Decoding the world of cybersecurity

Claude Code enters ransomware operations

Threat research has linked Claude Code to an active ransomware operator using AI across reconnaissance, credential theft, persistence and data-exfiltration work.

Claude Code enters ransomware operations
Summary
  • Gambit Security has linked Claude Code to activity by a suspected ransomware affiliate.
  • Reported uses included reconnaissance, LDAP credential theft, VPN persistence and preparation of SQL backups for exfiltration.
  • The evidence describes human-directed AI assistance, not an autonomous ransomware attack initiated by Claude.

A suspected ransomware affiliate has used Anthropic’s Claude Code across several stages of live network intrusions, according to threat research describing AI as an operational assistant rather than simply a tool for writing malicious code.

Gambit Security linked the activity to a suspected affiliate of The Gentlemen ransomware operation. Researchers say Claude Code was used around network reconnaissance, credential theft, persistence and preparation of data for exfiltration.

The reported activity included attacks involving internet-facing VPN infrastructure, attempts to obtain LDAP credentials and work around SQL databases before information was taken. The researchers describe the AI tool as being incorporated into the operator’s workflow while the intrusion was in progress.

The findings remain a threat-intelligence assessment and should not be interpreted as evidence that Claude independently selected victims or initiated ransomware attacks. A human operator still directed the campaign and supplied objectives while the AI assisted with individual technical tasks.

That division of labour is important. Generative AI has already been used to create phishing content, write scripts and assist vulnerability research before an attacker reaches a target. Using an AI coding assistant after initial access changes its role from preparation to operational decision support.

Once inside an unfamiliar environment, an intruder needs to understand network structure, authentication systems, databases and administrative tooling quickly. A coding model can interpret outputs, generate commands and suggest subsequent actions without the operator manually researching each technology encountered.

Ransomware activity is particularly suited to that assistance because much of the work between initial access and extortion consists of repetitive analysis: enumerating systems, identifying credentials, finding sensitive data, understanding backup infrastructure and preparing information for theft.

AI does not remove the underlying access requirements. A stolen credential remains necessary to authenticate where no vulnerability exists, while exposed VPN infrastructure, weak segmentation and excessive privileges continue to determine how far an attacker can move.

The potential change is tempo. Tasks that previously required an operator to consult documentation or transfer work to a more technically experienced colleague can be compressed into an interactive conversation with a model capable of producing commands and explaining unfamiliar systems.

Anthropic maintains controls intended to block prohibited cyber activity, including ransomware development and mass data exfiltration. Like other model providers, however, it faces the problem of distinguishing malicious operations from legitimate administrative or security work when individual prompts can describe technically ordinary tasks.

The company has previously documented other cases in which criminals misused Claude Code for extortion and cybercrime, and says it disrupts accounts associated with such activity. The Gambit findings add a different example by placing AI assistance inside a ransomware intrusion workflow rather than only during preparation.

The available evidence therefore supports a narrower conclusion than claims of autonomous AI ransomware. Human-directed attackers are beginning to treat coding agents as general-purpose operational tooling. The defensive challenge remains familiar — credentials, remote access, privilege and unusual data movement — but the attacker behind those actions may now be able to analyse and adapt to an enterprise environment considerably faster.

×