Anthropic: Russia-linked group used Claude to automate malware

Anthropic reported a Russia-linked group used Claude from Dec 2025 to Aug 2026 to iterate malware until it evaded detection, targeting more than 20 organizations including Ukrainian and European bodies.

Anthropic reported it disrupted a cyberespionage campaign in which a Russia-linked actor used its Claude AI to test, modify and rebuild malware automatically until security products stopped flagging it. The activity took place between December 2025 and August 2026, the company’s threat report says.

The report links the actor’s tradecraft and targets to the group tracked as Midnight Blizzard. The process involved feeding malware into autonomous Claude agents that checked whether specific security tools detected the payload. When a tool flagged the code, the agents altered the codebase, rebuilt the malware and redeployed it, repeating that cycle until the malware passed without detection.

Anthropic described the technique as closing a historically manual loop: defenders would deploy new detection signatures and attackers would manually rewrite tools. Automating the loop let the attackers speed testing and adaptation of malware.

The campaign targeted more than 20 organizations across Europe, the Middle East and Asia. Identified victims included Ukrainian government ministries, European defense and intelligence bodies, embassies and think tanks. The actor exfiltrated mailboxes from two drone component manufacturers and stole a complete proprietary software development kit for a drone vision system. For at least one target, the attackers spent several days reverse-engineering device architecture, the hardware bill of materials and supplier dependencies.

Anthropic detailed delivery and persistence techniques. The actor compromised at least three hospitality vendors that operate hotel guest Wi‑Fi, used stolen administrator credentials to hijack DNS and redirected guest traffic to intercept communications. The report also describes a method for taking over victims’ WhatsApp accounts by linking them as companion devices through headless browsers and suppressing read receipts so conversations could be exported without alerting users. At least two former high-level Ukrainian officials were targeted in that manner.

The company reported it disrupted the activity, applied the findings to strengthen internal AI safeguards and shared intelligence with authorities and industry partners where appropriate. The report frames these incidents alongside a broader pattern of threat actors abusing AI and targeting AI infrastructure and credentials.

Anthropic identified additional actors that targeted AI systems. One actor, tracked as GTG-50021, operated a fraudulent Claude reseller that proxied paying customers to another model while a bundled client app harvested Anthropic account credentials for resale. Another actor, GTG-50020, used prompt injection against an AI vendor’s automated evaluation sandbox to try to extract production API keys tied to multiple providers. That actor then launched a campaign against roughly 30 AI companies attempting to access a pre-release Claude model; Anthropic reports those attempts failed.

The report warns that stolen AI API keys can provide attackers with free compute, resale value and cover, since activity performed with a legitimate key is attributed to the keyholder. Anthropic recommends treating AI API keys and agent integrations with the same access controls and monitoring as other production credentials.

The cyber operations findings are part of a wider report in which Anthropic describes seven categories of AI misuse it has disrupted, including influence operations, surveillance and risks tied to biological and conventional weapons. The company links the weapons-related concerns to separate internal research on how large models could be used for intelligence targeting and weapons development.

Articles by this author