ZeroHour
The Hacker Newspublished ()ingested [email protected] (The Hacker News)2
Part of a story covered by 11 sources: “Anthropic threat report: APT29-linked spies, ShinyHunters and Chinese clusters used Claude agents to automate attacks, espionage and weapons research” — merged summary and timeline →

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

highThreat actor exploited in the wildimportance 82
AI summary · glm-5.3-flash

Anthropic disrupted APT29-linked GTG-20006, which used Claude to autonomously rebuild malware, hijack hotel Wi-Fi DNS, and target 20-plus Ukrainian, European, and US-linked organizations.

Anthropic attributed the campaign to GTG-20006, aligned with Midnight Blizzard (APT29/Cozy Bear), which developed an AI-driven process that monitors its implants against security products and autonomously rebuilds and redeploys detected malware. Targets included military intelligence, diplomatic, and defense organizations in Ukraine and Europe, plus Middle East and Asian maritime agencies; the actor compromised at least three hotel Wi-Fi vendors via DNS hijacking and served ClickFix lures delivering Windows, Android, and iOS malware such as PowerChrome, GiftDrop, and DarkSword. Operations also included a North African breach exfiltrating over 300,000 national identity records and 500,000-plus company registry entries, an Embassy Kit device-code phishing campaign stealing Microsoft 365 tokens from at least eight organizations, and WhatsApp account takeover using headless browsers. The campaign overlaps with CaptiveCrunch reporting from ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs.

  • AI agents monitored detection status and autonomously rebuilt malware to evade static detections
  • Hotel guest Wi-Fi DNS hijacking exposed guest traffic, device identifiers, and IP addresses
  • North African intrusion exfiltrated 300,000+ national identity records and 500,000+ company registry entries
  • Embassy Kit device code phishing stole M365 tokens from at least eight government organizations
  • Stolen hotel and device data used to target Ukraine-linked officials and drone manufacturers
Full article834 words · extracted from thehackernews.com · click to collapse

Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve.

The operation has been attributed to a cyber espionage group it calls GTG-20006 (where "GTG" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight Blizzard (aka APT29 and Cozy Bear).

This actor is said to have developed an AI-driven process to automatically rebuild and re-deploy their toolkit if it was detected by security products, thereby undermining defenders' ability to block the artifacts via static detections.

Attacks mounted by GTG-20006 have targeted military intelligence targets in Ukrainian and European governments, along with diplomatic and defense organizations and individuals connected to U.S. foreign policy.

The toolkit includes a number of programs -

  • Two Windows-based implants
  • A mobile exploitation kit
  • A credential stealing tool that targets browser password stores
  • A phishing platform designed to mimic priority targets like government organizations, and
  • An administrative console used to manage compromised accounts

"The actor also used AI to monitor how well their tools evaded detections from known security defenses," Anthropic explained. "If their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections."

Once the artifacts can bypass detection, they are staged on disposable hosting servers to which victims are redirected to so as to retrieve the malware via phishing, ClickFix, and DNS hijacking schemes.

The threat actor has also been observed using AI workflows to register domains, set up the hosting infrastructure used to send phishing emails, as well as to deliver the messages and monitor command-and-control (C2) channels for successful compromises.

More than 20 distinct organizations were singled out over the course of the reconnaissance and live operations. This included government ministries, defense and intelligence bodies, embassies and diplomatic missions, think tanks, and defense-industrial companies, mainly in Ukraine and Europe. The attacks also extended to the Middle East and maritime-related government agencies in Asia.

These efforts also overlap with a campaign dubbed CaptiveCrunch documented in recent months by ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs.

"The actor compromised at least three hospitality vendors that operate hotel guest Wi-Fi," Anthropic said. "They used compromised admin credentials to modify DNS records so that they pointed to services owned by the actor (a technique known as DNS hijacking). Guests of hotels using the compromised vendors who connected to the hotel Wi-Fi had their traffic, device identifier, and IP address sent to the actor's servers."

In the next stage, victims were served ClickFix-style lures to deliver Windows, Android, and iOS malware tailored to their device -

  • Windows - PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc
  • Android - GiftDrop, a rebranded version of GiftsExpress Android surveillance RAT
  • iOS - DarkSword

Furthermore, the threat actor has been found to use data stolen from the hotel management systems and the individual guests' devices to identify additional targets, particularly individuals associated with Ukraine, such as government officials and drone manufacturers.

This is complemented by attempts to take over victims' WhatsApp accounts using headless browsers to link victim accounts as companion devices and ultimately bulk-exporting Russian and Ukrainian language conversations from them while suppressing read receipts.

"The actor also targeted surveillance platforms," Anthropic said. "They found authorization flaws in the application interface of camera streaming services, and from there they enumerated users and harvested tokens that granted them access to the victims’ live camera streams."

GTG-20006 has been attributed to an intrusion targeting a North African government technology authority, leveraging credentials to a VPN appliance to hijack the central account server and exfiltrate the entire credential database consisting of over 300,000 national identity records and the commercial registry data of more than half a million companies operating in the country.

Also developed by the threat actor is a cloud email espionage platform, which used a device code phishing framework codenamed Embassy Kit to orchestrate a Microsoft 365 token theft campaign targeting diplomatic and government personnel, resulting in the unauthorized access and exfiltration of mail records from at least eight organizations, including a national prosecutor's office, a military education institute, and a regional intergovernmental organization.

The threat actor has also been observed delivering Windows credential stealers via fake update-themed social engineering lures, along with auxiliary tools for facilitating remote access and tampering with the victim machine's security updates so that the artifacts remain undetected.

"The actor used AI at every point in their operations," Anthropic said. "In on-premises environments, the actor used AI to monitor the stealth and persistence of their implants. "The result of the above is that AI has inverted the cost back onto defenders. Previously, defenders might have been able to slow an attacker's operational tempo via the deployment of a new detection."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html