Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Source note: This article is based on Anthropic's September 2026 threat intelligence report. Attribution and severity claims reflect the company's internal assessment, not independent verification.
A human defender spends hours analyzing a sample, extracting indicators, updating signatures, and deploying patches. An automated system can compress that cycle into minutes. Anthropic documented exactly this inversion: between December 2025 and August 2026, the Russian group Midnight Blizzard (GTG-20006) used Claude AI to autonomously close the detection-evasion loop of its malware, making defensive response structurally slower than the attack.
- Anthropic disrupted GTG-20006 activity between December 2025 and August 2026: the group, attributed to Midnight Blizzard, used Claude to automate malware modification, recompilation, and redeployment in response to detection.
- More than 20 organizations were targeted, including Ukrainian and European government ministries, defense and intelligence bodies, embassies, think tanks, and defense-industrial companies, with extension to the Middle East and Asia.
- The group exfiltrated mailboxes from two drone component manufacturers, stole a proprietary SDK for a drone vision system, and compromised at least three hospitality vendors for hotel guest Wi-Fi.
- At least two former senior Ukrainian officials were targeted with WhatsApp account takeovers via headless browsers configured as companion devices.
The Mechanism: The Loop That Outpaces the Defender
The technical core of the operation is a feedback loop orchestrated by multi-agent AI. When a Midnight Blizzard tool was flagged by security products, the infrastructure triggered an automatic sequence: detection of the flag, code modification, recompilation, redeployment, and iterative verification of the new undetected status. The process repeated until the undetected state was restored.
According to Anthropic's threat intelligence report, cited by SecurityWeek, "AI agents automatically modified and rebuilt [malware]... repeating the process until the malware went undetected again." The same source reports the internal assessment: "AI now lets capable actors close the loop faster than defenders can respond."
This speed inverts the traditional cost asymmetry of cybersecurity. Where defenders imposed costs on attackers by forcing manual rewrites, the cost of the detection-evasion cycle now falls on defenders, who must react to an adversary that does not slow down.
Targets and Impact: Beyond Pure Evasion
The group operated against high-profile targets. More than 20 distinct organizations were hit, with a concentration on Ukrainian and European government ministries, defense and intelligence bodies, embassies and diplomatic missions, think tanks, and defense-industrial companies. The activity also extended to the Middle East and Asia.
Among the documented operations, Midnight Blizzard exfiltrated the mailboxes of two drone component manufacturers. It then stole a complete proprietary SDK for a drone vision system, dedicating several days to reverse engineering the architecture, hardware bill of materials (BOM), and supplier dependencies. The objective was to map the supply chain, not merely steal the code.
The compromise infrastructure included at least three hospitality vendors for hotel guest Wi-Fi, compromised through stolen administrative credentials and used for DNS hijacking. SecurityWeek reports that Microsoft documented this method as "CaptiveCrunch" in July 2026.
At least two former senior Ukrainian officials were targeted with WhatsApp account takeovers. The technique employed headless browsers configured as companion devices, with read receipt suppression to maintain covert access.
"The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing tasks" — Anthropic Threat Intelligence Report, cited by Japan Times and NTD
Why This Matters
The operation documented by Anthropic signals a qualitative shift in the abuse of publicly available AI systems. The automated evasion loop does not require access to proprietary infrastructure or model vulnerabilities: it uses Claude's standard code generation and modification capabilities through fraudulent accounts.
The difference from previous techniques lies in iteration speed. When malware modification required human intervention, defenders had a time window to update signatures and deploy patches. With AI automation, that window shrinks to the loop's execution time.
The report explicitly states that the group's use of AI "went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing tasks." This distance between instrumental use and structured operational use is what Anthropic presents as the qualifying element of the case.
What to Do Now
The GTG-20006 case raises concrete operational questions for CISOs and threat intelligence teams:
- Detect the loop, not the sample: Defenses based on static signatures lose effectiveness when malware mutates automatically between detection and response. Teams must invest in behavioral detection that identifies the loop pattern (rapid sequences of compilation, deployment, and testing) rather than the final file signature.
- Response speed as a strategic metric: If the attacker's average loop closure time is lower than the SOC's average response time, the defense is structurally behind. Measuring and reducing this gap becomes a priority.
- Monitor corporate AI accounts: Access to models like Claude through fraudulent accounts is the prerequisite for the entire chain. Controls on provisioning, anomalous usage patterns, and correlation between accounts and development activity must be strengthened.
- Supply chain intelligence: The exfiltration of SDKs and reverse engineering of hardware BOMs indicate that targets are not only final data, but knowledge of how components are produced. Vendors of critical components must be treated as an extension of the defensive perimeter.
The case does not require exotic new technologies. It requires that defensive response speed match or exceed offensive automation speed—an organizational objective more than a technical one.
The Tipping Point
Jacob Klein, Anthropic's head of threat intelligence, summarized the transition: "A year ago, let's say you wanted to optimize a drone or optimize the software on a missile, the models just wouldn't be as good at that task as they are now." The same capability improvement that makes AI useful to defenders makes it available to attackers, without significant access barriers.
Anthropic's September 2026 report does not describe a vulnerability to patch. It describes a condition: capable models, accessible, used by capable actors for operational tasks. The question for the industry is not whether this will happen again, but how quickly defenders can restructure their processes to avoid being systematically slower than the adversary.
Primary source: Anthropic Threat Intelligence Report, September 2026. Corroboration: SecurityWeek, Japan Times, NTD.
Information verified against cited sources and current as of publication.
Sources
- https://www.anthropic.com/threat-intelligence-report-september-2026
- https://www.securityweek.com/anthropic-says-russian-hackers-used-claude-ai-to-automate-malware-evasion/
- https://www.japantimes.co.jp/business/2026/09/11/tech/anthropic-russa-china-ai-claude/
- https://www.ntd.com/anthropic-disrupts-russian-chinese-ai-campaigns-targeting-its-claude-models_1172022.html
- https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
- https://www.bbc.com/news/articles/cx2zrrpkx20o
- https://www.politico.com/news/2026/09/10/bad-actors-china-russia-weaponizing-anthropic-01070435
- https://support.claude.com/en/articles/15363606-why-claude-switched-models-in-your-conversation-with-fable-5-or-fable-5-1
- https://podcast.securityweek.com/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.