Anthropic said this week it disrupted a Russian state-sponsored group that built an AI-assisted workflow around Claude specifically to rebuild malware faster than defenders could re-detect it, a technique-development loop rather than a one-off jailbreak. Separately, Anthropic said financially motivated and China-linked espionage actors abused Claude to pull secrets out of 1.8 million Android apps, and that it identified industrial-scale distillation attacks against Claude from seven China-based labs, including Alibaba, Moonshot, DeepSeek and Z.ai. Anthropic's account names the technique and the scale. It does not name which detection signatures the rebuilt malware evaded, which is the artifact a bank's SecOps team would actually want.
For a Hong Kong or Singapore bank, the live regulatory question is not the distillation story, it is the malware-iteration one: HKMA's TM-G-1 and MAS TRM both assume attacker development cycles measured in weeks, and BIS said this month that routine patching schedules are "increasingly inadequate" as AI compresses that cycle to minutes. A defender running detection tuned against last month's malware family, refreshed on a quarterly cycle, is testing controls against a threat that no longer holds still between tests.
No vendor named in Anthropic's disclosure is one an APAC bank runs directly, so no product change follows from this story. The control that matters is internal: detection-signature refresh cadence tied to threat-intel ingestion, not to a patch calendar. A bank that still refreshes signatures on the same schedule it patches Windows is defending against last quarter's malware.