Anthropic dismantles a Russian state campaign that used Claude to autonomously rebuild malware, hijack hotel Wi-Fi, and breach diplomatic email accounts across Europe, Ukraine, and beyond.

Intelligence Lead

Anthropic has confirmed that a Russian state-sponsored unit tracked as GTG-20006, assessed to be affiliated with Midnight Blizzard (APT29, also known as Cozy Bear), built an AI-driven pipeline atop the company's Claude models to detect when its malware had been flagged by security software and rebuild it faster than defenders could respond. The operation compromised more than twenty government, diplomatic, defense, and infrastructure targets across Ukraine, Europe, the Middle East, and maritime agencies in Asia, and separately breached a North African government authority holding over 300,000 national identity records. The disclosure is among the clearest public confirmations to date that a nation-state intelligence service has operationalized generative AI as a force multiplier across the full attack lifecycle, from reconnaissance through exfiltration.

Situation Report

According to Anthropic's threat intelligence report, published 11 September 2026, GTG-20006 developed monitoring agents that tracked how well its malware evaded known security defenses. When a deployed artifact was flagged, the agents autonomously modified and rebuilt the code to defeat the specific detection, then re-staged it on disposable hosting infrastructure. The toolkit assessed includes two Windows-based implants, a mobile exploitation kit, a browser-based credential stealer, a phishing platform mimicking government portals, and an administrative console for managing compromised accounts. The actor used AI workflows to register domains, provision hosting, send phishing messages, and monitor command-and-control channels, compressing a process that traditionally required a full intrusion team into a largely automated pipeline.

Confirmed targeting spanned government ministries, defense and intelligence bodies, embassies, think tanks, and defense-industrial firms, concentrated in Ukraine and Europe but extending to the Middle East and to maritime-related agencies in Asia. A parallel and overlapping campaign, tracked separately by ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs as CaptiveCrunch, compromised at least three hospitality vendors that operate hotel guest Wi-Fi. The actor altered DNS records at the vendor level to redirect guest traffic, harvesting device identifiers and IP addresses, then served device-specific malware, including Windows implants such as PowerChrome and Shadow C2, an Android surveillance tool rebranded as GiftDrop, and the iOS implant DarkSword.

Reported intrusions also include a breach of a North African government technology authority, in which the actor exploited a VPN appliance to hijack the central account server and exfiltrate the entire credential database, comprising more than 300,000 national identity records and commercial registry data on over half a million companies. A separate cloud email espionage platform built by the actor, using a device-code phishing framework internally designated Embassy Kit, orchestrated a Microsoft 365 token-theft campaign against diplomatic and government personnel, resulting in confirmed mail exfiltration from at least eight organizations, including a national prosecutor's office and a military education institute.

Anthropic further assessed that the actor exploited authorization flaws in camera-streaming service APIs to harvest tokens granting access to victims' live camera feeds, and used headless browsers to hijack victims' WhatsApp accounts as linked companion devices, bulk-exporting Russian- and Ukrainian-language conversation histories while suppressing read receipts to avoid detection.

Background & Context

Midnight Blizzard, the cluster to which GTG-20006 has been linked with moderate-to-high confidence, is the same designation Microsoft applied to the actors behind the 2020 SolarWinds supply-chain compromise and subsequent intrusions into US federal agencies and technology firms. The group is broadly assessed to operate in support of Russia's Foreign Intelligence Service (SVR), with a persistent mandate to collect against Western government, diplomatic, and defense targets.

The disclosure lands roughly two weeks after the European Union and United Kingdom imposed a fresh sanctions round on Russian state and criminal cyber proxies, formally attributing a cyberattack on Poland's energy grid to the FSB's Centre 16. Together, the two actions indicate that Western governments and the private sector are moving toward more frequent, more specific public attribution of Russian cyber activity, a shift partly aimed at raising the political cost of operations that have historically been conducted with limited consequence.

Anthropic's report is also notable as a case study in AI governance. Frontier AI developers have increasingly positioned themselves as a chokepoint capable of detecting and disrupting misuse of their own models, a role with no clear precedent in prior generations of dual-use technology.

Analysis & Assessment

The central assessment to draw from this disclosure is structural rather than incident-specific: automated, AI-driven rebuild loops shift the economics of cyber conflict in the attacker's favor. Static detection signatures, the backbone of commercial endpoint security, lose effectiveness against an adversary that can regenerate evasive variants continuously and at near-zero marginal cost. Anthropic's own characterization, that AI has "inverted the cost back onto defenders," is a reasonable framing and likely understates the trajectory rather than overstates it.

It is assessed as likely that other well-resourced state actors, including Chinese and Iranian services already reported to be experimenting with AI-assisted operations, will adopt comparable rebuild-on-detection architectures within twelve to eighteen months, whether through Western frontier models, open-weight alternatives, or domestically developed systems less subject to vendor-side monitoring. It is also assessed as likely that criminal ransomware operators, who tend to adopt state tradecraft with a lag of one to two years, will follow.

The hospitality Wi-Fi vector deserves particular attention. Hotel networks sit outside most enterprise security perimeters entirely, and the technique's low cost and high yield against traveling officials, executives, and journalists suggests it will be reused well beyond this specific campaign, independent of whether GTG-20006's other infrastructure is dismantled.