Sophisticated Attacks No Longer Need Sophisticated Attackers


Dear Decision Maker,

Thank you for sticking with me. I want to talk about a very interesting topic today, but before I do, some updates, and the reason I have not been around.

We moved house. Actually, we moved country, me and my family. That has taken a lot of time and effort, as you can imagine. On top of that my wife is eight months pregnant, which creates another layer of complication, and we have a two year old toddler.

A lot of moving parts. And I am running two different companies in two very different fields.

So it has been full on. It has taken me a long time to just sit down and collect my thoughts. I have been travelling too, from the Middle East to Africa to inside Europe. I am finally back home this week.

We also have a lot of family stuff going on, and some health issues with our unborn child. That has taken a lot of brain power and time to support my wife and the family.

Honestly, it was also good for me to unplug for a while and recharge. Everything will always be in flux. There is always something going on. Right now I feel like I am in slightly more settled waters.

I will be travelling again this coming week, not far, but still, and then until the end of October. When the baby comes, travel is banned in our household.

Grey Dynamics has had a couple of mutations too. A lot of new people have joined; I will talk about who they are and what they will be doing in the next email.

We have been doing some really interesting things on the courses and on the website itself.

Our enterprise subscription has finally started. We welcomed and onboarded our first customer, an European government, to be more specific a Ministry of Defence.

I am very glad to support them, and I am looking forward to a lot more in the coming months.

On the courses: we have an awesome course on geospatial intelligence coming out next month with an awesome trainer, Brian Cameron. Ten years at NGA, a couple of years at the agency after that, and now in the private sector. Great human being, and I love working with him.

More short term: the illustrious Travis Button, our trainer for the TECHINT Course, is doing a webinar. If you are interested in arms, arms technology, defence technology and how it is moving, that one is for you.

Right. Let's get into the topic of the week.

The report

On 10 September Anthropic published its latest threat report, "Detecting and countering misuse of AI: September 2026."

It covers activity their Threat Intelligence team disrupted between December 2025 and August 2026, across seven harm areas:

  1. Cyber operations
  2. Influence operations
  3. Surveillance
  4. Scams and fraud
  5. Biological misuse
  6. Conventional weapons development
  7. Distillation.

I read the whole thing. It is long.

And I want to be clear about what it is: a company reporting on misuse of its own product. It is not neutral.

But it is also a window into real-world tradecraft that, as they say themselves, governments and UN panels usually only piece together afterwards from recovered hardware and public sources.

A model provider sees it at the production stage.

Here is what stood out to me, thinking out loud.

1. Sophistication is no longer a signal

This is the line that stopped me. Their own words:

“For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation.”

The examples they give are a:

  • hacktivist using stolen API keys
  • Financially motivated individuals
  • State espionage operator

Each sustaining multi-victim campaigns that a year ago would have needed many skilled operators and specialist knowledge.

If you have spent any time in attribution work, you know how much we lean on sophistication as a tell.

Custom tooling, clean tradecraft, patience: that used to say "state".

According to this report, that assumption is now unsafe. Plan accordingly.

2. AI is not the assistant anymore. It is the orchestrator.

The report says a majority of the cyber operations were enabled by AI via direct execution or orchestration, using multi-agent frameworks that ran reconnaissance, exploitation and exfiltration.

Humans stayed in the loop mainly to set targets and review what came out.

Two cases show what that looks like in practice:

GTG-20006

Which Anthropic says is consistent with public reporting on Midnight Blizzard, ran AI agents that monitored whether their malware was being detected by security products.

If it was, the agents autonomously modified and rebuilt it until it was undetected.

Targets included more than 20 organisations:

  • Government ministries
  • Defence
  • Intelligence bodies
  • Embassies
  • Think tanks
  • Defence-industrial companies

Concentrated in Ukraine and Europe with a recurring theme on drone supply chains.

They also compromised at least three hotel guest WiFi vendors and hijacked DNS to push malware onto guests' devices.

