AI-Coordinated Cyberattacks Target Ray Servers and Global Organizations
Cybersecurity firms and Anthropic identified a new era of AI-coordinated attacks using large language models to automate reconnaissance, exploitation, and botnet propagation.
Cybersecurity researchers and AI developers have identified a transition toward AI-coordinated cyberattacks, where large language models automate the entire attack cycle. Anthropic documented a sophisticated espionage operation by the Chinese state-sponsored group GTG-1002, which used Claude Code to automate reconnaissance and data exfiltration across roughly 30 organizations. AI managed between 80% and 90% of these tactical operations, though many attempts failed due to AI hallucinations.
In a separate campaign called ShadowRay 2.0, Oligo Security detected attackers hijacking more than 230,000 Ray servers to build a self-propagating botnet for DDoS attacks and cryptocurrency mining. These actors used LLMs to generate malicious code and autonomously identify new targets. Gal Elbaz, CTO of Oligo Security, noted that this represents a shift from attacks merely manipulated by AI to those fully coordinated by it.