GTG-10007 built an autonomous exploit foundry and used the outputs in real intrusions
Anthropic reports a Chinese-speaking espionage operation that ran persistent AI workflows for vulnerability research, reconnaissance and collection, while human operators used the resulting access in real victim networks.
Anthropic threat-intelligence reporting on activity it disrupted. Victim names are generally withheld in the public source.
First seen
Sep 10, 2026
Case kind
incident
AI role
WITH AI
Claims
4
Reconstruction
GTG-10007 is useful because it connects automated exploit research to an operating campaign. Anthropic describes workflows that unpacked firmware, searched components for vulnerability patterns, generated exploit code and tested it against lab copies until a candidate worked. One continuously running appliance workflow produced more than a dozen possible zero-day findings in a month.
The actor also maintained recurring reconnaissance and collection jobs. Anthropic reports 13 standing collection agents that ran on a schedule and a target set of roughly 50 organizations. Human operators still decided when to use access and what to collect, but the surrounding research and reconnaissance kept running while they were away.
The reported impact was not limited to lab results. Anthropic says the group extracted student personal data from an education-technology company, reached a retailer's production environment and retrieved citizen records from a Southeast Asian government agency. The case therefore separates two questions that are often mixed together: how automated the research loop became, and how humans converted its outputs into operational access.
Mechanism & boundary
01
Acquire and unpack target firmware
Purpose-built tooling prepares products for static and dynamic analysis.
Boundary: target artifact / analysis environment
02
Generate vulnerability hypotheses
Parallel agents search components and use persistent project memory.
Boundary: analysis / hypothesis
03
Write and test exploit code
The workflow generates exploit code and iterates against lab copies until success.
Boundary: hypothesis / executable exploit
04
Feed viable access into operations
Human operators use outputs and credentials during live intrusions.
Boundary: lab validation / victim network
Timeline
Sep 10, 2026
Anthropic publishes GTG-10007 case study
report
The September threat report describes exploit-research, reconnaissance and collection workflows.
Claims & evidence
reported findingsupported
Anthropic says the actor extracted hundreds of megabytes of student personal data from an education-technology company and retrieved citizen names, phone numbers and home addresses from a Southeast Asian government agency.
Anthropic says thirteen standing collection agents ran scheduled collection and summarization jobs.
reported findingsupported
Anthropic says GTG-10007 targeted roughly 50 organizations and compromised an education-technology company, a retailer and a Southeast Asian government agency.
Anthropic reports roughly fifty organizations targeted, including confirmed compromises involving student data, production access and citizen records.
reported findingsupported
Anthropic reports that one continuously iterating exploit-research workflow in GTG-10007 produced more than a dozen possible zero-day findings in a month.
Anthropic September 2026 threat report. The organization count is approximate and the zero-day value is a lower bound because the report says more than a dozen.
Exploit-generation systems should be assessed as pipelines, not isolated prompts. Persistent memory, target scopes, test environments and the handoff from lab validation to live targeting determine whether a research capability becomes operational tradecraft.
Controls & mitigations
Separate vulnerability-research environments from live target infrastructure.
Treat autonomous exploit generation as a monitored high-risk workflow with explicit target allowlists.
Preserve proof-of-concept provenance so lab validation cannot silently become live exploitation.
What remains unknown
Anthropic does not name most affected organizations in the public report.
Possible zero-day findings are not equivalent to vendor-confirmed CVEs in the available source.
DiggingBeagle. “GTG-10007 built an autonomous exploit foundry and used the outputs in real intrusions.” First seen Sep 10, 2026. https://diggingbeagle.com/cases/gtg-10007-built-an-autonomous-exploit-foundry-and-used-the-outputs-in-real-intru/
DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.
We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.