Skip to main content
The Wire
CyberNews by Zentrya One
critical Malware

Russian State-Sponsored Hackers Used Claude to Rebuild Malware After Detection

A Russian state-linked cyber-espionage operation has used Anthropic's Claude AI to create an automated malware-evasion workflow capable of detecting when its malicious tools were identified by security products and then modifying and rebuilding those tools to bypass the detections.

Anthropic disclosed the activity in its September 2026 threat intelligence report, describing the operation as GTG-20006. The company's attribution is consistent with public reporting connecting the activity to Midnight Blizzard, also known as APT29 and Cozy Bear.

The development represents a significant shift in AI-assisted cyber operations. Rather than using an AI model simply to write malware or phishing content, the threat actor integrated AI into an operational feedback loop in which detection itself triggered automated malware modification and redeployment.

Category Details
Threat group GTG-20006
Suspected affiliation Russian state-sponsored; activity consistent with Midnight Blizzard/APT29
AI platform Anthropic Claude
Primary objective Cyber espionage
AI capability abused Malware development, monitoring, modification and redeployment
Key innovation Automated detection-to-rebuild feedback loop
Primary targets Government, military, diplomatic and defense organizations
Geographic focus Ukraine and Europe, with activity extending to the Middle East and Asia
Malware PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc
Mobile malware GiftDrop and DarkSword
Other techniques Device-code phishing, DNS hijacking, ClickFix, credential theft

Anthropic says the campaign was disrupted and that it used information from the investigation to strengthen its safeguards and share relevant intelligence with authorities and industry partners.

From AI Assistant to Automated Malware Engineer

AI has already been used by attackers to write scripts, analyze code, generate phishing messages and accelerate reconnaissance.

The GTG-20006 operation goes a step further.

Anthropic found that the threat actor built customized AI-driven workflows covering multiple stages of the attack lifecycle, including:

  • Reconnaissance
  • Infrastructure acquisition
  • Malware development
  • Phishing
  • Persistence
  • Command-and-control operations
  • Credential theft
  • Data collection
  • Exfiltration
  • Detection monitoring
  • Malware modification

The most significant capability was the automated response to security detections.

When the actor's monitoring infrastructure determined that a malware sample had been detected, AI agents were instructed to modify and rebuild the affected artifact and continue iterating until it was no longer detected.

The Detection-to-Rebuild Attack Loop

Traditional malware development often follows a relatively predictable cycle:

Develop malware → deploy → security vendor detects → attacker modifies malware → redeploy

Each detection can therefore impose an operational cost on the attacker.

GTG-20006 attempted to compress that cycle using AI.

The observed model was closer to:

Deploy malware → monitor detection → identify detected artifact → modify malware → rebuild → test → redeploy → repeat

This effectively creates an automated adversarial feedback loop.

Instead of waiting for an operator to analyze why a sample was detected and manually produce another version, the AI-assisted workflow could perform much of the iteration automatically.

Anthropic said the agents were designed to continue modifying the toolkit until it became undetected by the relevant security products.

Why Static Detection Becomes Less Effective

Traditional endpoint security has historically relied heavily on signatures, hashes and other relatively stable characteristics.

A single malware sample can be blocked through:

  • File hashes
  • Static signatures
  • Known byte patterns
  • Malware family signatures
  • YARA rules
  • Known behavioral indicators

But an attacker that can rapidly produce functionally similar variants can force defenders into a continuous detection-update cycle.

The challenge is not that AI necessarily makes malware invisible. Rather, AI can potentially reduce the time between detection and attacker adaptation.

Anthropic described this as a reversal of the traditional economic advantage defenders gain from deploying new detections: capable adversaries may be able to modify their tooling faster than defenders can develop, test and deploy new signatures.

Targets Included Governments and Defense Organizations

The campaign focused heavily on strategic targets.

Anthropic identified more than 20 organizations involved in the actor's reconnaissance and live operations.

Targets included:

  • Government ministries
  • Military organizations
  • Intelligence agencies
  • Embassies
  • Diplomatic missions
  • Defense companies
  • Defense-industrial organizations
  • Think tanks
  • Drone technology providers

Most activity centered on Ukraine and Europe, although the operation also extended to organizations in the Middle East and maritime-related government entities in Asia.

The targeting of Ukrainian military and drone-related organizations was particularly notable.

Anthropic said the actor obtained mailboxes belonging to drone component manufacturers, targeted a military drone maker and stole a proprietary software development kit associated with a drone-vision system.

The attackers then spent days reverse-engineering the system's architecture, hardware components and supplier dependencies.

Malware Families Used by the Operation

Anthropic identified several malware families associated with GTG-20006.

Platform Malware / Tool Purpose
Windows PowerChrome Windows-based malicious tooling
Windows WUEngine Windows implant/tool
Windows Shadow C2 Command-and-control capability
Windows MiniPlasma Windows malware
Windows CloudSyncSvc Windows malware
Android GiftDrop Android surveillance malware
iOS DarkSword iOS exploit chain

The actor also operated a credential-stealing tool targeting browser password stores and maintained a phishing platform designed to impersonate high-priority government organizations.

