VMTech
Discuss a project

Anthropic Disrupts AI-Assisted Malware Rebuild Campaign

Anthropic Disrupts AI-Assisted Malware Rebuild Campaign

Anthropic reports AI-assisted espionage workflow

Anthropic said it disrupted a campaign by GTG-20006, a Russian state-sponsored threat actor that used Claude to develop an AI-assisted workflow for rebuilding and redeploying malware after detection. Anthropic said the group used AI to monitor how effectively its tools evaded known security products, then autonomously modified artifacts that had been identified.

The company describes GTG-20006 as a generative threat group and said the cluster aligns with broader reporting on Midnight Blizzard, also known as APT29 and Cozy Bear. Its activity targeted military intelligence interests in Ukrainian and European governments, as well as diplomatic and defence organizations and people connected to U.S. foreign policy.

Static detections face a faster rebuild cycle

The reported toolkit included two Windows implants, a mobile exploitation kit, a browser password-store credential stealer, a phishing platform impersonating priority targets, and an administrative console for compromised accounts. Once altered artifacts could bypass detection, the group staged them on disposable hosting servers and redirected victims to them through phishing, ClickFix lures, and DNS hijacking.

Anthropic said the group also used AI workflows to register domains, configure phishing-hosting infrastructure, deliver messages, and monitor command-and-control channels. More than 20 organizations were selected during reconnaissance and live operations, including ministries, defence and intelligence bodies, embassies, think tanks, defence-industrial companies, Middle Eastern targets, and maritime-related government agencies in Asia.

Hotel Wi-Fi and cloud accounts expanded the attack surface

Anthropic said the actor compromised at least three hospitality vendors operating hotel guest Wi-Fi. Using compromised administrative credentials, it changed DNS records to actor-controlled services. Hotel guests connecting through the affected vendors had traffic, device identifiers, and IP addresses sent to the actor's servers before receiving device-specific ClickFix lures.

The delivered malware included PowerChrome, WUEngine, Shadow C2, MiniPlasma, and CloudSyncSvc for Windows; GiftDrop for Android; and DarkSword for iOS. The actor also used data from hotel management systems and guest devices to identify further targets, including Ukrainian officials and drone manufacturers.

Additional operations included attempts to link victims' WhatsApp accounts as companion devices through headless browsers, harvesting tokens from surveillance-platform interfaces, and stealing Microsoft 365 tokens with a device-code phishing framework called Embassy Kit. Anthropic said the latter campaign accessed and exfiltrated mail records from at least eight organizations.

Business implication

For security teams, the reported workflow reinforces the need to treat malware detection as the start of an investigation rather than the end: monitor identity, DNS, hosting, email-token, and command-and-control activity, and prepare containment processes for tooling that may be rapidly rebuilt after a signature is deployed.

#cybersecurity#malware#threatintel#aisecurity
Open analytics
On the site 0 views
min read 3 11.09.2026
Instagram

Anthropic Disrupts AI-Assisted Malware Rebuild Campaign

Open the post on Instagram ↗