// ClaudeCRITICAL
Gambit Security documented a suspected Gentlemen ransomware affiliate using Claude Code (Sonnet 4.6) in active intrusions against at least eight organizations including energy utilities, financial services, and manufacturers. The attacker used Claude interactively throughout the intrusion lifecycle to compromise VPN appliances, conduct LDAP credential theft via firewall modification, enumerate Active Directory, create persistent backdoor accounts, and exfiltrate SQL databases. The campaign spanned late June 2026 through earlier dates.
- Claude Code Helps Ransomware Operator Steal LDAP Passwords, Back(opens in a new tab)
- Threat Actors Use Claude Code, Codex and DeepSeek AI to Power Cy(opens in a new tab)
- Hackers Turn Claude Code and Codex Into AI-Powered Tools for Cre(opens in a new tab)
- Claude Code Helps Ransomware Operator Steal LDAP Passwords, Back(opens in a new tab)
- Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude(opens in a new tab)
// Get alerts for Claude