AI Was Used Beyond Malware Development

The malware-rebuilding mechanism was only one component of the wider operation.

Anthropic found AI integrated across the campaign.

Reconnaissance

AI workflows were used to fingerprint email and remote-access infrastructure and collect publicly available information to build target lists.

Phishing Infrastructure

The actor used AI to research and register domains, configure hosting infrastructure and operate phishing campaigns.

Initial Access

One major technique involved device-code phishing, abusing legitimate cloud authentication flows to steal access to victims' cloud email accounts.

Credential Theft

The operation deployed credential-stealing tools and targeted browser password stores.

Data Collection

AI was used to process and organize very large quantities of stolen information, including hundreds of gigabytes of data.

Persistence

AI-assisted workflows helped maintain access to compromised accounts and tenants, including registering attacker-controlled devices in victim environments.

Malware Evasion

In on-premises environments, AI monitored whether implants were being detected and then modified and redeployed them when detection occurred.

This demonstrates that the AI component was not a standalone malware-development assistant. It was incorporated into the broader operational infrastructure.

Hotel Wi-Fi Providers Used as an Indirect Attack Path

The campaign also demonstrated how attackers can compromise third-party infrastructure to reach high-value targets.

Anthropic found that the actor compromised at least three hospitality vendors operating hotel guest Wi-Fi.

Using stolen administrative credentials, the attackers modified DNS records so that hotel guest traffic was redirected through infrastructure controlled by the attackers.

Guests connecting to affected hotel networks could have traffic, device identifiers and IP addresses exposed to the attackers.

The attackers subsequently used ClickFix-style lures to deliver malware tailored to Windows, Android and iOS devices.

Microsoft previously documented this activity under the name CaptiveCrunch.

This creates a particularly dangerous targeting model:

Compromise service provider → hijack trusted infrastructure → intercept or redirect users → identify valuable targets → deliver malware

WhatsApp and Surveillance Platform Targeting

The operation extended beyond traditional endpoint malware.

Attackers used headless browsers and WhatsApp automation tooling to link compromised accounts as companion devices and extract conversations while attempting to suppress read receipts.

At least two former senior Ukrainian officials were targeted using this technique.

The actor also targeted camera-streaming platforms.

Anthropic said the attackers identified authorization weaknesses in application interfaces, enumerated users and obtained tokens that provided access to live camera streams.

These activities demonstrate how the campaign combined stolen credentials, application weaknesses, automation and AI-assisted workflows rather than relying on a single malware family.

A North African Government Was Also Compromised

GTG-20006 was also linked to an intrusion targeting a North African government technology authority.

Attackers obtained credentials for a VPN appliance and used them to take control of a central account server.

The compromise exposed a database containing more than:

  • 300,000 national identity records
  • Commercial registry information belonging to more than 500,000 companies

The incident demonstrates how a single compromised remote-access credential can become the gateway to extremely valuable government datasets.

Microsoft 365 Token Theft

The actor also developed a cloud-email espionage platform known as Embassy Kit.

The framework was used to conduct device-code phishing campaigns against diplomatic and government personnel and steal Microsoft 365 authentication tokens.

Anthropic linked the activity to unauthorized access and email-data theft involving at least eight organizations, including a national prosecutor's office, a military education institution and a regional intergovernmental organization.

Security Updates Were Also Targeted

Another particularly concerning element involved attempts to interfere with security updates.

Anthropic observed Windows credential stealers delivered through fake-update social-engineering campaigns alongside remote-access tools designed to interfere with security updates on compromised machines.

This creates an additional advantage for the attacker: even if defenders publish new detection signatures, the compromised system may be prevented from retrieving or applying those protections.

For defenders, this means security-update failures should not always be treated as ordinary endpoint-management problems.

Unexpected update-service disruption can potentially be an indicator of post-compromise activity.

Indicators of Compromise

Anthropic published indicators associated with the GTG-20006 activity.

Selected indicators include:

Type Indicator
Domain ms365-live[.]com
Domain teams.ms365-live[.]com
Domain m365-owa[.]com
Domain owa-ms365[.]com
Domain ms365-device[.]com
Domain my-invite[.]org
Domain chamber-ua[.]org
Domain ukrinform-share[.]net
Domain docs-viewer[.]org
Domain wa-connect[.]eu
IP 104.145.210[.]184
IP 31.57.243[.]154
IP 104.194.151[.]133
IP 144.172.114[.]192
File WUEngine[.]exe
File DiagHost[.]exe
File msedgeupdate[.]exe
File version[.]dll

Anthropic's full indicator set contains additional domains, IP addresses, filenames and hashes and should be incorporated into enterprise threat-hunting workflows where appropriate.

Detection and Threat Hunting

The campaign illustrates why security teams should move beyond malware hashes and static signatures.

SOC teams should prioritize behavioral detections around:

Suspicious Malware Rebuilding

Monitor for repeated creation and replacement of executables with similar names or functionality.

