news.mlab.sh
Back to the feed
threat-intel

Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

High
Summary

Anthropic has disrupted a cyberespionage operation led by a Russia-linked group, Midnight Blizzard, that utilized Claude AI to continuously evade detection by security products. The group targeted over 20 organizations globally, including Ukrainian and European government entities, and stole sensitive data like drone component software and admin credentials. Beyond espionage, the report highlights a growing trend of threat actors targeting AI infrastructure and credentials, leveraging stolen keys for various malicious purposes.

Anthropic has successfully disrupted a cyberespionage operation attributed to a Russia-linked group, tracked as Midnight Blizzard. The activity spanned from December 2025 to August 2026 and involved the use of Claude AI to continuously adapt malware and bypass security defenses. According to Anthropic’s threat intelligence report, Midnight Blizzard targeted over 20 organizations, including Ukrainian and European government ministries, defense and intelligence bodies, embassies, and think tanks, with additional targets extending to the Middle East and Asia.

The group exfiltrated mailboxes from two drone component manufacturers and stole a complete proprietary software development kit for a drone vision system. They spent several days reverse-engineering the architecture, hardware bill of materials, and supplier dependencies. Furthermore, the group compromised at least three hospitality vendors operating hotel guest Wi-Fi, leveraging stolen admin credentials to redirect guest traffic through DNS hijacking. Microsoft separately documented this delivery method in July under the name CaptiveCrunch and linked it to Midnight Blizzard.

Anthropic also noted that the group took over victims’ WhatsApp accounts by linking them as companion devices through headless browsers, suppressing read receipts to export conversations undetected. At least two former high-level Ukrainian officials were targeted this way. The company disrupted the activity, used what it learned to strengthen its AI safeguards, and shared intelligence with authorities and industry partners where appropriate.

Beyond espionage, Anthropic’s report describes a separate, growing trend: threat actors are not only abusing AI as a tool to achieve their goals, but also targeting AI credentials and infrastructure. One group, tracked as GTG-50021, ran a fraudulent Claude reseller service that silently proxied paying customers to a different model while a bundled client application harvested their Anthropic account credentials for resale. A more direct case involved GTG-50020, a financially motivated Russian-speaking group that had previously targeted hotel-booking and fintech platforms. According to Anthropic, the actor used prompt injection against an AI vendor’s own automated evaluation sandbox, causing it to hand over production API keys belonging to multiple providers.

The hacker then used those stolen keys to continue its attacks and, separately, launched a campaign against roughly 30 AI companies over several days. Anthropic said the actor’s explicit goal, pursued through more than a dozen attempted avenues, was gaining access to a pre-release Claude model. The company emphasized that organizations should treat AI API keys and agent integrations with the same scrutiny as production credentials, as stolen keys can be used for resale value, free compute, and cover for malicious activity. These cyber operations findings are part of a broader report spanning seven categories of misuse Anthropic has disrupted, including influence operations, surveillance, and biological and conventional weapons misuse.

Read the full article at SecurityWeek