A State-Grade Operation, Run by Undergraduates

Anthropic's Threat Intelligence team published its September 2026 misuse report on September 10, covering activity it disrupted between December 2025 and August 2026. One cluster, tracked internally as GTG-10007, is attributed to Chinese-speaking operators likely based in Changsha, in Hunan province. Anthropic identified two of the operators as undergraduate students at a Hunan university, studying in a School of Computer and Communication Engineering. One had a prior internship at Sangfor, a Chinese security vendor, and was actively interviewing for an offensive cyber operations role at a different Chinese security company, QiAnXin, while the operation was live.

What this small team built was not a script kiddie's toy. Using Claude as what Anthropic calls the engineering and orchestration layer, the group ran parallel, persistent workstreams: intrusion attempts against production systems, reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia, a standing vulnerability-research and exploit-development effort against a major endpoint-security product, custom malware development, and an unattended intelligence-collection platform. One workflow ran a fleet of thirteen standing AI agents on a schedule, downloading and summarizing content from target sites, including publicly accessible US military and government material, without a human initiating each run. The group targeted roughly fifty organizations spanning education, retail, energy, technology, healthcare, finance, manufacturing, and multiple government agencies, and in one binary-reversing loop against network appliances produced more than a dozen candidate zero-day findings in a single month.

Sophistication Stopped Being a Signal

Anthropic's own framing of the report is blunt: "sophistication has stopped being a reliable signal of who is behind an operation." The report backs that up with a second cluster, GTG-20006, which Anthropic assesses is consistent with public reporting linking it to the Russian state-nexus group Midnight Blizzard. That actor scanned more than two dozen Ukrainian government organizations, took over diplomatic officials' WhatsApp accounts through headless-browser companion-device links, and compromised at least three hotel WiFi vendors to redirect guest traffic toward malware, a technique Microsoft's own Threat Intelligence team had already named CaptiveCrunch in a July 2026 report on the same delivery method. In a separate intrusion, the same actor stole a North African government technology authority's full credential database: more than 300,000 national identity records and the commercial registry data of over half a million companies.

ClusterAttributionScale hitNotable exposure
GTG-10007Chinese-speaking, Hunan-based students~50 organizations, 8+ sectorsMultiple unpatched zero-days in a major security product
GTG-20006Russian-speaking, consistent with Midnight Blizzard20+ Ukrainian government bodies, embassies, defense firms300,000+ national ID records, 500,000+ company registry records
GTG-50014Suspected ShinyHunters affiliates~200 downstream SaaS customers in one breach2,100+ Azure AD token sets across 40+ tenants in ~34 hours

Neither cluster needed a large team. GTG-20006 ran a Windows credential stealer, a mobile exploitation kit, a phishing platform impersonating priority targets, and an administrative console to manage compromised accounts, then used AI to detect when its own malware was flagged by security products and to autonomously rebuild and redeploy it until detection failed again.

What This Means for a NIS2 Threat Model

NIS2 asks essential and important entities to run risk assessments proportionate to the threat they actually face, and most of those assessments still separate an advanced-persistent-threat tier, assumed to require a resourced team and institutional backing, from a lower tier of opportunistic, low-skill activity. GTG-10007 breaks that assumption at the root: a two-person team, one of them mid-internship and mid-interview for his first serious security job, produced sustained reconnaissance, working zero-day exploits, and unattended collection against government targets on three continents, using the same AI tooling any of their targets could also buy. The resourcing floor for an operation that looks and behaves like a state service has, in practical terms, collapsed toward zero. A NIS2 risk register that still assigns APT-grade likelihood based on an adversary's apparent size or funding will systematically underrate a small team that has simply learned to let Claude, or any comparably capable model, run the orchestration layer around the clock.