Russian State-Sponsored Hackers Used Claude to Rebuild Malware After Detection
A Russian state-linked cyber-espionage operation has used Anthropic's Claude AI to create an automated malware-evasion workflow capable of detecting when its malicious tools were identified by security products and then modifying and rebuilding those tools to bypass the detections.

Anthropic disclosed the activity in its September 2026 threat intelligence report, describing the operation as GTG-20006. The company's attribution is consistent with public reporting connecting the activity to Midnight Blizzard, also known as APT29 and Cozy Bear.
The development represents a significant shift in AI-assisted cyber operations. Rather than using an AI model simply to write malware or phishing content, the threat actor integrated AI into an operational feedback loop in which detection itself triggered automated malware modification and redeployment.
| Category | Details |
|---|---|
| Threat group | GTG-20006 |
| Suspected affiliation | Russian state-sponsored; activity consistent with Midnight Blizzard/APT29 |
| AI platform | Anthropic Claude |
| Primary objective | Cyber espionage |
| AI capability abused | Malware development, monitoring, modification and redeployment |
| Key innovation | Automated detection-to-rebuild feedback loop |
| Primary targets | Government, military, diplomatic and defense organizations |
| Geographic focus | Ukraine and Europe, with activity extending to the Middle East and Asia |
| Malware | PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc |
| Mobile malware | GiftDrop and DarkSword |
| Other techniques | Device-code phishing, DNS hijacking, ClickFix, credential theft |
Anthropic says the campaign was disrupted and that it used information from the investigation to strengthen its safeguards and share relevant intelligence with authorities and industry partners.
From AI Assistant to Automated Malware Engineer
AI has already been used by attackers to write scripts, analyze code, generate phishing messages and accelerate reconnaissance.
The GTG-20006 operation goes a step further.
Anthropic found that the threat actor built customized AI-driven workflows covering multiple stages of the attack lifecycle, including:
- Reconnaissance
- Infrastructure acquisition
- Malware development
- Phishing
- Persistence
- Command-and-control operations
- Credential theft
- Data collection
- Exfiltration
- Detection monitoring
- Malware modification
The most significant capability was the automated response to security detections.
When the actor's monitoring infrastructure determined that a malware sample had been detected, AI agents were instructed to modify and rebuild the affected artifact and continue iterating until it was no longer detected.
The Detection-to-Rebuild Attack Loop
Traditional malware development often follows a relatively predictable cycle:
Develop malware → deploy → security vendor detects → attacker modifies malware → redeploy
Each detection can therefore impose an operational cost on the attacker.
GTG-20006 attempted to compress that cycle using AI.
The observed model was closer to:
Deploy malware → monitor detection → identify detected artifact → modify malware → rebuild → test → redeploy → repeat
This effectively creates an automated adversarial feedback loop.
Instead of waiting for an operator to analyze why a sample was detected and manually produce another version, the AI-assisted workflow could perform much of the iteration automatically.
Anthropic said the agents were designed to continue modifying the toolkit until it became undetected by the relevant security products.
Why Static Detection Becomes Less Effective
Traditional endpoint security has historically relied heavily on signatures, hashes and other relatively stable characteristics.
A single malware sample can be blocked through:
- File hashes
- Static signatures
- Known byte patterns
- Malware family signatures
- YARA rules
- Known behavioral indicators
But an attacker that can rapidly produce functionally similar variants can force defenders into a continuous detection-update cycle.
The challenge is not that AI necessarily makes malware invisible. Rather, AI can potentially reduce the time between detection and attacker adaptation.
Anthropic described this as a reversal of the traditional economic advantage defenders gain from deploying new detections: capable adversaries may be able to modify their tooling faster than defenders can develop, test and deploy new signatures.
Targets Included Governments and Defense Organizations
The campaign focused heavily on strategic targets.
Anthropic identified more than 20 organizations involved in the actor's reconnaissance and live operations.
