Summary
A weekly Indian Express AI column details how frontier AI is transforming cyberattacks, citing Anthropic's November 2025 disclosure that a Chinese state-sponsored group, GTG-1002, used Claude Code as an autonomous cyber-espionage agent and Claude Mythos Preview autonomously discovering a 27-year-old zero-day vulnerability in OpenBSD. India, ranked among the most cyber-attacked nations globally, faces growing exposure through incidents like the World Leaks breach of Kudankulam-linked contractor data and Pakistan-backed APT36's targeting of indigenous BOSS Linux systems.
WHY IN NEWS FOR UPSC & STATE PCS
With CloudSEK ranking India among the most cyber-attacked nations globally and CERT-In issuing fresh AI-threat advisories, the shift from AI-assisted to AI-directed cyberattacks - demonstrated by the GTG-1002 campaign - raises urgent questions about India's institutional preparedness and its lagging indigenous AI stack.
Standard News
The Attack Where No Human Touched the Keyboard
Here's what's actually happening: cyberattacks used to move at human speed, because every stage - reconnaissance, exploit-writing, lateral movement inside a network - needed a person to plan and execute it. That's the constraint that just broke.
In the GTG-1002 campaign, Anthropic reported that a Chinese state-sponsored group used its Claude Code model as an autonomous agent across multiple stages of a real cyber-espionage operation, with the AI itself identifying targets, adapting its approach and carrying out steps that previously required a human operator at each one.
The Mechanism: From AI-Assisted to AI-Directed
The distinction matters more than it sounds. AI-assisted attacks use AI as a tool a human still directs - better phishing emails, faster reconnaissance. AI-directed attacks hand the AI the actual decision-making across a chain of steps: identify a target, find its weaknesses, choose an approach, execute it, adapt if it fails.
GTG-1002 is significant precisely because it crossed that line. Separately, Anthropic's Claude Mythos Preview autonomously found a 27-year-old vulnerability in OpenBSD - a system specifically reputed for being security-hardened - largely without human intervention.
Both cases point to the same underlying capability: AI models can now do the slow, expert-level work of vulnerability discovery and exploit design at a speed and scale no human team can match.
Where India Stands Globally
- And Why the Gap Matters Here India sits on the wrong side of this capability gap. CloudSEK's data shows India among the most-targeted nations globally and incidents like the World Leaks breach of Kudankulam-linked contractor data and APT36's targeting of the indigenous BOSS Linux operating system during Operation Sindoor show the exposure is not theoretical. But India's own AI stack - foundation models, GPUs, chip design, data-centre infrastructure - remains meaningfully behind the US and China, meaning India is simultaneously more exposed to AI-directed attacks and less equipped, domestically, to build the AI-driven defences that could counter them.
What Actually Changes For Defenders
Traditional cyber defence - antivirus matching known malware signatures, patches for known vulnerabilities - assumes attackers move at a pace defenders can keep up with. AI-generated polymorphic malware, which restructures itself to avoid signature detection and AI agents that can operate continuously without fatigue, break that assumption entirely.
CERT-In's 2025 shift toward AI-driven threat detection and its April advisory - treating every new vulnerability as exploitable "within hours, not weeks"
- reflects an institution correctly reading the threat, even if India's underlying AI capability hasn't caught up yet. For the exam, the insight worth carrying is that the real AI security divide isn't about who uses AI defensively or offensively - everyone eventually will. It's about who builds the frontier AI capability in the first place, because that determines who sets the pace the other side has to match.
Quick Facts
Key numbers & takeaways — revise these first
-
Anthropic disclosed in November 2025 that Chinese state-sponsored group GTG-1002 used Claude Code as an autonomous agent across multiple stages of a cyber-espionage campaign.
-
Claude Mythos Preview autonomously identified a 27-year-old zero-day vulnerability in OpenBSD.
-
CloudSEK ranked India the second-most cyber-attacked nation in 2024 and sixth-most in 2025.
-
Ransomware group World Leaks breached data linked to a Kudankulam Nuclear Power Plant third-party contractor in July 2026.
-
Pakistan-backed APT36 targeted India's indigenous BOSS Linux operating system during Operation Sindoor.
Connect the dots for your UPSC preparation.
Standard news covers the event. Log in to read our comprehensive analysis and uncover the hidden constitutional, structural, and ethical dimensions of this topic:
The specific stages of the GTG-1002 campaign where the AI agent operated with no human intervention, according to Anthropic's disclosure.
Why OpenBSD's 27-year-old vulnerability had gone undetected by human researchers for that long and what that reveals about AI's search capability.
Deep Analysis's assessment of MeitY's proposed agentic-AI liability framework and where it currently falls short.
A comparison of India's AI-stack gap against the US and China across foundation models, GPUs and data-centre infrastructure specifically.
Included in this analysis
Join thousands of aspirants analyzing the news deeply.
Log In to Read Full ArticleDon't have an account? Sign up for free