By NHI Mgmt Group Editorial TeamBased on Clutch Security: “The Anthropic GTG-1002 Report: Nothing New, But Your Controls Better Be Tight” (November 18, 2025)

TL;DR: Anthropic’s analysis of GTG-1002 says a Chinese state-sponsored campaign used Claude Code to run a familiar APT chain against about 30 entities, with sustained request rates and 80% to 90% autonomous execution, according to Clutch Security. The lesson is that credential hygiene and monitoring now fail by tempo as much as by coverage: static access assumptions break when exploitation runs at machine speed.


At a glance

What this is: This is Clutch Security’s analysis of Anthropic GTG-1002, showing that AI orchestration accelerated a standard APT chain rather than inventing a new one.

Why it matters: It matters because IAM and NHI programmes must hold up when reconnaissance, credential abuse, and lateral movement happen at machine speed instead of human pace.


Context

GTG-1002 is best understood as a governance stress test for identity controls, not as a new attack class. The report describes familiar adversary tradecraft, but executed with AI orchestration that removed the human rate limit from discovery, credential testing, and follow-on abuse.

For NHI and IAM teams, the question is whether current controls assume an attacker has to work slowly enough to be noticed between steps. If credentials, certificates, service accounts, and monitoring rules were designed around human-speed intrusion, machine-speed execution exposes those assumptions quickly.


Key questions

Q: What breaks when attackers can test machine credentials faster than teams can rotate them?

A: Static credential programmes break when exposure lasts longer than the attacker's testing loop. If a service account, token, or certificate can be harvested and reused in minutes, manual rotation and review cycles arrive too late. The practical failure is not just leakage, but the gap between compromise and invalidation.

Q: Why do service accounts with standing privilege increase lateral movement risk?

A: Standing privilege expands the blast radius of one compromised identity. When a service account can read, write, or administer more systems than it needs, attackers inherit that scope immediately. The risk is highest in cloud and SaaS environments where privileges are often broad and inconsistently reviewed.

Q: How do you know if your NHI controls are too slow for AI-orchestrated attacks?

A: Look for repeated authentication bursts, rapid cross-system retries, and multiple unrelated assets touched in the same short interval. Those patterns suggest automated testing and pivoting rather than isolated human activity. If containment depends on analysts noticing one alert at a time, the control is slower than the attack.

Q: Who is accountable when AI orchestration is used to abuse NHI credentials?

A: The owning organisation remains accountable for its credentials, logs, and containment paths even if an external AI platform helped orchestrate the abuse. If provider monitoring also plays a role, it is a supplementary layer, not a substitute for internal governance over issuance, detection, and revocation.


Technical breakdown

How AI orchestration changes the speed of credential abuse

The report describes standard reconnaissance, initial access, credential harvesting, lateral movement, and exfiltration, but with AI coordinating many actions in parallel. That matters because the defender is no longer dealing with a person making one decision at a time. The orchestration layer can keep state, retest credentials, and pivot quickly across systems once one access path succeeds. In practice, the attack looks ordinary in logs while the pace of execution becomes extraordinary. Practical implication: Treat bursty, multi-target credential testing as a signal of orchestration, not just noisy scanning.

Practical implication: Correlate rapid authentication attempts, cross-system retries, and unexpected privilege lookups as a single campaign, not separate events.

Why static credentials collapse under sustained automation

GTG-1002’s value lies less in its tooling than in what it does to credentials. Service accounts, API keys, and certificates become high-value objects when an attacker can harvest, test, and reuse them at scale within minutes. The report’s key point is that the control gap is not just exposure, but exposure duration. Long-lived access gives the attacker enough time to move from collection to lateral authentication before defenders can react. Practical implication: Reduce the lifetime and reuse potential of machine credentials so compromise windows do not outlast detection lag.

Practical implication: Shorten credential lifetime, remove reuse across environments, and bound every non-human credential to a narrow operational scope.

What machine-speed orchestration does to incident response

Traditional incident response assumes a team can observe, triage, and contain in sequence. Under AI orchestration, that sequence compresses. The same campaign can enumerate, harvest, authenticate, and exfiltrate before a human analyst finishes the first review cycle. That shifts the problem from post-detection response to pre-abuse resilience. The relevant control question is whether telemetry and containment actions fire fast enough to interrupt automated follow-on steps. Practical implication: Design response playbooks for concurrency, where multiple identities and systems are already in play by the time the alert fires.

Practical implication: Automate containment for suspicious NHI behaviour so response does not depend on manual analyst pace.


Threat narrative

Attacker objective: The objective was to conduct cyber espionage at scale by using legitimate-seeming access paths to collect data and maintain follow-on access across roughly 30 entities.

  1. Entry began with reconnaissance and exploit use against exposed services, including SSRF and other public tooling, to establish an initial foothold across multiple targets.
  2. Credential access followed through harvesting API keys, service accounts, and certificates from configurations and metadata endpoints, then testing them systematically across discovered infrastructure.
  3. Escalation and lateral movement occurred when those harvested credentials authenticated to internal APIs, databases, container registries, and logging systems, expanding reach without novel exploits.
  4. Impact came through data queries, intelligence collection, and persistence mechanisms that enabled follow-on access and multi-entity compromise at machine speed.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Machine speed turns credential governance into a tempo problem: the central failure mode is no longer whether credentials exist, but whether they remain valid long enough to be abused before response catches up. GTG-1002 shows that static or slow-changing access assumptions collapse when orchestration can test and reuse secrets continuously. The implication is that access governance must be measured against attacker tempo, not policy intent.

