Live data from Hacker News

Disrupting the first reported AI-orchestrated cyber espionage campaign

anthropic.com

1–10 of 298 posts

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#3
It sounds like they built a malicious Claude Code client, is that right?

> The threat actor—whom we assess with high confidence was a Chinese state-sponsored group—manipulated our Claude Code tool into attempting infiltration into roughly thirty global targets and succeeded in a small number of cases. The operation targeted large tech companies, financial institutions, chemical manufacturing companies, and government agencies. We believe this is the first documented case of a large-scale cyberattack executed without substantial human intervention.

They presumably still have to distribute the malware to the targets, making them download and install it, no?

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#4
They're spinning this as a positive learning experience, and trying to make themselves look good. But, make no mistake, this was a failure on Anthropic's part to prevent this kind of abuse from being possible through their systems in the first place. They shouldn't be earning any dap from this.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#6
post #3

It sounds like they built a malicious Claude Code client, is that right? > The threat actor—whom we assess with high confidence was a Chinese state-sponsored group—manipulated our Claude Code tool into attempting infiltration into roughly thirty global targets and succeeded in a small number of cases. The operation targeted large tech companies, financial institutions, chemical manufacturing companies, and government…

No, they used Claude Code as a tool to automate and speed up their "hacking".

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#7
post #3

It sounds like they built a malicious Claude Code client, is that right? > The threat actor—whom we assess with high confidence was a Chinese state-sponsored group—manipulated our Claude Code tool into attempting infiltration into roughly thirty global targets and succeeded in a small number of cases. The operation targeted large tech companies, financial institutions, chemical manufacturing companies, and government…

One time my co-worker got a scam call and it was an LLM talking to him.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#9
post #8

so even Chinese state actors prefer Claude over Chinese models? edit: Claude: recommended by 4 of 5 state sponsored hackers

Uh..

No.

It's worse.

It's Chinese intel knowing that you prefer Claude. So they make Claude their asset.

Really no different than knowing that, romantically speaking, some targets prefer a certain type of man or woman.

Believe me, the intelligence people behind these things have no preferences. They'll do whatever it takes. Never doubt that.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#10
post #4

They're spinning this as a positive learning experience, and trying to make themselves look good. But, make no mistake, this was a failure on Anthropic's part to prevent this kind of abuse from being possible through their systems in the first place. They shouldn't be earning any dap from this.

Meh, drama aside, I'm actually curious what would be the true capabilities of a system that doesn't go through any "safety" alignment at all. Like an all out "mil-spec" agent. Feed it everything, RL it to own boxes, and let it loose in an air-gapped network to see what the true capabilities are.

We know alignment hurts model performance (oAI people have said it, MS people have said it). We also know that companies train models on their own code (google had a blog about it recently). I'd bet good money project0 has something like this in their sights.

I don't think we're that far from a blue vs. red agents fighting and RLing off of each-other in a loop.

Post reply on HN