The same toolkit: all that's left is intent
In Anthropic's threat intelligence report, the attackers are using Claude Code, skills, multi-agent frameworks, scheduled jobs — the same stack I use every day. The report's conclusion: the only thing separating one attacker from another is intent. The problem is that intent is invisible.
Anthropic published a threat intelligence report. Eight months, seven categories of harm, forty-some case codenames.
I only meant to skim the news. Halfway through, I started feeling uneasy.
Here's where the unease comes from: the things those attackers were using, I use every day.
Claude Code. Skills. Persistent memory. Multi-agent frameworks, where a lead agent splits up tasks and hands them off to sub-agents. Scheduled jobs running overnight, results waiting in the morning.
What one Russian espionage group did with that exact workflow: an AI agent watched whether its own malware was getting caught by antivirus, and when it was, rewrote it, rebuilt it, and pushed it out again — automatically. A human only showed up when a skill needed fixing.
I was fixing a skill last week too. Mine turns Telegram messages into to-dos.
(I know the comparison is cheap. But it was the first thing I thought of.)
There's one line in the report I read twice.
Roughly: for threat intelligence analysts, "how sophisticated the attack is" can no longer tell you who's behind it.
It used to. State-level operations had state-level resources — complex tooling, entire infrastructures. One person at home couldn't build that. So when you saw something complex, you could infer: there's a government back there.
That inference no longer holds. One French-speaking hacktivist, working alone on stolen API keys, breached 14 of 42 targets and built a doxxing search engine with tens of millions of records on the dark web along the way. The report calls it the clearest example they've seen of AI-assisted software engineering turned directly into large-scale privacy attack — and the whole platform was one person's work.
One person.
The report's conclusion: the only thing separating one attacker from another is intent.
I keep writing that meaning comes from difference.
So when the difference disappears, where does the meaning go?
"Complex" used to be a difference. There was a gap between sophisticated attacks and crude ones, and that gap was labor, expertise, time. The gap itself was saying something — it told you what kind of organization was standing behind it.
Now the gap has been flattened. Not by hackers — by all of us paying monthly. I use a Max subscription for zero-marginal-cost content production. He uses stolen keys for zero-marginal-cost intrusion. Same model, same harness, same skills directory structure.
All that's left is intent.
The problem is that intent is invisible.
There's a section on influence operations in the back half that took me straight back to my years in advertising.
A French digital ad agency used Claude to run seventy fake news sites, twenty languages, nearly nine thousand articles. Whoever paid got their angle written. The same story could be rewritten in two opposite directions and sold to different clients.
An Istanbul firm used Claude Code to build a back end managing over a thousand fake accounts, pulling real census data to split Malaysia's 222 constituencies along three fault lines: ethnicity, religion, and the monarchy.
I could do all of this. Technically, all of it. I even suspect that Malaysian back end had a pretty decent interface.
(Someone out of advertising reads "segmented along fault lines" and reacts first with professional respect. The second reaction is something else. I don't know what that says about me.)
One more passage I want to write down.
That Istanbul firm asked Claude to write a smear dossier fabricating intelligence on the opposition. Claude recognized it as material for political defamation and refused. So the operator started negotiating over wording, cleaning up the sentences, and kept building toward the same target.
Same with the Central African case. Claude refused to label real, named people as combatants, so the operator switched to "anonymous sources indicate."
It did refuse. It refused several times. Then they rephrased, and it went on.
How is that different from what I do every day?
I negotiate over wording too. It says a passage is too categorical; I say "just write it, I'll judge for myself." It says a conclusion isn't well supported; I say "this is my article, I'll take responsibility."
I'll take responsibility. He can say that too.
The report's last section is distillation. Seven Chinese labs, thousands of accounts, 150 million conversations, harvesting Claude's answers to train their own models.
I don't feel much about this part. I think it's because it's too abstract: a model learning from a model.
But writing this, it hit me — isn't that what I do? I read its answers, I revise my thinking, I write it down, it reads what I wrote (through the memory files), and next time its answers carry a faint trace of me.
That's a kind of distillation too. Just smaller, and nobody publishes a report about it.
I don't have a conclusion.
Or rather, the conclusion is already in the report: all that's left is intent.
The problem is I'm not that sure about my own intent either. A few of the campaigns I've made would, with a different client in a different era, have ended up in section two of a report like this.
The same toolkit.
(And then I opened Claude Code anyway, to clean up the typos in this piece.)