Anthropic Accuses Alibaba of Massive Claude Cloning Attack [Prime Cyber Insights]
I'm Aaron Cole. Welcome to the briefing room for Prime Cyber Insights on June 26th, 2026. <br/><i>acting_description:</i> professional, steady, leading <i>speed:</i> 0.98 <i>trailing_silence:</i> 0.2 I am Lauren Mitchell. Aaron, we're opening today with a major escalation in the AI arms race. Ars Technica reports that Anthropic has accused Alibaba of a massive campaign to clone its Claude model. <br/><i>acting_description:</i> engaged, measured, responsive <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 This wasn't a standard breach, Lauren. It was a distillation attack. Anthropic alleges that operators affiliated with Alibaba used 25,000 fraudulent accounts to generate over 28 million exchanges with Claude, specifically targeting its most valuable reasoning and software engineering capabilities. <br/><i>acting_description:</i> analytical, direct, serious <i>speed:</i> 0.95 <i>trailing_silence:</i> 0.4 Correct. The goal is to extract the model's logic without the massive R&D costs. Anthropic claims Alibaba used proxy networks to evade detection, and interestingly, this reportedly continued even after the administration issued warnings about industrial-scale AI theft. <br/><i>acting_description:</i> clear, precise, supportive <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 It highlights a new front in espionage. Turning to traditional state actors, we're also tracking a new implant from Turla. Google Threat Intelligence has detailed a Windows backdoor called STOCKSTAY being used against military and diplomatic targets in Ukraine. <br/><i>acting_description:</i> authoritative, focused, poised <i>speed:</i> 0.97 <i>trailing_silence:</i> 0.2 The technical overlaps with Turla's Kazuar toolkit are significant, Aaron. STOCKSTAY is a .NET suite using WebSocket connections for C2. It's modular, with specific components like MARKETMAKER for initial execution and STOCKTRADER for the actual information theft. <br/><i>acting_description:</i> observant, technical, neutral <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.4 Practitioners should note that STOCKSTAY often masquerades as harmless utilities like calculators or PDF viewers. It's been observed in the wild being delivered through malicious R-D-P files and WinRAR vulnerabilities, specifically CVE 2025 8088. <br/><i>acting_description:</i> informative, cautionary, firm <i>speed:</i> 0.94 <i>trailing_silence:</i> 0.3 While we're on vulnerabilities, CISA just issued an urgent warning for edge infrastructure. Critical flaws in Lantronix EDS5000 and Ubiquiti UniFi OS are being actively exploited. The Lantronix bug, CVE 2025 67038, is particularly nasty