Targets included:
- Government ministries
- Military organizations
- Intelligence agencies
- Embassies
- Diplomatic missions
- Defense companies
- Defense-industrial organizations
- Think tanks
- Drone technology providers
Most activity centered on Ukraine and Europe, although the operation also extended to organizations in the Middle East and maritime-related government entities in Asia.
The targeting of Ukrainian military and drone-related organizations was particularly notable.
Anthropic said the actor obtained mailboxes belonging to drone component manufacturers, targeted a military drone maker and stole a proprietary software development kit associated with a drone-vision system.
The attackers then spent days reverse-engineering the system's architecture, hardware components and supplier dependencies.
Malware Families Used by the Operation
Anthropic identified several malware families associated with GTG-20006.
| Platform | Malware / Tool | Purpose |
|---|---|---|
| Windows | PowerChrome | Windows-based malicious tooling |
| Windows | WUEngine | Windows implant/tool |
| Windows | Shadow C2 | Command-and-control capability |
| Windows | MiniPlasma | Windows malware |
| Windows | CloudSyncSvc | Windows malware |
| Android | GiftDrop | Android surveillance malware |
| iOS | DarkSword | iOS exploit chain |
The actor also operated a credential-stealing tool targeting browser password stores and maintained a phishing platform designed to impersonate high-priority government organizations.
AI Was Used Beyond Malware Development
The malware-rebuilding mechanism was only one component of the wider operation.
Anthropic found AI integrated across the campaign.
Reconnaissance
AI workflows were used to fingerprint email and remote-access infrastructure and collect publicly available information to build target lists.
Phishing Infrastructure
The actor used AI to research and register domains, configure hosting infrastructure and operate phishing campaigns.
Initial Access
One major technique involved device-code phishing, abusing legitimate cloud authentication flows to steal access to victims' cloud email accounts.
Credential Theft
The operation deployed credential-stealing tools and targeted browser password stores.
Data Collection
AI was used to process and organize very large quantities of stolen information, including hundreds of gigabytes of data.
Persistence
AI-assisted workflows helped maintain access to compromised accounts and tenants, including registering attacker-controlled devices in victim environments.
Malware Evasion
In on-premises environments, AI monitored whether implants were being detected and then modified and redeployed them when detection occurred.
This demonstrates that the AI component was not a standalone malware-development assistant. It was incorporated into the broader operational infrastructure.
Hotel Wi-Fi Providers Used as an Indirect Attack Path
The campaign also demonstrated how attackers can compromise third-party infrastructure to reach high-value targets.
Anthropic found that the actor compromised at least three hospitality vendors operating hotel guest Wi-Fi.
Using stolen administrative credentials, the attackers modified DNS records so that hotel guest traffic was redirected through infrastructure controlled by the attackers.
Guests connecting to affected hotel networks could have traffic, device identifiers and IP addresses exposed to the attackers.
The attackers subsequently used ClickFix-style lures to deliver malware tailored to Windows, Android and iOS devices.
Microsoft previously documented this activity under the name CaptiveCrunch.
This creates a particularly dangerous targeting model:
Compromise service provider → hijack trusted infrastructure → intercept or redirect users → identify valuable targets → deliver malware
WhatsApp and Surveillance Platform Targeting
The operation extended beyond traditional endpoint malware.
Attackers used headless browsers and WhatsApp automation tooling to link compromised accounts as companion devices and extract conversations while attempting to suppress read receipts.
At least two former senior Ukrainian officials were targeted using this technique.
The actor also targeted camera-streaming platforms.
Anthropic said the attackers identified authorization weaknesses in application interfaces, enumerated users and obtained tokens that provided access to live camera streams.
These activities demonstrate how the campaign combined stolen credentials, application weaknesses, automation and AI-assisted workflows rather than relying on a single malware family.
A North African Government Was Also Compromised
GTG-20006 was also linked to an intrusion targeting a North African government technology authority.
Attackers obtained credentials for a VPN appliance and used them to take control of a central account server.