GTG-10007

Chinese-speaking operators likely in Changsha, Hunan.

Two were identified as undergraduate students.

They ran what the report calls an exploit foundry: autonomous workflows doing vulnerability research around the clock, including against a major security product, and producing multiple previously unknown vulnerabilities.

Roughly fifty organisations targeted.

They ran "agent swarms" with persistent campaign memory, so work carried on while the owners were away.

Undergraduates. Think about that.

3. Your AI keys are now loot

This one is directly relevant to anyone running a business.

Stolen API keys and session tokens have become the sole objective of some criminal groups.

The report lists three things an attacker gets from your AI credentials:

  1. Loot (resale value)
  2. Compute (their attack runs at your expense)
  3. Cover (the activity is attributed to you)

One hacktivist campaign ran for a month entirely on stolen keys.

One method they describe: fake websites offering discounted access to frontier models, delivering credential harvesters disguised as popular AI tools, including Claude Code.

Their advice is simple and I agree with it: treat AI keys and agent integrations with the same seriousness as production credentials.

Buy access only through authorised channels. A discount that routes your traffic through an unknown intermediary is not a discount.

4. Influence operations in our neighbourhood

This is the part we are very interested in, because it is Africa.

Central African Republic

A Russian-speaking actor in Bangui ran a daily content operation through Radio Lengo Songo (98.9 FM), coordinated with RT, Sputnik Afrique, TASS and the Russian House in Bangui.

Anthropic links the actor to Politology, the Africa Corps/Wagner influence branch they assess came under SVR control in late 2023.

The model was used not just for content but for the apparatus:

  1. Employment contracts mandating loyalty to the CAR President and "Russia and its contingent"
  2. Scoring rubrics to rank staff
  3. A three-strike dismissal process
  4. Forged Gendarmerie
  5. Ministry of Defence documents
  6. Recurring surveillance file on opposition figures

Rated Category Four on the Breakout Scale: real reach, through FM radio.

Democratic Republic of Congo

A France-based digital advertising agency, LKM Company, ran an influence-as-a-service network of roughly 70 fake news websites and over 250 inauthentic commenting accounts, publishing at least 8,913 articles in about 20 languages.

Political stance shifted depending on who was paying.

The heaviest single focus was the DRC, with 318 articles, mostly supporting the government position on mineral deals and tensions with Rwanda.

Anthropic found no evidence of government direction.

Category Two: little real engagement.

Two things I take from this.

First, influence is now a commercial product with plausible deniability built in.

Second, and this is the contrarian bit: most of these operations failed to reach a genuine audience.

The report says so plainly.

The widest authentic reach came where state media was the distribution mechanism: FM radio, satellite, shortwave, global television.

Distribution still beats generation.

Content is cheap.

Audience is not.

5. Surveillance: the engineering team is gone

The report describes AI being used in place of an engineering workforce. The case that hit closest to home for me is Mali.

A single subscriber, likely a Bamako-based consultant working with Mali's state intelligence service (ANSE), used the model to build "Lakana 360", a domestic surveillance platform covering roughly 25 million SIM cards across all three national mobile operators.

  • Call records
  • SMS
  • Voice
  • Cross-SIM voiceprint tracking
  • Flagging of VPN and encryption users
  • Geofenced watch lists
  • Matching against the national biometric registry

The warrant requirement for generating a dossier on a phone number was removed at the operator's request.

And here is the uncomfortable part: the platform runs on-premises with local models.

Banning the account disrupted the design work.

It did not disrupt the deployment.

Elsewhere: a PRC religious affairs intelligence unit that once had many teams of analysts is now reportedly a single office producing thousands of investigations a month.

And a PRC-aligned actor with no Arabic ran a multi-day recruitment operation against Uyghur targets in Syria, with the model drafting outreach in the regional dialect and translating replies in real time.

6. Weapons

Six cases: three in China, two in Russia, one in Yemen.

