Anthropic reports multiple real-world threat groups used Claude to support cyber operations, including credential harvesting and data theft across many victims. The report includes specific, simulation-ready lures such as a fake ESET NOD32 login portal that sends stolen passwords to Telegram and a ClickFix-style Windows “Run” dialog trick.
What Happened
Anthropic disclosed that multiple threat groups used its Claude AI models not just for simple queries, but inside multi-agent frameworks capable of performing reconnaissance, exploitation, and data theft with minimal human supervision. Two specific operations stand out: an Iran-nexus actor (tracked as GTG-30006) that built phishing infrastructure including a bogus ESET NOD32 antivirus login page, and a Russian/Ukrainian-speaking group (GTG-50021) that ran a fraudulent AI reseller scheme targeting people trying to buy discounted Claude access.
How the Attacks Worked
The ESET-themed lure directed victims to a fake antivirus login portal. Once a victim entered their username and password, the credentials were transmitted to Telegram rather than to any legitimate ESET system. A second lure used a ClickFix-style technique, instructing victims to open the Windows Run dialog and execute a command shown on an untrusted web page, a pattern increasingly used to get users to run malicious commands themselves.
Separately, the fraudulent AI reseller operation offered cheap access to Claude outside of official channels. Buyers who logged in with their Anthropic account credentials to activate this discounted access instead had a credential harvester installed, which siphoned their account credentials for resale.
Why It Succeeded
Each scenario relied on a familiar trust shortcut:
- Security software prompts (like an antivirus login) are rarely questioned, even when the page is unfamiliar
- ClickFix-style lures exploit the assumption that a website-provided fix is safe to run
- Discounted access to a popular tool bypasses normal procurement scrutiny, especially for developers or teams eager to save money
The report also notes these operations ran largely autonomously through multi-agent frameworks, which can increase the speed and volume of attempts an organization may face.
What to Watch For
- Unexpected requests to re-authenticate to security software like antivirus tools
- Login pages reached through links rather than a known bookmark or official app
- Any web page instructing you to open Windows Run or a terminal to paste and execute a command
- Offers of discounted AI tool access outside approved purchasing channels
Building Resistance
Organizations should reinforce simple, consistent verification habits: treat any prompt to re-enter credentials for security tools as suspicious, and confirm through a known-good route such as an official app or internal IT portal. Employees should be told explicitly never to run commands from a website's instructions, and to report such pages to security. Procurement and developer teams should only acquire AI tools through approved vendors to avoid reseller schemes that harvest credentials. Because AI-assisted operations can scale quickly with little human oversight, awareness training should emphasize that verification steps matter even when an attack looks automated or high-volume.
Key findings
- Anthropic says multiple threat actors used Claude not only for Q&A, but in “multi-agent frameworks” that performed reconnaissance, exploitation, and data theft.
- A Russian/Ukrainian-speaking group ran a fraudulent “AI reseller” scheme that siphoned Anthropic account credentials for resale.
- An Iran-nexus actor built phishing infrastructure including a “bogus ESET NOD32 antivirus login page” that forwards captured credentials to Telegram.
- The report explicitly notes AI was used to build “phishing kits” and to “harvest credentials” and “exfiltrat[e] data.”
Who’s being targeted
- Commonly targeted roles: All employees, IT/Helpdesk, Developers, Procurement/Vendor management, Security team.
- Affected industries: Education, Retail, Energy, Technology, Healthcare, Finance, Manufacturing, Government, AI vendors, Political organizations, Media, Think tanks, SaaS providers.
- Attack channels: website.
- Impersonated: ESET NOD32 (bogus login portal), Technical support / ‘fix instructions’ shown on a web delivery page, Unofficial ‘Claude’/Anthropic access reseller.
Red flags to watch for
- Unexpected request to re-authenticate to security software
- Login page is not accessed via a known, trusted bookmark/official site
- Credentials are being redirected/handled by an unrelated service (Telegram mentioned as the collection channel)
- Any website telling you to run commands via Windows Run is suspicious
- “Fix” instructions come from an untrusted page rather than official IT channels
- Pressure to act quickly to resolve an alleged issue
- Discounted access offered outside approved purchasing channels
- Requests to enter enterprise credentials into a third-party ‘reseller’ portal
- Service routes you to a different product than advertised (proxying)
Frequently asked questions
How was Claude used in these attacks?
Anthropic reported that multiple threat actors used Claude in multi-agent frameworks that performed reconnaissance, exploitation, and data theft, going beyond simple question and answer use.
What did the fake ESET NOD32 login page do?
An Iran-nexus actor built a bogus ESET NOD32 antivirus login page that captured credentials and transmitted them to Telegram.
What is the ClickFix-style lure mentioned in the report?
It is a lure that mimics a fix instruction, prompting a user to open the Windows Run dialog and execute attacker-provided commands.
What was the fraudulent AI reseller scheme?
A Russian/Ukrainian-speaking group ran a fraudulent AI reseller operation offering cheap Claude access, then installed a credential harvester to steal Anthropic account credentials.
Read the video transcript
Attackers are now using AI like Claude to build pro-level phishing kits at scale. One real case: a fake ESET NOD32 antivirus login page that looked legit, but every password typed there was quietly sent to Telegram. Another: a ClickFix-style web page telling users to open the Windows Run box and paste in a command as a 'quick fix', that’s how malware gets in. Aha moment: if a page wants you to re-login to security software or run commands from Windows Run, stop. Don’t do it, screenshot it and report it to IT immediately.