Anthropic says Russian hackers used Claude AI to automate malware avoidance

Anthropic disrupted a cyberespionage operation whose trading and targeting matched the Russian state-nexus group tracked as Midnight Blizzard, the company said in a threat intelligence report released this week.

The report covers the activity the company identified and closed between December 2025 and August 2026.

According to Anthropic, Midnight Blizzard used Claude to monitor how well its malware evaded detection by security products. When a tool is flagged, AI agents automatically modify and restore it, then redistribute it, repeating the process until the malware is detected again.

Anthropic said this shifts the cost of the detection-avoidance cycle back onto defenders. Historically, new detection signatures have forced attackers into a slower, manual cycle of rewriting tools. The company said AI now allows capable actors to “close the loop” faster than defenders can respond.

The Russian-linked hackers targeted more than 20 organizations, according to the report. Victims included Ukrainian and European government ministries, defense and intelligence agencies, embassies and think tanks, with additional targets in the Middle East and Asia.

Anthropic noted that the actor snagged mailboxes from two drone component manufacturers and stole a complete proprietary software development kit for a drone vision system. The attacker spent several days reverse engineering its architecture, hardware specification and vendor dependencies.

Advertising. Scroll to continue reading.

The group also compromised at least three hospitality providers that manage Wi-Fi for hotel guests, using stolen administrator credentials to redirect guest traffic through DNS hijacking. Microsoft separately documented this delivery method in July under the name CaptiveCrunch and linked it to Midnight Blizzard.

Anthropic said the same actor took over victims’ WhatsApp accounts, connecting them as companion devices through headless browsers, suppressing read receipts to export conversations undetected. At least two former high-ranking Ukrainian officials have been targeted in this way.

Anthropic said it shut down the activity, used what it learned to strengthen its AI safeguards, and shared information with authorities and industry partners when appropriate.

AI infrastructure as a target

Beyond espionage, Anthropic’s report describes a separate, growing trend: threat actors are not only misusing AI as a tool to achieve their goals, but are also targeting AI’s credentials and infrastructure.

One group, tracked as GTG-50021, ran a fraudulent Claude distribution service that quietly proxied paying customers to a different model while a batch client application collected their Anthropic account credentials for resale, the report said.

A more direct case involved GTG-50020, a financially motivated Russian-speaking group that previously targeted hotel reservations and fintech platforms. According to Anthropic, the actor used an instant injection against an AI vendor’s own automated sandbox to evaluate, which caused it to hand over production API keys belonging to multiple vendors.

The hacker then used these stolen keys to continue his attacks and, separately, launched a campaign against approximately 30 AI companies over several days. Anthropic said the actor’s express goal, pursued through more than a dozen attempts, was to gain access to a pre-model of Claude. However, none of the attempts were successful.

Anthropic said attackers can use the stolen AI credentials for resale value, free computation for their own operations, and cover as the resulting activity is attributed to the legitimate keyholder. The company said organizations should treat AI API keys and agent integrations with the same care as production credentials.

Findings from cyber operations are part of a broader report covering seven categories of abuse that Anthropic disrupted, including influence operations, surveillance, and misuse of biological and conventional weapons. The company noted that the latter is associated with a separate Frontier Red Team study she published the capabilities of artificial intelligence models to guide intelligence and develop conventional weapons.

Connected: Advanced scan reveals fourth cyber incident with Rogue Claude

Connected: AI gives under-resourced attackers nationwide reach, Google warns

Connected: US agencies warn that China is systematically extracting frontier AI capabilities

Leave a Reply

Your email address will not be published. Required fields are marked *