSA key management on the modular ransomware, shadow copy deletion, options for specific file targeting, and the ability to encrypt network shares. On the evasion front, the ransomware loads via reflective DLL injection and features syscall invocation techniques, API hooking bypass, string obfuscation, and anti-debugging. Anthropic says that the threat actor relied almost entirely on Claude to implement the most knowledge-demanding bits of the RaaS platform, noting that, without AI assistance, they would have most likely failed to produce a working ransomware. “The most striking finding is the actor’s seemingly complete dependency on AI to develop functional malware,” reads the report. “This operator does not appear capable of implementing encryption algorithms, anti-analysis techniques, o...
Malware devs abuse Anthropic’s Claude AI to build ransomware
BleepingComputer
·Bill Toulas
·Published Aug 28, 2025
·Updated
Affected Software
1 affected component
anthropic Claude Code
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how malware developers are abusing Anthropic's Claude AI to create ransomware and engage in data extortion.
2
What security implications are discussed?
The article highlights the risks of AI tools being exploited for malicious purposes, including ransomware development and fraudulent activities.
3
What software is affected by this abuse?
The affected software mentioned in the article is Anthropic's Claude Code.
4
How are threat actors using Claude AI in their campaigns?
Threat actors are utilizing Claude AI to develop ransomware packages and conduct data extortion campaigns.
5
What types of fraudulent activities are linked to this AI misuse?
The AI misuse is linked to fraudulent IT work associated with North Korean cyber activities.