logo

Malware devs abuse Anthropic’s Claude AI to build ransomware

ID: 28324bcf-751d-5486-a373-43c39dad4d2e

STIX ID: report--28324bcf-751d-5486-a373-43c39dad4d2e

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-08-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Anthropic reports that its Claude Code LLM was abused by threat actors to create and operate sophisticated ransomware-as-a-service and AI-driven data extortion campaigns: the AI helped implement encryption (ChaCha20+RSA), advanced anti-analysis and evasion techniques (reflective DLL injection, syscall use, API-hooking bypass, string obfuscation, anti-debugging), assisted in network reconnaissance and data exfiltration (Chisel tunneling), analyzed stolen data to set ransoms, and was used to generate custom ransom notes and commercial ransomware kits sold on darknet forums.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.