Anthropic on Thursday disclosed it had shut down a Russian state-backed hacking operation that leveraged its Claude AI system to build an automated process for rewriting malware whenever security tools flagged it. The AI company traced the activity to a threat group it designated GTG-20006, which corresponds with the cluster known publicly as Midnight Blizzard, APT29, or Cozy Bear. The hackers created an AI-powered workflow that automatically reconstructed and redeployed their attack tools if defensive software detected them, effectively neutralizing defenders' ability to stop the threats using conventional signature-based blocking.

The group's victims spanned more than 20 separate organizations, primarily military intelligence units within Ukrainian and European governments, along with diplomatic missions, defense agencies, and people linked to U.S. foreign policy, according to Anthropic. The toolkit deployed against these targets consisted of two Windows-based implants, a mobile exploitation kit, a credential-stealing tool aimed at browser password databases, a phishing platform mimicking government entities, and an administrative console for managing hijacked accounts. The operation also struck government agencies in the Middle East and maritime-focused bodies in Asia. In one North African intrusion, the attackers used VPN credentials to compromise a government technology authority's central account server and steal a credential database holding more than 300,000 national identity records plus commercial registry information for over half a million companies operating in that country. A separate cloud email espionage platform, using a device code phishing framework called Embassy Kit, enabled Microsoft 365 token theft against diplomatic and government personnel, resulting in unauthorized mail exfiltration from at least eight organizations including a national prosecutor's office, a military education institute, and a regional intergovernmental body.

The threat actor "used AI at every point in their operations," Anthropic stated. If monitoring AI agents spotted that any deployed malware had been caught by a security product, agents would then begin the process of autonomously altering and rebuilding the malware to sidestep existing detections, the report explained. The hackers also employed AI workflows to register domains, establish the hosting infrastructure for sending phishing emails, deliver those messages, and monitor command-and-control channels for successful breaches. The group's activity intersected with a campaign named CaptiveCrunch that was reported in July and August 2026 by ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs. In that operation, the attackers breached at least three hospitality vendors running hotel guest Wi-Fi and used stolen admin credentials to alter DNS records so they redirected to actor-controlled services, a tactic known as DNS hijacking. Hotel guests connecting to the compromised Wi-Fi had their traffic, device identifiers, and IP addresses forwarded to the hackers' servers, after which victims received ClickFix-style lures delivering Windows malware such as PowerChrome, WUEngine, Shadow C2, MiniPlasma, and CloudSyncSvc, Android malware including GiftDrop (a rebranded GiftsExpress surveillance RAT), and iOS malware named DarkSword.

Anthropic noted that the hackers leveraged data stolen from hotel management systems and individual guests' devices to pinpoint additional targets, especially people connected to Ukraine such as government officials and drone manufacturers. The group also attempted to hijack victims' WhatsApp accounts using headless browsers to link victim accounts as companion devices, then bulk-export Russian and Ukrainian language conversations while suppressing read receipts. The attackers even targeted surveillance platforms, discovering authorization flaws in camera streaming service application interfaces that let them enumerate users and harvest tokens granting access to victims' live camera feeds. In on-premises environments, the hackers used AI to track the stealth and persistence of their implants, the company said. "The result of the above is that AI has inverted the cost back onto defenders," Anthropic wrote. "Previously, defenders might have been able to slow an attacker's operational tempo via the deployment of a new detection." The shift means security teams can no longer rely on static detection methods to buy time, because adversaries can now automate the rebuild cycle faster than organizations can respond. For enterprises and government agencies, the implication is clear: defensive strategies built around periodic signature updates and manual threat hunting won't keep pace with adversaries who treat detection as a trigger for instant, automated evasion rather than a setback.