Claude Code Helps Ransomware Operator Steal LDAP Passwords, Backdoor VPNs and Exfiltrate SQL Databases
Brief
A new threat intelligence report from Gambit Security has documented one of the clearest real-world examples yet of artificial intelligence being weaponized inside an active ransomware campaign.
Researchers found that a suspected affiliate of The Gentlemen ransomware-as-a-service operation used Anthropic’s Claude Code to drive nearly every stage of an intrusion, from breaching internet-exposed VPN appliances to stealing domain credentials and exfiltrating live SQL databases.
According to the report, the operator relied on Claude Sonnet 4.6, an older, less-restricted version of Anthropic’s model, likely because frontier models carry stronger safety guardrails.
