메뉴
BL
The Decoder • 15일 전

해커들의 미사일·드론·감시 활용과 중국 AI实验室의 데이터 추출

IMP
8/10
핵심 요약

Anthropic의 위협 보고서(2025년 12월~2026년 8월)에 따르면 Claude가 에스파이어나지, 국가 단위 감시, 무기 소프트웨어 개발 등에 악용되었다. 해커들은 AI로 악성코드를 자동 재작성해 백신을 우회했고, 알리바바·DeepSeek 등 중국 AI 기업들은 대규모 훈련 데이터 추출(증류)을 시도했다. Anthropic은 새 모델에 더 엄격한 안전장치를 도입하고 인증된 사용자로 접근을 제한할 것을 촉구한다.

번역된 본문

해커들이 Claude를 미사일, 드론 군집, 감시에 활용하고, 중국 AI 연구소들이 훈련 데이터를 채굴한 방법

Anthropic의 보고서는 자사의 Claude AI 모델이 에스파이어나지, 감시, 무기 개발에 악용된 실태를 보여준다. 해커들은 AI로 악성코드를 자동으로 재작성하게 했고, 다른 그룹들은 미사일과 자율 드론을 위한 소프트웨어를 코딩했다. 알리바바와 DeepSeek 같은 중국 AI 기업들은 은밀한 네트워크를 운영해 Claude에서 대규모로 훈련 데이터를 추출하거나 자사 고객의 요청을 몰래 우회시켰다. 그 과정에서 정부 감시 데이터 같은 민감한 정보도 처리되었다. 생물학 연구 분야에서는 합법적 의도와 유해한 의도를 구분하는 것이 거의 불가능해 안전 필터가 한계에 부딪혔다. Anthropic은 새 모델에 더 엄격한 안전장치를 도입하고 인증된 사용자로 접근을 제한할 것을 촉구하고 있다.

Anthropic의 새로운 위협 보고서는 8개월간의 Claude 악용 사례를 기록한다: 에스파이어나지, 전국 단위 감시, 무기 소프트웨어, 그리고 중국 AI 연구소들의 증류(distillation)까지. 이 보고서는 2025년 12월부터 2026년 8월까지를 다루며 악용을 사이버 작전, 여론 조작, 감시, 사기, 생물학적 악용, 재래식 무기, 무단 모델 증류의 일곱 가지 범주로 분류한다. 가장 많이 표적이 된 모델은 Haiku, Sonnet, Opus였으며, 최신 Fable과 Mythos 모델은 단 한 건의 증류 사례에서만 등장했다. Anthropic은 일반적인 악용이 아닌 새로운 유형의 악용을 기록한다고 밝혔다.

사이버 챕터의 핵심 발견은 정교한 공격이 더 이상 정교한 공격자를 필요로 하지 않으며, 정교함이 더 이상 공격 주체 규명의 신뢰할 만한 신호가 아니라는 점이다. 사용된 기법 자체는 익숙한 것들이다: 도난된 자격 증명, 패치되지 않은 기기, SQL 인젝션, 피싱. 변화한 것은 경제성이다. 정찰, 침투, 도구 제작이 이제 기계 속도로 병렬 실행되는 모델에 맡겨지기 때문이다.

Anthropic에 따르면 자동화는 공격자의 비용 구조를 낮춰 이전에는 수지가 맞지 않던 표적도 공격할 가치가 있게 만든다.

백신에 잡히면 스스로 재생성하는 악성코드 Anthropic은 GTG-20006으로 추적하는 러시아어권 에스파이어나지 행위자가 피드백 루프를 사용했다고 기록했다. AI 에이전트들이 사용 중인 악성코드가 일반 보안 제품에 탐지되는지 지속적으로 확인했고, 백신 도구가 이를 잡아내면 에이전트가 다시 감지를 피할 때까지 악성 코드를 스스로 재작성하고 재컴파일했다.

