Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
A Russian state-sponsored threat actor, linked to Midnight Blizzard (APT29/Cozy Bear) and operating under the designation GTG-20006, has been leveraging AI to continuously rebuild and evade malware detection. The group has targeted Ukrainian and European government organizations, including military intelligence, diplomatic missions, and defense companies, alongside Middle Eastern and maritime agencies. They utilize a sophisticated toolkit including implants, phishing platforms, and credential stealers, all while employing AI to monitor and adapt to security defenses, resulting in a reversal of the cost of defense for security teams.
Anthropic revealed that a Russian state-sponsored threat actor, operating under the designation GTG-20006, has been utilizing AI to continuously rebuild and evade malware detection. This group is linked to Midnight Blizzard (APT29/Cozy Bear) and has been targeting Ukrainian and European government organizations, including military intelligence, diplomatic missions, and defense companies, alongside Middle Eastern and maritime agencies.
The actor employs a sophisticated toolkit including two Windows-based implants (PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc), a mobile exploitation kit (GiftDrop/GiftsExpress), a credential stealing tool, and a phishing platform. They use AI to monitor how well their tools evade detection from known security defenses, autonomously modifying and rebuilding malware to bypass existing detections. Once malware bypasses detection, it is staged on disposable hosting servers to which victims are redirected via phishing, ClickFix, and DNS hijacking schemes.
Attacks have been observed targeting over 20 distinct organizations, including government ministries, defense and intelligence bodies, embassies, diplomatic missions, think tanks, and defense-industrial companies, primarily in Ukraine and Europe, with extensions to the Middle East and Asia. The group has also been linked to a campaign dubbed CaptiveCrunch, where they compromised hospitality vendors to hijack hotel guest Wi-Fi and steal user data.
Furthermore, the actor has been found to use stolen hotel data and guest device information to identify additional targets, particularly individuals associated with Ukraine, such as government officials and drone manufacturers. They also leveraged WhatsApp to link victim accounts as companion devices and bulk-export Russian and Ukrainian language conversations while suppressing read receipts. The group has targeted surveillance platforms, exploiting vulnerabilities in camera streaming services to enumerate users and harvest tokens, granting access to live camera streams.
In a separate incident, GTG-20006 targeted a North African government technology authority, leveraging compromised VPN credentials to exfiltrate over 300,000 national identity records and commercial registry data. They also developed a cloud email espionage platform, utilizing a device code phishing framework (Embassy Kit) to steal Microsoft 365 tokens and exfiltrate mail records from at least eight organizations, including a national prosecutor's office, a military education institute, and a regional intergovernmental organization. The actor delivers Windows credential stealers via fake update-themed social engineering lures and auxiliary tools for facilitating remote access and tampering with security updates to maintain undetected malware presence. The result is a reversal of the cost of defense, as AI has inverted the traditional dynamic where defenders could slow an attacker’s operational tempo.
