Topic 10 of 18
GS Paper 3 AI-Enabled Cybersecurity Threats Science and Technology - AI-Enabled Cybersecurity Threats, Critical Infrastructure and India's Policy Response

The Attack Where No Human Touched the Keyboard

Source Indian Express, Bloo, The Hacker News, The Hindu, ORF, Inspira Enterprise

Picture a cyberattack running for days across multiple targets, adapting its own code, choosing its own next move - with no human operator ever touching the keyboard. That is not a hypothetical anymore.

Summary

A weekly Indian Express AI column details how frontier AI is transforming cyberattacks, citing Anthropic's November 2025 disclosure that a Chinese state-sponsored group, GTG-1002, used Claude Code as an autonomous cyber-espionage agent and Claude Mythos Preview autonomously discovering a 27-year-old zero-day vulnerability in OpenBSD. India, ranked among the most cyber-attacked nations globally, faces growing exposure through incidents like the World Leaks breach of Kudankulam-linked contractor data and Pakistan-backed APT36's targeting of indigenous BOSS Linux systems.

WHY IN NEWS FOR UPSC & STATE PCS

With CloudSEK ranking India among the most cyber-attacked nations globally and CERT-In issuing fresh AI-threat advisories, the shift from AI-assisted to AI-directed cyberattacks - demonstrated by the GTG-1002 campaign - raises urgent questions about India's institutional preparedness and its lagging indigenous AI stack.

Standard News

The Attack Where No Human Touched the Keyboard

Here's what's actually happening: cyberattacks used to move at human speed, because every stage - reconnaissance, exploit-writing, lateral movement inside a network - needed a person to plan and execute it. That's the constraint that just broke.

In the GTG-1002 campaign, Anthropic reported that a Chinese state-sponsored group used its Claude Code model as an autonomous agent across multiple stages of a real cyber-espionage operation, with the AI itself identifying targets, adapting its approach and carrying out steps that previously required a human operator at each one.

The Mechanism: From AI-Assisted to AI-Directed

The distinction matters more than it sounds. AI-assisted attacks use AI as a tool a human still directs - better phishing emails, faster reconnaissance. AI-directed attacks hand the AI the actual decision-making across a chain of steps: identify a target, find its weaknesses, choose an approach, execute it, adapt if it fails.

GTG-1002 is significant precisely because it crossed that line. Separately, Anthropic's Claude Mythos Preview autonomously found a 27-year-old vulnerability in OpenBSD - a system specifically reputed for being security-hardened - largely without human intervention.

Both cases point to the same underlying capability: AI models can now do the slow, expert-level work of vulnerability discovery and exploit design at a speed and scale no human team can match.

Where India Stands Globally

  • And Why the Gap Matters Here India sits on the wrong side of this capability gap. CloudSEK's data shows India among the most-targeted nations globally and incidents like the World Leaks breach of Kudankulam-linked contractor data and APT36's targeting of the indigenous BOSS Linux operating system during Operation Sindoor show the exposure is not theoretical. But India's own AI stack - foundation models, GPUs, chip design, data-centre infrastructure - remains meaningfully behind the US and China, meaning India is simultaneously more exposed to AI-directed attacks and less equipped, domestically, to build the AI-driven defences that could counter them.

What Actually Changes For Defenders

Traditional cyber defence - antivirus matching known malware signatures, patches for known vulnerabilities - assumes attackers move at a pace defenders can keep up with. AI-generated polymorphic malware, which restructures itself to avoid signature detection and AI agents that can operate continuously without fatigue, break that assumption entirely.

CERT-In's 2025 shift toward AI-driven threat detection and its April advisory - treating every new vulnerability as exploitable "within hours, not weeks"

  • reflects an institution correctly reading the threat, even if India's underlying AI capability hasn't caught up yet. For the exam, the insight worth carrying is that the real AI security divide isn't about who uses AI defensively or offensively - everyone eventually will. It's about who builds the frontier AI capability in the first place, because that determines who sets the pace the other side has to match.

Quick Facts

Key numbers & takeaways — revise these first

  • Anthropic disclosed in November 2025 that Chinese state-sponsored group GTG-1002 used Claude Code as an autonomous agent across multiple stages of a cyber-espionage campaign.

  • Claude Mythos Preview autonomously identified a 27-year-old zero-day vulnerability in OpenBSD.

  • CloudSEK ranked India the second-most cyber-attacked nation in 2024 and sixth-most in 2025.

  • Ransomware group World Leaks breached data linked to a Kudankulam Nuclear Power Plant third-party contractor in July 2026.

  • Pakistan-backed APT36 targeted India's indigenous BOSS Linux operating system during Operation Sindoor.

Beyond The Headlines
GS Paper 3 Science and Technology - AI-Enabled Cybersecurity Threats, Critical Infrastructure and India's Policy Response

Connect the dots for your UPSC preparation.

Standard news covers the event. Log in to read our comprehensive analysis and uncover the hidden constitutional, structural, and ethical dimensions of this topic:

1

The specific stages of the GTG-1002 campaign where the AI agent operated with no human intervention, according to Anthropic's disclosure.

2

Why OpenBSD's 27-year-old vulnerability had gone undetected by human researchers for that long and what that reveals about AI's search capability.

3

Deep Analysis's assessment of MeitY's proposed agentic-AI liability framework and where it currently falls short.

4

A comparison of India's AI-stack gap against the US and China across foundation models, GPUs and data-centre infrastructure specifically.

Included in this analysis

Deep Analysis Sharpens your Mains-level understanding.
8 Languages Read the news comfortably in your language.
PYQ Connection Direct connection with previous year Mains questions.
Expected Questions Possible upcoming questions for Prelims & Mains.
Daily Evaluation Daily Prelims test, plus category-wise Mains evaluation.
Mentor Observation Daily, topic-wise expert feedback on your tests.
Value Additions Important Case Studies and daily Vocab Word.

Join thousands of aspirants analyzing the news deeply.

Log In to Read Full Article

More from 25 Aug 2026

Short titles by category — open any story to read it fully.