Unexpected patterns such as:

malware detected → executable replaced → new hash → new network connection

should receive investigation.

Abnormal Process Relationships

Monitor for unusual relationships involving:

  • Browser processes
  • PowerShell
  • Command shells
  • Scripting engines
  • Update utilities
  • Temporary directories
  • Newly created executables

Security Update Tampering

Investigate endpoints where:

  • Windows Update services unexpectedly stop
  • Security products lose connectivity
  • Signature updates fail repeatedly
  • Security tooling configuration changes unexpectedly
  • Defender or EDR components are disabled

Device-Code Authentication

Monitor for unusual device-code authentication activity, particularly involving privileged or government accounts.

Defenders should investigate:

  • Unexpected device registrations
  • New devices associated with existing accounts
  • Authentication from unusual locations
  • Device-code sign-ins without corresponding user activity
  • Suspicious OAuth/token activity

DNS Hijacking

For organizations operating network-management or hospitality infrastructure, monitor unexpected DNS-record modifications and changes to authoritative DNS configurations.

Defensive Recommendations

Organizations can reduce exposure to this style of AI-assisted operation by strengthening controls across the entire attack lifecycle.

Move Beyond Hash-Based Detection

Static indicators remain useful, but they should be supplemented with:

  • Behavioral analytics
  • Process-tree analysis
  • EDR/XDR telemetry
  • Network anomaly detection
  • Memory analysis
  • Application control
  • Identity analytics

If malware variants can be automatically rebuilt, hash-based blocking becomes increasingly fragile.

Protect Identity and Authentication

Because device-code phishing and stolen credentials played important roles in the campaign, organizations should prioritize phishing-resistant authentication.

Recommended controls include:

  • FIDO2/passkeys
  • Strong conditional access
  • Device compliance enforcement
  • Risk-based authentication
  • Token protection
  • Continuous session monitoring
  • Restrictions on unauthorized device registration

Monitor Third-Party Infrastructure

Organizations should not limit monitoring to their own endpoints.

Third-party services that provide:

  • DNS
  • Wi-Fi
  • Identity
  • SaaS
  • Email
  • Hosting
  • Remote access

can become stepping stones into the primary target.

Protect the Detection Pipeline

Security teams should also monitor the security tools themselves.

Attackers may attempt to:

  • Disable EDR
  • Block signature updates
  • Tamper with security services
  • Prevent telemetry collection
  • Modify firewall rules
  • Block security infrastructure

A sudden reduction in endpoint telemetry should be treated as a potential security event rather than simply an operational fault.

The Bigger AI Security Problem

The most important lesson from the campaign is not that attackers can ask AI to write malware.

That capability was already expected.

The more significant development is operational automation.

AI can now potentially connect multiple individual tasks into a continuous workflow:

Reconnaissance → infrastructure setup → phishing → compromise → credential theft → persistence → detection monitoring → malware modification → redeployment → data theft

Anthropic's broader assessment is that AI is increasingly acting as an orchestrator rather than merely an assistant. Its investigation found multi-agent workflows performing reconnaissance, exploitation and data-exfiltration tasks while human operators remained involved primarily in selecting targets and reviewing results.

This changes the economics of cyber operations.

An attacker no longer needs to manually perform every repetitive task. AI can potentially compress hours or days of operational work into automated workflows.

What This Means for SOC Teams

For SOC analysts, the defensive implication is straightforward:

Do not assume that blocking one malware sample ends the attack.

If the adversary has an automated rebuild capability, a successful detection may simply trigger another malware variant.

Security teams should therefore focus on identifying the underlying behavior and attack infrastructure, including:

  • Initial access mechanisms
  • Identity abuse
  • Persistence
  • C2 patterns
  • Process behavior
  • DNS activity
  • Lateral movement
  • Data-access patterns
  • Security-control tampering

The objective should be to break the attack chain rather than continuously chase individual malware hashes.

Final Takeaway

The GTG-20006 campaign represents a notable evolution in AI-assisted cyber espionage.

The Russian state-linked actor did not merely use Claude to create malicious code. Anthropic found that the group integrated AI into an operational feedback loop capable of monitoring malware detections, modifying affected tools, rebuilding them and redeploying new versions.

The campaign targeted governments, military organizations, diplomatic entities, defense companies and drone-related technology providers, while also compromising third-party hospitality infrastructure and abusing cloud authentication mechanisms.

For defenders, the lesson is clear: AI can shorten the attacker adaptation cycle, making static detection alone increasingly insufficient.

Organizations should respond by combining endpoint behavior analytics, identity protection, network monitoring, threat intelligence, security-control integrity monitoring and rapid incident response.

The future contest between attackers and defenders may increasingly depend not only on who can detect threats first, but on who can adapt their detection and response mechanisms faster than the adversary can change the attack.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

critical Malware

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Threat actors are exploiting vulnerabilities in Cisco Secure Firewall Management Center (FMC) to gain access to enterprise environments, steal credentials and ultimately deploy Qilin ransomware, turning vulnerable security infrastructure into an entry point for broader network compromise.

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.