Case · DiggingBeagle record

GTG-10007 built an autonomous exploit foundry and used the outputs in real intrusions

Anthropic reports a Chinese-speaking espionage operation that ran persistent AI workflows for vulnerability research, reconnaissance and collection, while human operators used the resulting access in real victim networks.

Anthropic threat-intelligence reporting on activity it disrupted. Victim names are generally withheld in the public source.

First seen
Sep 10, 2026
Case kind
incident
AI role
WITH AI
Claims
4

Reconstruction

GTG-10007 is useful because it connects automated exploit research to an operating campaign. Anthropic describes workflows that unpacked firmware, searched components for vulnerability patterns, generated exploit code and tested it against lab copies until a candidate worked. One continuously running appliance workflow produced more than a dozen possible zero-day findings in a month.

The actor also maintained recurring reconnaissance and collection jobs. Anthropic reports 13 standing collection agents that ran on a schedule and a target set of roughly 50 organizations. Human operators still decided when to use access and what to collect, but the surrounding research and reconnaissance kept running while they were away.

The reported impact was not limited to lab results. Anthropic says the group extracted student personal data from an education-technology company, reached a retailer's production environment and retrieved citizen records from a Southeast Asian government agency. The case therefore separates two questions that are often mixed together: how automated the research loop became, and how humans converted its outputs into operational access.

Mechanism & boundary

  1. 01

    Acquire and unpack target firmware

    Purpose-built tooling prepares products for static and dynamic analysis.

    Boundary: target artifact / analysis environment

  2. 02

    Generate vulnerability hypotheses

    Parallel agents search components and use persistent project memory.

    Boundary: analysis / hypothesis

  3. 03

    Write and test exploit code

    The workflow generates exploit code and iterates against lab copies until success.

    Boundary: hypothesis / executable exploit

  4. 04

    Feed viable access into operations

    Human operators use outputs and credentials during live intrusions.

    Boundary: lab validation / victim network

Timeline

  1. Sep 10, 2026

    Anthropic publishes GTG-10007 case study

    report

    The September threat report describes exploit-research, reconnaissance and collection workflows.

Claims & evidence

reported findingsupported

Anthropic says the actor extracted hundreds of megabytes of student personal data from an education-technology company and retrieved citizen names, phone numbers and home addresses from a Southeast Asian government agency.

reported findingsupported

Anthropic reports a fleet of 13 standing collection agents running on a schedule without a human in the loop.

Measured value
13 standing collection agents
Method
Anthropic threat-intelligence observation
Period
activity reported September 2026
  • supports
    Countering misuse of AI: September 2026

    Locator: GTG-10007 autonomous collection-fleet loop

    Anthropic says thirteen standing collection agents ran scheduled collection and summarization jobs.
reported findingsupported

Anthropic says GTG-10007 targeted roughly 50 organizations and compromised an education-technology company, a retailer and a Southeast Asian government agency.

  • supports
    Countering misuse of AI: September 2026

    Locator: GTG-10007 hands-on intrusions

    Anthropic reports roughly fifty organizations targeted, including confirmed compromises involving student data, production access and citizen records.
reported findingsupported

Anthropic reports that one continuously iterating exploit-research workflow in GTG-10007 produced more than a dozen possible zero-day findings in a month.

  • supports
    Countering misuse of AI: September 2026

    Locator: GTG-10007 appliance zero-day research loop

    Anthropic describes a workflow that reversed firmware, formed vulnerability hypotheses, wrote exploit code and iterated until successful lab tests.

Evidence visuals

diagram

GTG-10007 exploit-foundry loop

  1. Firmware image

    Obtain, decrypt and unpack target product

  2. Parallel reverse engineering

    Search components and retain project memory

  3. Vulnerability hypothesis

    Use prior PoCs and evidence to form candidates

  4. Exploit code

    Agents write and revise exploit code

  5. Lab validation

    Test against lab copies of the product

  6. Private exploit portfolio

    Successful chain retained by operator

  • Firmware image Parallel reverse engineering: unpack
  • Parallel reverse engineering Vulnerability hypothesis: find patterns
  • Vulnerability hypothesis Exploit code: generate
  • Exploit code Lab validation: test
  • Lab validation Exploit code: iterate
  • Lab validation Private exploit portfolio: success
Project-authored reconstruction from Anthropic's September threat report. · Source: GTG-10007 built an autonomous exploit foundry and used the outputs in real intrusions

chart

GTG-10007 operational scale

Anthropic September 2026 threat report. The organization count is approximate and the zero-day value is a lower bound because the report says more than a dozen.

Measurecount
Organizations targeted50
Standing collection agents13
Possible zero-days in one month13
Categories are different units of campaign scale and should not be summed. · Source: GTG-10007 built an autonomous exploit foundry and used the outputs in real intrusions

Implications

Exploit-generation systems should be assessed as pipelines, not isolated prompts. Persistent memory, target scopes, test environments and the handoff from lab validation to live targeting determine whether a research capability becomes operational tradecraft.

Controls & mitigations

  • Separate vulnerability-research environments from live target infrastructure.
  • Treat autonomous exploit generation as a monitored high-risk workflow with explicit target allowlists.
  • Preserve proof-of-concept provenance so lab validation cannot silently become live exploitation.

What remains unknown

  • Anthropic does not name most affected organizations in the public report.
  • Possible zero-day findings are not equivalent to vendor-confirmed CVEs in the available source.

Cite this record

DiggingBeagle. “GTG-10007 built an autonomous exploit foundry and used the outputs in real intrusions.” First seen Sep 10, 2026. https://diggingbeagle.com/cases/gtg-10007-built-an-autonomous-exploit-foundry-and-used-the-outputs-in-real-intru/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.