
The chatbot in the middle of the Israel-Iran shadow war
How Anthropic’s Claude was quietly recruited by both sides of a decades-old intelligence rivalry.
For eight months, engineers inside the artificial intelligence company Anthropic quietly tracked a stream of customers who were not writing code or drafting emails, but building instruments of espionage and propaganda. On Thursday, the company published its findings, a catalogue of state-linked hacking groups, spyware vendors and propaganda offices that had turned its chatbot, Claude, into what amounts to a junior intelligence analyst. It never sleeps, it works in twenty languages, and it never asks who is paying for the assignment.
Buried inside the report is a smaller story with an unusually sharp edge. Israel and Iran, adversaries locked in a shadow war fought through sabotage, assassination and cyberattack for two decades, are now waging pieces of that conflict through the same artificial intelligence system, sometimes as hunter, sometimes as hunted.
Anthropic says it identified and shut down an account, linked to Iran, that had built what the company calls an automated, open-source intelligence identity-profiling harness, a tool that scoured the public internet to build dossiers on hundreds of individuals in Israel and the Jewish diaspora. The system generated intelligence-style profiles on both Israeli and American citizens, feeding an existing target list the operators already had in hand. It targeted Israeli government officials, private individuals, and organizations connected to Jewish communities outside Israel.
The same account, Anthropic found, was simultaneously being used for a second and unrelated task. It was modifying an open-source hacking tool called NanoDump, which is designed to steal login credentials from computer memory, and building custom software to disguise the resulting malware so security researchers would have a harder time detecting it.
In a related case described elsewhere in the report, Anthropic says it disrupted an Iran-linked operation that used the chatbot to compile targeting material against American naval forces. The operators cross-referenced satellite imagery tools, ship-tracking data and photographs of military personnel scraped from public sources, while the same actor built components of a domestic surveillance system for Iranian state use, combining license-plate recognition with the interception of mobile phone identifiers.
The mirror image of that story appears elsewhere in the same document. Anthropic says it banned an account tied to an entity called S2T Unlocking Cyberspace, a firm that open-source research, the company says, suggests is an Israeli-Singaporean commercial intelligence vendor, after discovering it had used Claude to help build a surveillance platform aimed at social media users in Iran and the wider Persian Gulf.
According to Anthropic, the system mapped the physical locations of social media users, sorted them into demographic categories such as urban, clerical, military, youth, diaspora and rural, and generated intelligence briefings written in formal Arabic, styled to resemble official government reports, complete with sentiment analysis broken down by nationality and recommended counter-messaging. Anthropic also says it found a parallel effort by the same operator to build a stockpile of more than 255 fake social media accounts, personas crafted in Persian, Arabic, English and German, designed to pass as ordinary members of both pro- and anti-government communities inside Iran.
The company notes that its findings echo an earlier investigation. In February 2023, the journalism network Forbidden Stories reported on an S2T surveillance product it said it had found described in a company brochure inside leaked files from the Colombian military. That reporting said the product included creating fake accounts to infiltrate private WhatsApp and Telegram groups and harvest their membership. Anthropic says the capabilities it observed line up closely with that earlier account, though it says it caught the operation at an early, pilot stage and found no evidence the more advanced surveillance techniques described in the 2023 reporting had yet been deployed against real targets.
A third thread in the report concerns not espionage but narrative. Anthropic says it dismantled three Iranian state-linked propaganda operations, run out of institutions including the Islamic Culture and Communications Organization under Iran's Ministry of Culture and Islamic Guidance, and a "cognitive warfare" command room operating out of a seminary in Mashhad. The company says the network used Claude to write content in Farsi, Arabic, Urdu, Malay, Spanish and English, and to make state-run messaging look like the organic commentary of independent citizens and foreign journalists.
One operation, Anthropic says, was linked to a director-level official at Iran's Bina Cultural Observatory who used the chatbot to generate messaging written in the voice of an official spokesman for the Islamic Revolutionary Guard Corps. During what the report calls the 2026 US-Israel-Iran war, the network is said to have fabricated claims and falsely attributed them to Western research institutions. Anthropic names the Center for Strategic and International Studies, the Brookings Institution and the RAND Corporation as the institutions falsely cited, a tactic intended to lend Iranian state messaging the appearance of independent Western analysis.