The compromise exposed a database containing more than:
- 300,000 national identity records
- Commercial registry information belonging to more than 500,000 companies
The incident demonstrates how a single compromised remote-access credential can become the gateway to extremely valuable government datasets.
Microsoft 365 Token Theft
The actor also developed a cloud-email espionage platform known as Embassy Kit.
The framework was used to conduct device-code phishing campaigns against diplomatic and government personnel and steal Microsoft 365 authentication tokens.
Anthropic linked the activity to unauthorized access and email-data theft involving at least eight organizations, including a national prosecutor's office, a military education institution and a regional intergovernmental organization.
Security Updates Were Also Targeted
Another particularly concerning element involved attempts to interfere with security updates.
Anthropic observed Windows credential stealers delivered through fake-update social-engineering campaigns alongside remote-access tools designed to interfere with security updates on compromised machines.
This creates an additional advantage for the attacker: even if defenders publish new detection signatures, the compromised system may be prevented from retrieving or applying those protections.
For defenders, this means security-update failures should not always be treated as ordinary endpoint-management problems.
Unexpected update-service disruption can potentially be an indicator of post-compromise activity.
Indicators of Compromise
Anthropic published indicators associated with the GTG-20006 activity.
Selected indicators include:
| Type | Indicator |
|---|---|
| Domain | ms365-live[.]com |
| Domain | teams.ms365-live[.]com |
| Domain | m365-owa[.]com |
| Domain | owa-ms365[.]com |
| Domain | ms365-device[.]com |
| Domain | my-invite[.]org |
| Domain | chamber-ua[.]org |
| Domain | ukrinform-share[.]net |
| Domain | docs-viewer[.]org |
| Domain | wa-connect[.]eu |
| IP | 104.145.210[.]184 |
| IP | 31.57.243[.]154 |
| IP | 104.194.151[.]133 |
| IP | 144.172.114[.]192 |
| File | WUEngine[.]exe |
| File | DiagHost[.]exe |
| File | msedgeupdate[.]exe |
| File | version[.]dll |
Anthropic's full indicator set contains additional domains, IP addresses, filenames and hashes and should be incorporated into enterprise threat-hunting workflows where appropriate.
Detection and Threat Hunting
The campaign illustrates why security teams should move beyond malware hashes and static signatures.
SOC teams should prioritize behavioral detections around:
Suspicious Malware Rebuilding
Monitor for repeated creation and replacement of executables with similar names or functionality.
Unexpected patterns such as:
malware detected → executable replaced → new hash → new network connection
should receive investigation.
Abnormal Process Relationships
Monitor for unusual relationships involving:
- Browser processes
- PowerShell
- Command shells
- Scripting engines
- Update utilities
- Temporary directories
- Newly created executables
Security Update Tampering
Investigate endpoints where:
- Windows Update services unexpectedly stop
- Security products lose connectivity
- Signature updates fail repeatedly
- Security tooling configuration changes unexpectedly
- Defender or EDR components are disabled
Device-Code Authentication
Monitor for unusual device-code authentication activity, particularly involving privileged or government accounts.
Defenders should investigate:
- Unexpected device registrations
- New devices associated with existing accounts
- Authentication from unusual locations
- Device-code sign-ins without corresponding user activity
- Suspicious OAuth/token activity
DNS Hijacking
For organizations operating network-management or hospitality infrastructure, monitor unexpected DNS-record modifications and changes to authoritative DNS configurations.
Defensive Recommendations
Organizations can reduce exposure to this style of AI-assisted operation by strengthening controls across the entire attack lifecycle.
Move Beyond Hash-Based Detection
Static indicators remain useful, but they should be supplemented with:
- Behavioral analytics
- Process-tree analysis
- EDR/XDR telemetry
- Network anomaly detection
- Memory analysis
- Application control
- Identity analytics
If malware variants can be automatically rebuilt, hash-based blocking becomes increasingly fragile.