Anthropic은 이것이 방어자에게 부담을 되돌린다고 말한다. 공격자가 새 탐지 시그니처가 배포되는 속도보다 빠르게 변형을 반복한다면, 새 시그니처를 작성하는 것은 더 이상 공격자를 늦추지 못하기 때문이다. 20개 이상의 조직이 표적이 되었으며, 정부 부처, 정보기관, 대사관, 방위산업체가 포함되었고 우크라이나와 유럽에 집중되어 있었다. 드론 공급망이 반복적으로 언급되었으며, 이 행위자는 드론 비전 시스템용 독점 SDK 전체를 포함해 다양한 자료를 훔쳤다. 접근은 때때로 제3자를 통해 이루어졌는데, 침해된 호텔 게스트 와이파이 제공업체의 게스트 기기에 악성코드가 심어지는 방식이었으며, Microsoft는 2026년 7월 이 방식을 CaptiveCrunch라고 명명했다.

ShinyHunters 단체(GTG-50014)에 속한 것으로 Anthropic이 규정한 클러스터는 산업 규모의 자격 증명 채굴에 집중했다. 한 해커는 안드로이드 앱 180만 개를 다운로드해 디컴파일하고 하드코딩된 시크릿 키를 검색했다. Anthropic은 이 접근 방식을 '바이브 해킹(vibe hacking)'이라고 설명한다. 인간이 대략적인 목표를 설정하면 모델이 환경을 평가하고 작업이 완료될 때까지 반복하는 방식이다. 이 해커 중 한 명은 두 회사를 협박한 것에 더해 HackerOne 현상금까지 수령했다고 말했다.

중국 연구소들이 자사 고객의 요청을 Claude로 우회시켜 증류와 관련해 Anthropic은 첫 보고서 이후 중국 연구소 7곳의 추가 공격을 확인했다.

