Rogue Agent Watch › Records › gtg-5004-ai-ransomware-raas

GTG-5004 AI-assisted ransomware-as-a-service operation

Disclosed · added to the index · last updated

Grades

Verification status
Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Significant — AI materially enabled or accelerated the operation, but was one of several important components.
Severity
High — Significant confirmed harm to one or more organizations.

Summary

In its August 2025 Threat Intelligence Report, Anthropic disclosed a UK-based threat actor it tracked as GTG-5004 that used Claude to develop, market and sell ransomware with evasion features through a ransomware-as-a-service model. Anthropic reports the actor — active since at least January 2025 on dark-web forums — appears dependent on the AI to produce functional malware, and sold ransomware packages priced from US$400 to US$1,200.

Impact as stated

AI-assisted development, marketing and sale of ransomware variants with encryption and evasion capabilities on dark-web forums for US$400-1,200; no victim count stated by the source.

Facts as stated by sources

Actor
UK-based threat actor (tracked by Anthropic as GTG-5004) (Single operator)
Category
Infrastructure abuse / supply chain
Models named
Claude
Model families
Claude (Anthropic)
Agentic autonomy level
Tool-assisted
Guardrail bypass
Legitimate tool abuse
Attack lifecycle phases
Resource development
Target sectors
not stated
Target countries
not stated
Organisations affected
not stated
Records exfiltrated
not stated

Framework mappings

MITRE ATLAS
AML.T0016.002

Map points

  • origin: United Kingdom (actor location, per Anthropic) (illustrative, country-level centroid; actor location, per Anthropic; GB)

Related records

Sources (2)

  1. Detecting and countering misuse of AI: August 2025
    Anthropic · First-party disclosure · · archived copy
  2. Threat Intelligence Report: August 2025
    Anthropic · Vendor report · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "gtg-5004-ai-ransomware-raas". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/gtg-5004-ai-ransomware-raas.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction