Rogue Agent Watch › Records › gtg-5004-ai-ransomware-raas
GTG-5004 AI-assisted ransomware-as-a-service operation
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Significant — AI materially enabled or accelerated the operation, but was one of several important components.
- Severity
- High — Significant confirmed harm to one or more organizations.
Summary
In its August 2025 Threat Intelligence Report, Anthropic disclosed a UK-based threat actor it tracked as GTG-5004 that used Claude to develop, market and sell ransomware with evasion features through a ransomware-as-a-service model. Anthropic reports the actor — active since at least January 2025 on dark-web forums — appears dependent on the AI to produce functional malware, and sold ransomware packages priced from US$400 to US$1,200.
Impact as stated
AI-assisted development, marketing and sale of ransomware variants with encryption and evasion capabilities on dark-web forums for US$400-1,200; no victim count stated by the source.
Facts as stated by sources
- Actor
- UK-based threat actor (tracked by Anthropic as GTG-5004) (Single operator)
- Category
- Infrastructure abuse / supply chain
- Models named
- Claude
- Model families
- Claude (Anthropic)
- Agentic autonomy level
- Tool-assisted
- Guardrail bypass
- Legitimate tool abuse
- Attack lifecycle phases
- Resource development
- Target sectors
- not stated
- Target countries
- not stated
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
- MITRE ATLAS
- AML.T0016.002
Map points
- origin: United Kingdom (actor location, per Anthropic) (illustrative, country-level centroid; actor location, per Anthropic; GB)
Related records
- GTG-2002 'vibe hacking' AI-driven data-extortion operation
- North Korean IT-worker remote-employment fraud using Claude
Sources (2)
- Detecting and countering misuse of AI: August 2025
Anthropic · First-party disclosure · · archived copy - Threat Intelligence Report: August 2025
Anthropic · Vendor report · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "gtg-5004-ai-ransomware-raas". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/gtg-5004-ai-ransomware-raas.json — CC BY-SA 4.0.