AI-Powered Threats: Iran-Linked Actors and Houthi Cells Exploit Anthropic’s Claude for Military Operations and Domestic Surveillance

The intersection of artificial intelligence and modern asymmetric warfare has entered a perilous new phase, underscored by alarming revelations in Anthropic’s September 2026 threat intelligence report. According to the document, Iran-linked threat actors and affiliated regional proxy networks have systematically leveraged American-built generative artificial intelligence technology—specifically Anthropic’s Claude models—to augment military reconnaissance, accelerate advanced weapons development, and execute large-scale domestic surveillance operations. The findings highlight a profound national security challenge: advanced frontier AI models, designed primarily for commercial productivity and software development, are increasingly being subverted by adversarial nation-states to bypass traditional technological barriers in weapon design and cyber-espionage.
The Anatomy of the Threat: Reconnaissance Against the U.S. Navy
Among the most unsettling discoveries detailed in the Anthropic report is the utilization of Claude to support tactical military reconnaissance and formulate targeting recommendations directed against United States naval forces operating in the Middle East. Historically, compiling comprehensive targeting profiles against heavily defended modern warships required sophisticated intelligence apparatuses, extensive signals intelligence (SIGINT) capabilities, and dedicated human intelligence networks. However, threat actors demonstrated that modern large language models can dramatically lower the threshold for complex military data aggregation.
The operation involved synthesizing disparate, publicly accessible data sources into actionable tactical intelligence. Perpetrators cross-referenced publicly available ship and aircraft transponder identifiers—such as Automatic Identification System (AIS) and ADS-B data—with high-resolution commercial satellite imagery and open-source records of U.S. naval deployments. Furthermore, the AI model was used to parse captions from publicly available military photographs to extract the names and identities of U.S. military personnel, illustrating an aggressive human-mapping component.
Beyond physical tracking, the malicious actors utilized Claude to research potential cyber and physical vulnerabilities in critical communications infrastructure deployed aboard modern naval vessels. The targeted systems included known technical flaws and configuration weaknesses affecting Cobham Sailor Very Small Aperture Terminal (VSAT) satellite communications equipment, widely utilized enterprise Cisco networking hardware, and Schneider Electric EcoStruxure industrial control and automation systems. By querying the AI on these technical specifications, the threat actors sought to identify vectors for electronic warfare, communication disruption, or localized cyber-intrusions. In response to these activities, Anthropic confirmed that it immediately banned the offending accounts, deployed enhanced behavioral detection mechanisms, and formally shared its intelligence findings with relevant U.S. government authorities.

Acceleration of Regional Missile and Rocket Programs in Yemen
While the strategic direction originates from Tehran, the operational deployment of AI-assisted engineering extends deep into regional proxy networks. The threat intelligence report revealed a sophisticated cell operating in northern Yemen under the control of Houthi leadership—factions closely aligned with Iran—that utilized Claude Code to accelerate multiple domestic weapons development programs.
Rather than relying on traditional groups of aeronautical and software engineers, the cell utilized multiple instances of the AI model as an automated engineering workforce. The technology was directly applied to three major munitions initiatives:
- A guided rocket system utilizing an off-the-shelf, phone-class flight computer to assist with terminal guidance phases.
- A multistage ballistic missile program designed with a projected operational range exceeding 2,000 kilometers.
- The R2000 missile family, which notably included a hypersonic glide vehicle (HGV) variant.
The engineering tasks offloaded to the AI model were foundational to modern precision-guided munitions. The actors employed Claude to write and debug guidance, navigation, and control (GNC) software; integrate open-source autopilot frameworks with inexpensive phone-class hardware; formulate position-estimation algorithms; tune operational flight parameters; construct embedded firmware; and execute virtual flight simulations. By substituting human engineering hours with automated code generation, the Houthi-controlled cell demonstrated how readily accessible commercial AI tools can compress the research and development timelines typically associated with state-sponsored defense programs. Although technically operating outside Iran’s direct borders, these proxy groups maintain robust technological exchanges with Tehran, raising concerns that localized software breakthroughs can be seamlessly transferred to broader state-run industrial manufacturing bases.
Domestic Surveillance and Social Media Profiling
The misuse of advanced artificial intelligence extended well beyond kinetic military applications into the realm of domestic social media surveillance and opposition monitoring. Iranian paramilitary and internal security agencies deployed Claude to conduct mass-surveillance campaigns targeting political dissidents, civil society figures, and anti-regime voices both domestically and internationally.
In one documented operation, an Iran-linked security unit utilized the AI model to ingest, parse, and analyze 155,216 individual public posts (tweets) scraped from social media platforms over a single 12-month period. The objective of this massive data processing effort was to systematically profile, identify, and surveil 6,388 specific opposition individuals. By automating sentiment analysis, behavioral pattern matching, and social network mapping, the security apparatus was able to construct comprehensive dossiers on dissidents with unprecedented speed.

In a separate campaign, an affiliated actor established an automated engineering pipeline using Claude to develop proprietary tracking and harvesting software. This effort culminated in the deployment of a malicious Firefox browser extension titled "al-Najm al-thāqib" (The Piercing Star). The extension was engineered to stealthily mass-harvest user identities, browsing telemetry, and personal credentials across major social media and communication platforms. Confronted with these breaches of its acceptable use policies, Anthropic enacted bans against 16 distinct accounts linked to Iranian paramilitary and domestic security institutions. However, cybersecurity analysts note that such mitigation efforts represent an ongoing game of cat-and-mouse, as threat actors continually rotate infrastructure, use proxy identities, and adapt their prompting techniques to evade automated detection systems.
Broader Geopolitical Implications and Industry Response
The revelations from Anthropic’s threat report emphasize a critical dilemma facing the artificial intelligence industry and international policymakers: the dual-use nature of generative AI. While foundational models are built to foster global scientific advancement, commercial software engineering, and educational enrichment, their underlying capabilities in coding, data synthesis, and technical reasoning are inherently agnostic to the moral intent of the user.
Security researchers point out that Iran is not an isolated actor in this domain. Similar threat intelligence evaluations across the technology sector have consistently indicated that state-sponsored cyber-espionage and military modernization units in nations such as the People’s Republic of China and the Russian Federation are actively exploring and integrating Western AI models into their respective defense ecosystems. These nations recognize that commercially available frontier models often surpass domestic AI developments in certain coding and reasoning benchmarks, making them highly attractive targets for intelligence exploitation.
The implications for international security are profound. As AI models become more autonomous and capable of handling complex end-to-end software engineering and system design, export controls traditionally focused on physical hardware—such as high-performance graphics processing units (GPUs), semiconductor manufacturing equipment, and dual-use aerospace materials—may prove insufficient. Securing the AI supply chain now requires a multi-layered defense strategy combining rigorous identity verification, real-time behavioral monitoring, advanced red-teaming against military use-cases, and close public-private partnerships between artificial intelligence labs and national security agencies.
Ultimately, the findings published by Anthropic serve as a stark reminder that the digital battleground of the 21st century extends deeply into commercial codebases. As adversarial states and non-state actors continue to probe the limits of commercial artificial intelligence, technology companies face mounting pressure to fortify their safety guardrails without stifling legitimate technological innovation, establishing a fragile balance that will define the future of global cybersecurity.







