TF Cybercrime Round-Up: 17 September 2026

Eve Harrison

An 8-year-old DDoS empire, seized. A federal agency telling defenders to lie to hackers on purpose. And a 154-page Anthropic report describing Russian freelancers who built drones that pick their targets — funded, they told the AI, by Moscow’s answer to DARPA.


This cybercrime round-up spans four fronts — a criminal takedown, a novel piece of federal defensive guidance, a disturbing new AI misuse disclosure, and a court filing that reimagines the AI industry’s foundational data practices. The FBI seized the domains behind NightmareStresser, an eight-year-old DDoS-for-hire platform with more than 566,000 registered users. CISA published its first-ever guidance on deploying fake credentials and honeypots to catch intruders already inside a network. Anthropic disclosed that Russia-linked operators used Claude to build autonomous kamikaze drone software that selects human targets without a person in the loop. Newly unsealed court filings also reveal a Microsoft executive called AI training data scraping “the largest theft of labour in human history.”

What’s Happening & Why It Matters

NightmareStresser Goes Dark After Eight Years

The FBI, working with the US Attorney’s Office for the District of Alaska and the Royal Canadian Mounted Police, seized the domains behind NightmareStresser on Tuesday. The platform marketed itself on its defunct site: “the longest-running, most powerful” DDoS-for-hire service, boasting more than 566,000 registered users and 52 dedicated servers capable of launching attacks up to 200 Gbps. Since 2022 alone, the service facilitated hundreds of thousands of actual or attempted attacks against educational institutions, government agencies, gaming platforms, and individual users worldwide.

The takedown is part of Operation PowerOFF, a coordinated international law enforcement effort running since December 2018. That history matters — an identical domain was seized back in December 2022, alongside six arrests, and the service rebuilt and reopened under the same name. The FBI didn’t confirm any arrests in this latest action, meaning NightmareStresser’s operators may attempt the same resurrection playbook a third time.

CISA: Plant Fake Accounts For Attackers to Find

CISA published its first-ever formal guidance on cyber deception Wednesday, titled Using Cyber Decoys to Strengthen Detection and Response. The core problem it addresses is specific: attackers avoid malware and instead abuse stolen legitimate credentials and built-in administrative tools—activity that blends into normal network behaviour and defeats traditional signature-based detection. CISA’s answer is deliberate deception: fake admin credentials nobody should ever use, decoy databases, bogus sensitive files, and “honeytokens” that trigger high-confidence alerts the instant anyone touches them.

Chris Butera, CISA’s acting executive director for cybersecurity, called the appeal: “Cyber decoys used in a proactive cyber defence strategy help make critical infrastructure networks unfriendly places for adversaries and enhance resilience to compromise, even against living-off-the-land techniques.” The guidance focuses on organisations without dedicated deception specialists — low-cost fake assets, CISA argues, produce high-value alerts because no legitimate employee would ever interact with them.

Russian Freelancers Used Claude to Build Drones

The most disturbing item this week comes from Anthropic’s 154-page threat report, covering activity between December 2025 and August 2026. A small freelance team in Russia, which Anthropic tracks as GTG-27005 and which called its project DronDoc or Serafim, used Claude Code to write swarm coordination, computer vision, and terminal guidance software for first-person-view kamikaze drones. According to Anthropic, the resulting software let drones select targets — including people — and issue detonation commands with no human in the loop.

The team trained its computer-vision system on real Ukrainian combat footage and used actual Ukrainian locations for simulated missions. They told Claude their work was funded by Russia’s Advanced Research Foundation — the country’s answer to DARPA — alongside its National Technology Initiative and Ministry of Defence. Anthropic could not verify those funding claims, but noted the accounts were linked to a regional Russian university and a federal research centre associated with the Russian Academy of Sciences. As TF covered in The Humans Will Be Dead: Death by AI in 10 Years?!, Anthropic CEO Dario Amodei warned months earlier that AI could let a single operator command a drone swarm. His company’s report describes the coordination layer he warned about, built with his company’s tool.

Separately, Anthropic disrupted a Russia-linked espionage group tracked as GTG-20006, which automated hacking operations against more than 20 organisations — Ukrainian government ministries, defence agencies, embassies, and drone manufacturers among them. After breaching two drone-component makers, the group used Claude to reverse-engineer a stolen drone vision system’s complete software development kit, recovering its architecture and supplier dependencies. When security tools flagged their malware, the group used Claude to modify and redeploy the detected code — an AI-assisted evasion loop that adapts faster than manual detection can keep pace with.

Microsoft Called AI Scraping “Theft”

Newly unsealed filings in The New York Times‘s ongoing lawsuit against OpenAI and Microsoft reveal a Microsoft executive described the companies’ AI training practices as tantamount to theft — with OpenAI’s leadership acknowledging its models posed an “existential threat” to the publishers whose work trained them. The filings detail how both companies bypassed paywalls undetected, built training datasets from scraped content, and stripped copyright notices before the data reached the model—so the model wouldn’t output copyright notices to users.

CEO Satya Nadella testified under oath that “anything that is paywalled should be licensed by anyone who wants to use it… for grounding or training,” and said he would have invoked Microsoft’s contractual right to force OpenAI to retrain its models had he known paywalled content was involved. That testimony is against the unsealed internal characterisation of the same practice as theft. OpenAI’s Head of ChatGPT, Nick Turley, wrote that publishers face an “existential threat” from products that are “largely substitutive” and will become “more and more substitutive as they get better” — an internal admission that cuts against the fair-use defence both companies have argued.

TF Summary: What’s Next

NightmareStresser’s operators face no confirmed arrests as of this writing, leaving open the possibility of a third relaunch under the same or a similar name. CISA’s decoy guidance carries no compliance deadline — it is voluntary advice for critical infrastructure operators. Anthropic continues monitoring for GTG-27005 and GTG-20006 activity following its disclosed disruptions. The New York Times v. OpenAI and Microsoft case proceeds toward trial, with publishers arguing the unsealed admissions undermine the companies’ fair-use defence.

MY FORECAST: Expect NightmareStresser to attempt a relaunch within months, given its documented history of resurrecting under the same brand after prior takedowns — Operation PowerOFF’s own track record suggests seizure alone ends a DDoS-for-hire operation without accompanying arrests. CISA’s decoy guidance will see uneven adoption; well-resourced critical infrastructure operators will implement it quickly, while smaller organisations the guidance targets lack the staff to build and maintain a deception programme, no matter how low-cost CISA places it. The DronDoc disclosure is the story with the longest tail — expect Congressional hearings on AI-enabled autonomous weapons development to cite this specific case, given how it matches the “AI could enable one operator to command a drone swarm” warning TF has already documented from Anthropic’s CEO.



[gspeech type=full]

Share This Article
Avatar photo
By Eve Harrison “TF Gadget Guru”
Background:
Eve Harrison is a staff writer for TechFyle's TF Sources. With a background in consumer technology and digital marketing, Eve brings a unique perspective that balances technical expertise with user experience. She holds a degree in Information Technology and has spent several years working in digital marketing roles, focusing on tech products and services. Her experience gives her insights into consumer trends and the practical usability of tech gadgets.
Leave a comment