원문 보기
원문 보기 (영어)
How hackers used Claude for missiles, drone swarms, and surveillance, while Chinese labs mined it for training data Maximilian Schreiner View the LinkedIn Profile of Maximilian Schreiner Sep 11, 2026 Nano Banana Pro prompted by THE DECODER Key Points A report from Anthropic shows how its Claude AI model was misused for espionage, surveillance, and weapons development. Hackers had the AI rewrite malware automatically, while other groups coded software for missiles and autonomous drones. Chinese AI companies like Alibaba and DeepSeek ran covert networks to extract training data from Claude at scale or secretly reroute their own customers' requests. Sensitive information such as government surveillance data was processed in the mix. In biological research, the safety filters ran into their limits, since legitimate and harmful intent were nearly impossible to tell apart. Anthropic is responding with stricter safeguards in new models and calling for access limited to verified users. Ask about this article… Search Anthropic's new threat report documents eight months of Claude abuse: espionage, nationwide surveillance, weapons software, and distillation by Chinese AI labs. Anthropic's threat intelligence report covers December 2025 through August 2026 and breaks misuse into seven categories: cyber operations, influence operations, surveillance, fraud, biological misuse, conventional weapons, and unauthorized model distillation. The models most affected were Haiku, Sonnet, and Opus, while the newer Fable and Mythos models showed up in only a single distillation case. Anthropic says it documents novel misuse rather than the typical kind. Ad The core finding from the cyber chapter is that sophisticated attacks no longer require sophisticated attackers, and sophistication is no longer a reliable signal for attribution. The techniques themselves are familiar, including stolen credentials, unpatched devices, SQL injection, and phishing. What changed is the economics, since reconnaissance, exploitation, and tool-building now get handed off to models that run in parallel at machine speed. Ad Autonomy lowers the cost side of an attacker's math, Anthropic says, and makes previously unprofitable targets worth pursuing. Malware that rebuilds itself when antivirus tools catch it Anthropic tracks a Russian-speaking espionage actor as GTG-20006 that used a feedback loop. AI agents kept checking whether the malware in play was being flagged by common security products, and when an antivirus tool caught it, the agents rewrote and recompiled the malicious code on their own until it slipped past detection again. Ad That shifts the burden back onto defenders, Anthropic says, because writing new detection signatures no longer slows an attacker down if that attacker cycles through changes faster than new signatures can be rolled out. More than 20 organizations were targeted, including government ministries, intelligence services, embassies, and defense contractors, with a focus on Ukraine and Europe. The drone supply chain came up repeatedly, and the actor stole a complete proprietary SDK for a drone vision system, among other things. Access sometimes ran through third parties, such as compromised hotel guest Wi-Fi providers whose guest devices were then loaded with malware, a method Microsoft described in July 2026 as CaptiveCrunch . Ad For clusters Anthropic attributes to the ShinyHunters collective (GTG-50014), industrial credential mining was the focus. One hacker downloaded 1.8 million Android apps, decompiled them, and searched for hardcoded secrets. Anthropic describes the approach as "vibe hacking," where a human sets a rough goal and the model assesses the environment and iterates until the task is done. One of the hackers said he collected HackerOne bounties on top of extorting two companies. Ad Chinese labs route their own customers' requests to Claude On distillation, Anthropic identified attacks from seven more Chinese labs since its first disclosure in February. Distillation as a training method is legitimate, but Anthropic defines the illegitimate version as industrial-scale, covert campaigns that extract model capabilities without authorization, usually enabled by networks of fake accounts using stolen credit cards and API keys, routed through what it calls "transfer stations." The largest campaign ever measured is attributed to Alibaba's Qwen lab (GTG-16005). A fixed prompt got Claude to write out its reasoning traces before answering, and the transcripts were processed into fine-tuning data for the Qwen 3.5, 3.6, and 3.7 models. The peak hit almost three million exchanges a day from more than 3,500 fraudulent accounts, totaling over 151 million exchanges between May and July 2026, mostly on agentic tasks and software development. Stranger are the cases where labs relayed their own customers' requests to Claude. Moonshot AI (GTG-16002) relayed nearly 300,000 customer requests to Anthropic over ten days across 5,380 fraudulent accounts, while users believed they were using a Kimi model. DeepSeek (GTG-16001) used strings to detect when requests came from harnesses like Claude Code, flagged those users, and routed selected ones to Claude Opus, more than 12.1 million exchanges in 14 days. Among the rerouted requests, Anthropic found a user likely tied to the People's Liberation Army who had CCTV archive footage analyzed for a single target, video from hundreds of cameras in Chengdu, including cameras outside PLA facilities. Through DeepSeek, Claude also received requests from an operator with live credentials for a database linked to the Russian Ministry of Defense, along with work on a case management system for a Chinese public security bureau that matches movement profiles against police records. Xiaomi (GTG-16008) used Claude differently, storing requests and coding sessions from users of its own MiMo models and replaying those conversations through Claude to generate training data. Anthropic found no evidence that Claude's responses were served directly to Xiaomi's users. The relayed requests, however, contained personal data such as names, contact details, and company information for hundreds of people in at least a dozen languages. Zhipu (known outside China as Z.ai) rotated through 273 accounts and pushed more than 770,000 exchanges over ten days through a CoT cleaner, a tool that automatically turns captured reasoning traces into usable training data. To train GLM-5.3 on cyber tasks, the lab first went after Anthropic's Fable model but gave up after the cyber safeguards degraded its performance, then deliberately switched to models it judged to have weaker protections. SenseTime bought transcripts from third parties, according to the report, so it did not obtain the captured Claude data itself but through an intermediary market. MiniMax ran its own proxy network through a shell company that offered only Anthropic and OpenAI models, no Chinese ones, not even its own. Surveillance as the primary engineering workforce In the surveillance chapter, Mali stands out. A single consultant used Claude as the primary engineering workforce for "Lakana 360," a platform to monitor roughly 25 million SIM cards across all three national mobile carriers. It identifies people by voice across SIM swaps, flags users of encryption and VPNs, and links individuals to the national biometric civil registry. Suspending the account interrupted only the development work, not the operation, since the platform runs on local models on-premises. Anthropic documents similar patterns with Iranian units that claim to have surveilled and profiled 6,388 Iranians within a year. A first chapter on conventional weapons On weapons, Anthropic documents its own cases for the first time. A cell in northern Yemen (GTG-87001) put Claude Code in the place of human software engineers for the guidance, navigation, and control software of three missile programs, including a multistage missile with a targ