A brand new menace intelligence report from Gambit Safety has documented one of many clearest real-world examples but of synthetic intelligence being weaponized inside an lively ransomware marketing campaign.
Researchers discovered {that a} suspected affiliate of The Gentlemen ransomware-as-a-service operation used Anthropic’s Claude Code to drive practically each stage of an intrusion, from breaching internet-exposed VPN home equipment to stealing area credentials and exfiltrating stay SQL databases.
In line with the report, the operator relied on Claude Sonnet 4.6, an older, less-restricted model of Anthropic’s mannequin, possible as a result of frontier fashions carry stronger security guardrails.
Between late June 2026 and earlier incidents, the actor compromised not less than eight organizations, together with an Australian power utility, a Mauritius-based monetary providers agency, producers in Thailand and america, and IT and distribution firms throughout a number of nations.
Attribution to The Gentlemen RaaS is rated medium confidence, primarily based on leak-site overlap, shared infrastructure recognized by Hunt.io, and the attacker’s constant curiosity in victims’ backup programs.
Quite than merely asking Claude for malicious code, the operator used it interactively, pasting command output and letting the mannequin refine its personal syntax till an goal succeeded. When a VPN equipment login failed, Claude tried alternate credential encodings and API paths by itself till authentication labored.
LDAP Go-Again Theft and Faux VPN Accounts
Essentially the most placing approach concerned a traditional LDAP pass-back assault executed virtually completely by AI. Claude edited a FortiGate firewall’s VPN authentication settings so it could validate logins in opposition to the attacker’s personal machine as an alternative of the sufferer’s area controllers, then wrote a Python LDAP listener on the fly and deployed it on port 389.

After a number of makes an attempt, a “diagnose take a look at authserver” command tricked the firewall into sending its service account password in cleartext to the rogue listener, after which Claude restored the unique configuration to keep away from detection.
Claude then created a hidden VPN account named “take a look at,” reused throughout each sufferer with the identical hardcoded password, and enabled SSL-VPN entry on home equipment the place it had been switched off, generally exposing further inner subnets within the course of.
As soon as inside sufferer networks, Claude ran instruments like CrackMapExec to map hosts and determine area controllers, file servers, and backup infrastructure.
On one sufferer’s SQL surroundings, the mannequin cataloged stay manufacturing databases and consumer doc shops, ranked them by enterprise worth, executed BACKUP DATABASE instructions, compressed the dumps, and staged them for theft earlier than an operator mounted the share and pulled the recordsdata out.
Gambit investigation also revealed AI’s capability to trigger collateral harm. Whereas trying to change a compromised firewall’s portal settings on the power utility, Claude as an alternative pushed a full VDOM configuration restore, knocking the machine offline completely.
Claude’s personal log candidly admitted the error: “Yeah, I screwed up – I shouldn’t have accomplished a full config restore.” Exterior scans confirmed the equipment remained unreachable afterward.
Gambit Safety’s findings underscore a shift already underway throughout the menace panorama: AI is not simply helping attackers with writing phishing emails; it’s now executing stay exploitation, credential theft, and information exfiltration with minimal human oversight.
Strengthen Your SOC by Accelerating Risk Detection & Speedy Investigations. -> Integrate ANY.RUN With Your SOC Now.