Protect Identity and Authentication
Because device-code phishing and stolen credentials played important roles in the campaign, organizations should prioritize phishing-resistant authentication.
Recommended controls include:
- FIDO2/passkeys
- Strong conditional access
- Device compliance enforcement
- Risk-based authentication
- Token protection
- Continuous session monitoring
- Restrictions on unauthorized device registration
Monitor Third-Party Infrastructure
Organizations should not limit monitoring to their own endpoints.
Third-party services that provide:
- DNS
- Wi-Fi
- Identity
- SaaS
- Hosting
- Remote access
can become stepping stones into the primary target.
Protect the Detection Pipeline
Security teams should also monitor the security tools themselves.
Attackers may attempt to:
- Disable EDR
- Block signature updates
- Tamper with security services
- Prevent telemetry collection
- Modify firewall rules
- Block security infrastructure
A sudden reduction in endpoint telemetry should be treated as a potential security event rather than simply an operational fault.
The Bigger AI Security Problem
The most important lesson from the campaign is not that attackers can ask AI to write malware.
That capability was already expected.
The more significant development is operational automation.
AI can now potentially connect multiple individual tasks into a continuous workflow:
Reconnaissance → infrastructure setup → phishing → compromise → credential theft → persistence → detection monitoring → malware modification → redeployment → data theft
Anthropic's broader assessment is that AI is increasingly acting as an orchestrator rather than merely an assistant. Its investigation found multi-agent workflows performing reconnaissance, exploitation and data-exfiltration tasks while human operators remained involved primarily in selecting targets and reviewing results.
This changes the economics of cyber operations.
An attacker no longer needs to manually perform every repetitive task. AI can potentially compress hours or days of operational work into automated workflows.
What This Means for SOC Teams
For SOC analysts, the defensive implication is straightforward:
Do not assume that blocking one malware sample ends the attack.
If the adversary has an automated rebuild capability, a successful detection may simply trigger another malware variant.
Security teams should therefore focus on identifying the underlying behavior and attack infrastructure, including:
- Initial access mechanisms
- Identity abuse
- Persistence
- C2 patterns
- Process behavior
- DNS activity
- Lateral movement
- Data-access patterns
- Security-control tampering
The objective should be to break the attack chain rather than continuously chase individual malware hashes.
Final Takeaway
The GTG-20006 campaign represents a notable evolution in AI-assisted cyber espionage.
The Russian state-linked actor did not merely use Claude to create malicious code. Anthropic found that the group integrated AI into an operational feedback loop capable of monitoring malware detections, modifying affected tools, rebuilding them and redeploying new versions.
The campaign targeted governments, military organizations, diplomatic entities, defense companies and drone-related technology providers, while also compromising third-party hospitality infrastructure and abusing cloud authentication mechanisms.
For defenders, the lesson is clear: AI can shorten the attacker adaptation cycle, making static detection alone increasingly insufficient.
Organizations should respond by combining endpoint behavior analytics, identity protection, network monitoring, threat intelligence, security-control integrity monitoring and rapid incident response.
The future contest between attackers and defenders may increasingly depend not only on who can detect threats first, but on who can adapt their detection and response mechanisms faster than the adversary can change the attack.
Related reporting
Iran-Linked Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Cybersecurity and intelligence agencies from the United Kingdom, United States and Netherlands have exposed an Iranian state-linked cyber-espionage campaign using sophisticated Windows malware to monitor dissidents, activists and journalists around the world.
Russia-Aligned Hackers Use GuardBreaker Prompt Injection to Disrupt AI Malware Analysis
A Russia-aligned threat actor has embedded an adversarial prompt inside malicious code to manipulate AI-powered malware analysis systems, attempting to trigger safety protections and prevent automated tools from examining the actual payload.
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Threat actors are exploiting vulnerabilities in Cisco Secure Firewall Management Center (FMC) to gain access to enterprise environments, steal credentials and ultimately deploy Qilin ransomware, turning vulnerable security infrastructure into an entry point for broader network compromise.