The Yemen cell was working on a guided rocket, a multi-stage ballistic missile with a stated range goal above 2,000 km, and a missile set with a hypersonic glide vehicle variant.

They used the model in place of human software engineers for guidance, navigation and control code, running several instances as a small team: one writing, one researching, one reviewing.

They test-fired a guided rocket.

It appears to have failed.

Within hours they were back asking why.

Anthropic says it has no evidence they fielded an operational device, and that many requests were blocked.

But not all. A

nd the actors had already built an offline simulation toolkit that does not depend on any AI provider.

7. The rest, briefly

  • Fraud: a China-based studio built over 20 dating apps with more than 4,700 AI personas talking to at least 25,000 people over two weeks in April 2026, roughly 2.36 million messages, mixed with real gig workers at about three bots to one human for video calls and authenticity checks.
  • Bio: five case studies. Anthropic's own conclusion is that these are evidence of state-linked dual-use research routinely evading access controls, not evidence of imminent biological threats.
  • Distillation: further attacks from seven China-based labs, routed through proxy "transfer stations" using fake identities, stolen cards and stolen API keys. Only the generally available models; nothing against the restricted ones.

So what do I actually think?

Three things.

One.

Everything I wrote in the AI newsletter earlier this year still stands.

The models do the volume; humans set the targets and make the judgement.

The report says exactly that about the attackers. Humans remained in the loop to set targets and review exfiltration.

While, adversary is using AI the way I told you to use it. That should tell you something about the pace of this.

Two.

The old signals are breaking.

If sophistication no longer tells you who is behind an operation, then attribution has to lean harder on the things AI cannot fake:

  1. Human sources
  2. Behavioural patterns
  3. Infrastructure history
  4. Ground truth

The report itself notes that the attacks were familiar: stolen credentials, unpatched edge devices, phishing.

What changed was speed, scale and depth, not the playbook.

Three.

For those of us working in Africa and the Middle East, this is not abstract.

CAR. DRC. Mali. Yemen. Syria.

These are the theatres in the report.

The tooling has arrived on the ground before most of the institutions there have any idea it exists.

“Information costs money. Intelligence makes money.”

And right now the people paying attention to this are not the people who should be.

Ahmed
CEO Grey Dynamics
Where headlines end, ground truth begins


Hi! We are Grey Dynamics

Our mission is to provide comprehensive and actionable intelligence to businesses, government agencies, and private clients. With a team of experienced intelligence collectors and analysts, many with backgrounds in intelligence services, military, law enforcement, and academia, we are committed to delivering insights that drive informed decision-making.

Read more from Hi! We are Grey Dynamics

Dear Decision Maker, Roughly 50,000 people crossed into one small Spanish city on the African Continent in little over a day. At least 67 of them died doing it. And within two days, almost all of them had walked back into Morocco. Voluntarily. That is Ceuta this week. And if your feed looks anything like mine, you already got the verdict before you got the facts: "Hybrid warfare. Morocco weaponising migrants against Spain." And the proof, the thing everyone kept resharing, was a video of...

Dear Decision Maker, First, an apology. Last week's newsletter didn't reach everyone. Some of you got it, some of you didn't, and that's on us. We had a technical issue on the send, and we've fixed it. If you felt like you'd been dropped, you hadn't. Thank you for sticking with me. Now, to this week. I've been thinking about this topic for a while. It keeps coming up: In client conversations In the headlines In the quiet questions people ask me when the recording stops I've written before...

Dear Decision Maker, I'm Travis Butson, Technical Intelligence Instructor here at Grey Dynamics. Ahmed has given me the reins for the email this week to introduce myself, share a little about my background, and talk in detail about Grey Dynamics’ recently released Technical Intelligence Fundamentals course. Experience and Passion, in equal measure. We were all weird as kids right? Everyone had their thing they were infatuated with, whether it was farm machinery or trains, or any one of the...