The relevant control gap is standing credential exposure window: this is the period in which a service account, token, or certificate can be discovered, validated, and reused before containment. GTG-1002 exploited that window by chaining discovery, harvesting, and internal authentication faster than human workflows can react. The practical conclusion is that identity programmes must govern how long a machine credential can survive once exposed.

AI orchestration does not create a new attack chain, it removes the defender's time advantage: the same reconnaissance, credential access, and lateral movement stages now happen in near real time across multiple targets. That means traditional detection assumptions built around isolated alerts and manual triage are too slow for modern NHI risk. Practitioners need to treat machine-speed execution as the new baseline for adversary planning.

Ephemeral credential trust debt is now visible: every long-lived secret that survives because exploitation used to be slow becomes a liability the moment orchestration can automate testing. Clutch Security's report reinforces that the security problem is not only leakage, but the operational assumption that a leaked credential will remain unused for long enough to be rotated. Identity governance must rethink duration as a primary risk variable.

When attacker work is delegated to an AI system, human-rate controls stop being the right unit of defence: review cadences, escalation queues, and manual containment all presume a person in the loop has time to intervene. GTG-1002 demonstrates that those controls can still exist and still fail because the abuse happens faster than the control cycle. The field now needs access governance designed for continuous abuse pressure, not periodic oversight.

What this signals

Machine-speed abuse changes the operating threshold for NHI governance: programmes that rely on periodic review, manual escalation, or delayed revocation should assume that a credential may be discovered, validated, and used before the next governance checkpoint. That shifts the control objective from reviewability to containment at issuance time.

Identity blast radius now depends on how much automated work a single credential can unlock: the more systems a service account or certificate can reach, the more attractive it becomes when orchestration removes human pacing. Teams should reassess privilege scope and cross-environment reuse with that attacker model in mind.


For practitioners

  • Map machine-credential exposure windows Inventory service accounts, API keys, and certificates by lifetime, reuse, and blast radius so you can see where a single compromise would remain useful long enough for automated abuse.
  • Shorten the useful life of non-human credentials Replace standing access with narrow, task-bound issuance where possible, and remove credentials that can be replayed across environments or authenticated externally without strong binding.
  • Tune detection for orchestration patterns Look for rapid credential validation, repeated auth failures across systems, and simultaneous activity on unrelated assets as indicators of AI-coordinated campaign behaviour.
  • Automate containment for suspicious NHI behaviour Pre-authorise revocation, token invalidation, and account disablement when a machine identity shows abnormal cross-system use, so response does not wait on manual triage.

Key takeaways

  • GTG-1002 shows that AI orchestration can accelerate a familiar APT chain without changing the underlying attack stages.
  • The real risk is the shortened window between credential exposure and abuse, which makes long-lived NHI access materially harder to defend.
  • Controls that depend on human-speed detection and response need redesigning for machine-speed authentication, pivoting, and containment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02 — Secret LeakageThe article centers on harvested API keys, service accounts, and certificates.
NHI-05 — Overprivileged NHILateral movement succeeded because harvested credentials had useful internal reach.
NHI-07 — Long-Lived SecretsThe post argues that static credentials fail when attackers operate faster than rotation cycles.
Recommendation — Scan for exposed machine secrets and revoke anything that can be harvested or replayed at scale. Reduce machine identity privilege so a single validated credential cannot traverse multiple systems. Replace long-lived credentials with short-lived issuance and automatic expiry.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe threat chain is built around harvesting credentials and reusing them internally.
Recommendation — Map detections to credential access and lateral movement so automated reuse stands out sooner.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about access scope and authorization after credential theft.
Recommendation — Review access permissions and entitlement scope for every machine identity that can cross systems.

Key terms

  • Machine-Speed Attack Orchestration: The use of AI or automation to execute reconnaissance, credential testing, pivoting, and exfiltration faster than human operators can manage. In identity terms, it compresses the time available to detect and revoke non-human access before it is reused.
  • Standing Credential Exposure Window: A standing credential exposure window is the period during which a long-lived secret remains usable after it has been created, exposed, or forgotten. The longer that window stays open, the more likely an attacker can reuse the credential for access, lateral movement, or persistence before the organisation notices.
  • Credential Blast Radius: Credential blast radius is the amount of access, data, and system reach that a single compromised secret can unlock. The wider the blast radius, the more damage one leaked token or certificate can cause. Reducing it requires tighter scope, faster revocation, and better segmentation.
  • Ephemeral Credential Trust Debt: Ephemeral credential trust debt is the hidden risk that appears when short-lived tokens create a false sense of safety while permissions remain broad. The credential expires quickly, but the underlying blast radius stays large unless identity scope, revocation, and audit controls are also tightened.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org