high_confidence

Anthropic AI-orchestrated Campaign

The [Anthropic AI-orchestrated Campaign](https://attack.mitre.org/campaigns/C0062) was conducted in September 2025 by a likely China nexus espionage actor identified as GTG-1002. The [Anthropic AI-orchestrated Campaign](https://attack.mitre.org/campaigns/C0062) was a highly coordinated operation that manipulated Claude Code to perform reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis, and exfiltration operations at approximately 30 entities in the technology, financial, chemical, and government sectors. During the [Anthropic AI-orchestrated Campaign](https://attack.mitre.org/campaigns/C0062), human operators used Claude Code agents and Model Context Protocol (MCP) tools to automate cyber operations. Operators broke attacks into discrete tasks, used crafted prompts, and established personas to bypass AI guardrails, enabling the agents to execute the operations with minimal human involvement.(Citation: Anthropic AI Orchestrated Campaign NOV 2025)(Citation: Anthropic Disrupting AI Espionage NOV 2025)

Start date
1 September 2025
End date
1 September 2025
Techniques
26

Attributed actors

Techniques (26)

collection4
T1119Automated Collection
T1213.006Databases
T1074.001Local Data Staging
T1005Data from Local System
credential-access1
T1552.001Credentials In Files
discovery6
T1049System Network Connections Discovery
T1046Network Service Discovery
T1082System Information Discovery
T1087Account Discovery
T1083File and Directory Discovery
T1016System Network Configuration Discovery
exfiltration1
T1567Exfiltration Over Web Service
initial-access3
T1078Valid Accounts
T1190Exploit Public-Facing Application
T1078.003Local Accounts
persistence3
T1078Valid Accounts
T1136.001Local Account
T1078.003Local Accounts
privilege-escalation2
T1078Valid Accounts
T1078.003Local Accounts
reconnaissance5
T1595.002Vulnerability Scanning
T1592.002Software
T1595.001Scanning IP Blocks
T1590.004Network Topology
T1592.004Client Configurations
resource-development5
T1588.002Tool
T1584.004Server
T1683Generate Content
T1588.007Artificial Intelligence
T1587.004Exploits
stealth2
T1078Valid Accounts
T1078.003Local Accounts

Indicators of compromise

No IOCs linked to this campaign yet.