• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - AI Trends and Related News - Anthropic’s September Threat Report: AI bot armies mass-produce fake news, seven Chinese AI labs collude to steal models via distillation, and Taiwan is also on the list.

Anthropic’s September Threat Report: AI bot armies mass-produce fake news, seven Chinese AI labs collude to steal models via distillation, and Taiwan is also on the list.

KOCPC Editor by KOCPC Editor
September 11, 2026
in AI Trends and Related News, Latest Technology News

Anthropic released its latest threat intelligence report on September 10, documenting multiple operations abusing Claude that its threat intelligence team detected and disrupted between December 2025 and August 2026, spanning seven areas: cyber operations, influence operations, surveillance, fraud, biological misuse, conventional weapons development, and model distillation. The actors in the report include suspected state-backed groups, profit-driven criminals, commercial spyware vendors, state propaganda organizations, and politically motivated individuals. Most noteworthy are three threads: how AI bot networks mass-produce fake news, the AI dating-scam empire built by Chinese studios, and the distillation war launched against Claude by multiple Chinese labs.

AI troll army: one person, one program, thousands of fake news stories

The influence operations chapter reveals that AI has already become the “news station” for online troll armies. In the cases listed in the report, Claude was embedded into existing human editorial workflows, acting as a deputy editor or content producer, enabling resource-limited actors to operate at a volume far beyond human capacity. The most typical case is in Bangladesh: an actor living in the Gaibandha area used a self-written “fake_news_3.py” program to directly call the Claude API, producing a fixed output each round of 15 headlines, 3 fabricated reports, and 15 sets of image-generation prompts, with the content uniformly supporting the ruling Awami League and attacking opposition parties, student leaders, and the interim government. The actor demanded that the content be “explosive enough and radical enough” and also “simple enough for rural people to understand,” and internal communications even said, “No one knows the news is fake.”

This online troll rotated through 29 Claude accounts to evade detection and, over sixteen months, produced at least 1,500 headlines, 300 sets of fabricated stories, and 1,500 sets of image prompts, then used a scheduling program to queue videos on YouTube a month in advance, alongside Facebook Live and TikTok live broadcasts, targeting a group of rural supporters with limited literacy. After investigating, Anthropic concluded that there was no evidence the ruling party directly ordered or funded the operation, but the content clearly favored the ruling party.


State-level cases are equally eye-catching. In Bangui, the capital of the Central African Republic, a Russian-speaking actor produces pro-Russian, anti-French content every day through a radio station linked to the Wagner Group. He also uses Claude to generate employee contracts, performance review standards, and a “three-strikes” termination process, writes “support for Russia” into the contracts, and asks the model to remove traces of AI writing so that the radio station’s content does not read as if it were machine-generated.

Three state-backed institutions in Iran, meanwhile, treat Claude as a propaganda headquarters: the Islamic Culture and Communication Organization (ICCO), the Khorasani Islamic Propagation Office, and the Bina Cultural Observatory. Operatives describe themselves as carrying out “soft war” and “cognitive warfare,” and one of them said their job was to “be the director” rather than “be the narrator,” making state-endorsed content look like an independent voice. During the 2026 US-Israel-Iran War, this network also put false information under the names of Western think tanks such as CSIS, Brookings, and RAND, and attribution laundering has become standard operating procedure.

China Dating Scams: 75% of the Matchmaking Pool Is AI

The fraud section contains only one case, but its scale is astonishing. The operation, codenamed GTG-15001, originated from an app studio in China, used Claude to build more than 20 dating apps, and used Claude to power chat AI personas, while publicly claiming “fully human service.” Within two weeks in April 2026, Anthropic detected more than 4,700 AI personas engaging in conversations with at least 25,000 users; Claude sent about 2.36 million messages in two weeks, and the matching pool deliberately maintained an AI-to-human ratio of about 3:1.

The studio hired real women as contract workers to blend into the matching pool, handling video calls and following social media accounts—parts AI can’t do—to lower victims’ guard. These employees themselves also use a smaller AI model to help with replies, sending them by clicking suggested responses. The app also has built-in anti-review mechanisms: development documents show that the UI controller only activates during app store review, more than 20 app variants use different class names to evade similarity matching, and the server side can be configured to route payments to third-party payment processors, completely hidden during review. Anthropic has handed store-related details to Apple and Google and shared intelligence with other AI labs.

Distillation Wars: 7 Chinese Labs, Nearly 200 Million Requests

Model distillation is the most substantial section of this report. Distillation itself is a legitimate training method: a larger teacher model generates responses, which are then used to train a smaller student model to imitate them. What Anthropic defines as “illicit distillation” is an attack that covertly extracts model capabilities at industrial scale and copies them into other models, typically sustained by fake credit cards, stolen API keys, and large numbers of fake accounts. Since first disclosing this in February 2026, Anthropic has detected and disrupted distillation attacks by seven Chinese labs (including nearly every Chinese AI company of note), with five campaigns totaling nearly 200 million request exchanges.

The largest was Alibaba: operators targeted the chain-of-thought reasoning traces of Opus 4.6 and 4.7, injecting a fixed prompt into every request to force Claude to output the full reasoning process before giving an answer, with nearly 3 million exchanges on peak days and more than 3,500 fraudulent accounts used. Between May and July, Alibaba’s distillation scale exceeded 151 million exchanges; Anthropic called it the largest distillation attack ever measured, and the distilled capabilities were used to train Qwen 3.5, 3.6, and 3.7.

