Campaign · all campaigns
Anthropic AI-orchestrated CampaignC0062 unknown
aka Anthropic AI-orchestrated Campaign
Last updated: 2026-08-20
About this actor
The [Anthropic AI-orchestrated Campaign](https://attack.mitre.org/campaigns/C0062) was conducted in September 2025 by a likely China nexus espionage actor identified as GTG-1002. The [Anthropic AI-orchestrated Campaign](https://attack.mitre.org/campaigns/C0062) was a highly coordinated operation that manipulated Claude Code to perform reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis, and exfiltration operations at approximately 30 entities in the technology, financial, chemical, and government sectors. During the [Anthropic AI-orchestrated Campaign](https://attack.mitre.org/campaigns/C0062), human operators used Claude Code agents and Model Context Protocol (MCP) tools to automate cyber operations. Operators broke attacks into discrete tasks, used crafted prompts, and established personas to bypass AI guardrails, enabling the agents to execute the operations with minimal human involvement.(Citation: Anthropic AI Orchestrated Campaign NOV 2025)(Citation: Anthropic Disrupting AI Espionage NOV 2025)
Source: MITRE ATT&CK
How we know this
- Data origin
- MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
- Techniques
- MITRE ATT&CK STIX mappings — 36 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1005Data from Local System ↗T1016System Network Configuration Discovery ↗T1046Network Service Discovery ↗T1049System Network Connections Discovery ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1078Valid Accounts ↗T1078.003Local Accounts ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1087Account Discovery ↗T1119Automated Collection ↗T1136Create Account ↗T1136.001Local Account ↗T1190Exploit Public-Facing Application ↗T1213Data from Information Repositories ↗T1213.006Databases ↗T1552Unsecured Credentials ↗T1552.001Credentials In Files ↗T1567Exfiltration Over Web Service ↗T1584Compromise Infrastructure ↗T1584.004Server ↗T1587Develop Capabilities ↗T1587.004Exploits ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1588.007Artificial Intelligence ↗T1590Gather Victim Network Information ↗T1590.004Network Topology ↗T1592Gather Victim Host Information ↗T1592.002Software ↗T1592.004Client Configurations ↗T1595Active Scanning ↗T1595.001Scanning IP Blocks ↗T1595.002Vulnerability Scanning ↗T1683Generate Content ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 13 / 36 | 36% |
AC-2 | 11 / 36 | 31% |
CM-6 | 11 / 36 | 31% |
AC-6 | 10 / 36 | 28% |
AC-3 | 9 / 36 | 25% |
AC-5 | 8 / 36 | 22% |
CA-7 | 8 / 36 | 22% |
IA-2 | 8 / 36 | 22% |
AC-4 | 7 / 36 | 19% |
CM-5 | 7 / 36 | 19% |
CM-7 | 7 / 36 | 19% |
SC-28 | 7 / 36 | 19% |
SC-7 | 7 / 36 | 19% |
RA-5 | 6 / 36 | 17% |
SI-7 | 6 / 36 | 17% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- FIN13 0.22
- Leviathan Australian Intrusions 0.19
- SharePoint ToolShell Exploitation 0.18
- Volt Typhoon 0.18
- Indrik Spider 0.17