[ad_1]
A brand new menace intelligence report from Gambit Safety has documented one of many clearest real-world examples but of synthetic intelligence being weaponized inside an energetic ransomware marketing campaign.
Researchers discovered {that a} suspected affiliate of The Gentlemen ransomware-as-a-service operation used Anthropic’s Claude Code to drive practically each stage of an intrusion, from breaching internet-exposed VPN home equipment to stealing area credentials and exfiltrating dwell SQL databases.
In response to the report, the operator relied on Claude Sonnet 4.6, an older, less-restricted model of Anthropic’s mannequin, doubtless as a result of frontier fashions carry stronger security guardrails.
Between late June 2026 and earlier incidents, the actor compromised at the very least eight organizations, together with an Australian power utility, a Mauritius-based monetary providers agency, producers in Thailand and america, and IT and distribution corporations throughout a number of nations.
Attribution to The Gentlemen RaaS is rated medium confidence, based mostly on leak-site overlap, shared infrastructure recognized by Hunt.io, and the attacker’s constant curiosity in victims’ backup techniques.
Moderately than merely asking Claude for malicious code, the operator used it interactively, pasting command output and letting the mannequin refine its personal syntax till an goal succeeded. When a VPN equipment login failed, Claude tried alternate credential encodings and API paths by itself till authentication labored.
LDAP Cross-Again Theft and Pretend VPN Accounts
Essentially the most putting approach concerned a basic LDAP pass-back assault executed nearly completely by AI. Claude edited a FortiGate firewall’s VPN authentication settings so it could validate logins in opposition to the attacker’s personal machine as a substitute of the sufferer’s area controllers, then wrote a Python LDAP listener on the fly and deployed it on port 389.

After a number of makes an attempt, a “diagnose check authserver” command tricked the firewall into sending its service account password in cleartext to the rogue listener, after which Claude restored the unique configuration to keep away from detection.
Claude then created a hidden VPN account named “check,” reused throughout each sufferer with the identical hardcoded password, and enabled SSL-VPN entry on home equipment the place it had been switched off, typically exposing extra inside subnets within the course of.
As soon as inside sufferer networks, Claude ran instruments like CrackMapExec to map hosts and determine area controllers, file servers, and backup infrastructure.
On one sufferer’s SQL atmosphere, the mannequin cataloged dwell manufacturing databases and shopper doc shops, ranked them by enterprise worth, executed BACKUP DATABASE instructions, compressed the dumps, and staged them for theft earlier than an operator mounted the share and pulled the recordsdata out.
Gambit investigation also revealed AI’s capability to trigger collateral injury. Whereas making an attempt to change a compromised firewall’s portal settings on the power utility, Claude as a substitute pushed a full VDOM configuration restore, knocking the system offline completely.
Claude’s personal log candidly admitted the error: “Yeah, I screwed up – I shouldn’t have completed a full config restore.” Exterior scans confirmed the equipment remained unreachable afterward.
Gambit Safety’s findings underscore a shift already underway throughout the menace panorama: AI is now not simply aiding attackers with writing phishing emails; it’s now executing dwell exploitation, credential theft, and information exfiltration with minimal human oversight.
Strengthen Your SOC by Accelerating Menace Detection & Fast Investigations. -> Integrate ANY.RUN With Your SOC Now.
[ad_2]
Source link