Moonshot (Kimi) and DeepSeek’s tactics are more controversial: both companies secretly routed their own users’ requests to Claude and then returned Claude’s answers to the users, who had no idea throughout that they were using someone else’s model. Moonshot once forwarded nearly 300,000 requests over 10 days, accumulated more than 23 million exchanges from May to July, and used “cross-session replay attacks” to extract reasoning traces; DeepSeek’s method was the same, and the forwarded traffic carried real user data, including internal documents from Chinese tech companies and database credentials for Russian defense agencies.

Zhipu (Z.ai) targeted the cybersecurity capabilities of US frontier models ahead of the GLM 5.3 launch, rotating through 273 fake accounts within 10 days to generate 770,000 exchanges. It at one point tried to attack Claude Fable’s security protections, then pivoted to Opus 4.6 after failing; Xiaomi replayed user conversations from its own MiMo model to Claude, making over 400,000 requests and using 1,500 accounts, and is also suspected of exploiting MiMo-V2-Pro’s free trial period to attract international developers. SenseTime directly bought users’ conversation records with Claude from third-party data brokers, and MiniMax even ran a proxy network through shell companies, selling only Anthropic and OpenAI models, with its own models completely off the list.

Anthropic’s response includes: Claude summarizing its internal reasoning before replying, Fable 5.1’s preserved thinking mechanism, and requiring identity verification for suspicious accounts. The industry reacted strongly to this list, with Futurum Group CEO Daniel Newman saying bluntly on X that it was “freaking insane,” challenging the achievements of Chinese open-source models as “basically stolen from U.S. frontier labs,” and saying “many people have been fooled by claims that Chinese models are faster, better, and cheaper.”

Now can we talk about why these Chinese “Open Weight” models are so good? Because it’s basically all lifted from U.S. frontier labs.

Sad how many people have fallen for the litany of narratives that China is building better, faster, cheaper models.

They are literally routing… https://t.co/jiedm13mTG

— Daniel Newman (@danielnewmanUV) September 10, 2026

Cyber warfare, surveillance, weapons, and biological domains

Alarms are simultaneously sounding in other domains. The cyber warfare chapter describes the shift in AI’s role as “from assistant to commander”: most operations are now directly carried out by multi-agent frameworks for reconnaissance, intrusion, and data exfiltration, with humans only responsible for setting objectives and reviewing results. Cases include Russian espionage operations suspected to be linked to Midnight Blizzard, as well as the ShinyHunters hacking group. In the surveillance domain, there are China’s surveillance recruitment operations targeting Uyghurs, religious affairs intelligence operations, and “public opinion monitoring”; advisors in Mali’s national security department used Claude to build a surveillance platform called Lakana 360 covering the country’s three major telecom operators, covering approximately 25 million SIM cards.

The conventional weapons chapter reviews six cases: three in China, two in Russia, and one in Yemen, involving drafting fire-control specifications, targeting software, and intelligence collection on directed-energy weapons; in the biological domain, it reports that recent model capabilities have approached a “suspicious threshold,” and Anthropic has imposed stricter restrictions on dual-use biological research queries with Fable 5.

Taiwan is also on the surveillance target list.

Two China-related operations in the report touched on Taiwan. In the religious affairs intelligence operation, Anthropic blocked a set of intelligence accounts suspected of being directed by the Chinese government; the actors used Claude in place of an entire analysis team and created Chinese-language dossiers targeting Asian religious leaders and the Chinese diaspora. The targets included the leadership of the Presbyterian Church in Taiwan, Catholic cardinals in Asia, Tibetan Buddhist communities, and Falun Gong. The dossiers recorded the targets’ China-related activities, scandals, and exploitable leverage, and also collected personal data such as dates of birth, immigration dates, and social media accounts.

In public opinion monitoring operations, another case had Claude process 15 to 30-plus social media and Western and Taiwanese media reports every day, rewriting them into internal government briefings. Dissent and foreign reports were flagged as risks, Taiwanese politicians, labor activists, and student activists were all on the monitoring list, Taiwanese media reports were reframed as hostile content, and cross-strait and cultural diplomacy activities were labeled as threats to sovereignty. The wording of the documents directly applied the framework of psychological warfare, legal warfare, and public opinion warfare from China’s Three Warfares doctrine.

Conclusion

However, it is important to note that this report is Anthropic’s own account, and external researchers cannot access the underlying account data, prompts, network indicators, or law enforcement records to reproduce its findings. But the scale of the data and density of detail in the report make it one of the most comprehensive public documents to date on how AI is being weaponized. Anthropic says it released these findings because it believes it has a responsibility to disclose malicious use of its services, and hopes other developers can identify similar patterns on their own platforms. The more capable the models, the higher the risk, unless AI developers and defenders in society take action to make them safer.

Data source

Source: KOCPC Chinese

Tags: AI troll armyAnthropicClaudeThreat Report

Recent Posts

  • Out of inspiration? OpenAI Showcase features a large collection of games, websites, and AI apps built with GPT, and you can even try them directly.
  • Death Stranding 2 Sales Below Expectations? Sony Abandons Hideo Kojima’s New Game Physint, Then Xbox Takes Over
  • Thinking of switching password managers? A new Android feature makes the process easier.
  • Anthropic’s September Threat Report: AI bot armies mass-produce fake news, seven Chinese AI labs collude to steal models via distillation, and Taiwan is also on the list.
  • Running PC games on iPhone is no longer a dream: Madeira open-source project gets Cyberpunk 2077 running on phones.

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology