BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Russian hackers use AI to auto-evolve malware, Anthropic reveals

Russian state-sponsored group used Claude AI to rebuild malware and evade defenses for 20+ orgs

  • Russian state-sponsored group GTG-20006 (Midnight Blizzard) abused Anthropic’s Claude AI to automate malware rebuilding and evade security defenses.
  • The AI-driven workflow enabled automatic detection of deployed malware, followed by autonomous modification to bypass static security tools.
  • Attacks targeted over 20 organizations, including government ministries, defense bodies, and embassies in Ukraine, Europe, the Middle East, and Asia.
  • The operation also used AI for phishing infrastructure setup, DNS hijacking via compromised hotel Wi-Fi, and monitoring of command-and-control channels.

Anthropic on Thursday revealed it disrupted a campaign by Russian state-sponsored threat actor GTG-20006, which abused the company’s Claude AI to develop a fully automated cyber espionage workflow. The group, aligned with Midnight Blizzard (APT29), targeted military intelligence, diplomatic, and defense organizations in Ukrainian and European governments, as well as individuals connected to U.S. foreign policy.

- Advertisement -

The actor built an AI-driven process that automatically rebuilt and redeployed its toolkit whenever security products detected it. “If their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections,” Anthropic explained. This inverted the cost onto defenders, who previously could slow attackers by deploying new detections.

Beyond malware, the group used AI workflows to register domains, set up phishing hosting, and monitor command-and-control channels. Over 20 distinct organizations were singled out, including government ministries, defense bodies, embassies, think tanks, and defense-industrial companies, mainly in Ukraine and Europe, with extensions to the Middle East and maritime agencies in Asia. These efforts overlap with a campaign dubbed CaptiveCrunch documented by ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs.

The actor compromised at least three hospitality vendors operating hotel guest Wi-Fi by using stolen admin credentials to perform DNS hijacking. Guests connecting to the hotel Wi-Fi had their traffic, device identifier, and IP address sent to the actor’s servers, where victims received ClickFix-style lures delivering Windows, Android, and iOS malware. The threat actor also exploited authorization flaws in camera streaming services to harvest tokens and access live video feeds.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Porsche abandons 911 NFT project, values down 96%

Porsche has officially shut down its PIONΞERS CIRCLE 911 NFT project, leaving holders with...

GitLab AI Gateway critical flaw enables remote code execution

GitLab disclosed a critical vulnerability, CVE-2026-90970, in its AI Gateway with a CVSS score...

Lloyds: 3 in 4 UK Banks Eye Tokenization Shift

Nearly 75% of major UK financial institutions expect tokenization to reshape financial services, according...

Bitcoin Reaches $86.8K as Inflation Reading Raises Rate Pause Odds

Bitcoin traded at $86,757 Friday, up 3% on the day and 2% over the...

Nike stock crashes to 13-year low amid layoffs

Nike's stock fell to a 13-year low as revenue slipped 4% and the company...

Must Read

Top 9 VPNs That Accept Bitcoin And Crypto

CyberGhost | FastVPN | TorGuard | Private Internet Access | ExpressVPN | NordVPN | Private VPN | SurfShark | AirVPN | Why Buy VPN...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading