BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Russian hackers use AI to auto-evolve malware, Anthropic reveals

Russian state-sponsored group used Claude AI to rebuild malware and evade defenses for 20+ orgs

  • Russian state-sponsored group GTG-20006 (Midnight Blizzard) abused Anthropic’s Claude AI to automate malware rebuilding and evade security defenses.
  • The AI-driven workflow enabled automatic detection of deployed malware, followed by autonomous modification to bypass static security tools.
  • Attacks targeted over 20 organizations, including government ministries, defense bodies, and embassies in Ukraine, Europe, the Middle East, and Asia.
  • The operation also used AI for phishing infrastructure setup, DNS hijacking via compromised hotel Wi-Fi, and monitoring of command-and-control channels.

Anthropic on Thursday revealed it disrupted a campaign by Russian state-sponsored threat actor GTG-20006, which abused the company’s Claude AI to develop a fully automated cyber espionage workflow. The group, aligned with Midnight Blizzard (APT29), targeted military intelligence, diplomatic, and defense organizations in Ukrainian and European governments, as well as individuals connected to U.S. foreign policy.

- Advertisement -

The actor built an AI-driven process that automatically rebuilt and redeployed its toolkit whenever security products detected it. “If their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections,” Anthropic explained. This inverted the cost onto defenders, who previously could slow attackers by deploying new detections.

Beyond malware, the group used AI workflows to register domains, set up phishing hosting, and monitor command-and-control channels. Over 20 distinct organizations were singled out, including government ministries, defense bodies, embassies, think tanks, and defense-industrial companies, mainly in Ukraine and Europe, with extensions to the Middle East and maritime agencies in Asia. These efforts overlap with a campaign dubbed CaptiveCrunch documented by ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs.

The actor compromised at least three hospitality vendors operating hotel guest Wi-Fi by using stolen admin credentials to perform DNS hijacking. Guests connecting to the hotel Wi-Fi had their traffic, device identifier, and IP address sent to the actor’s servers, where victims received ClickFix-style lures delivering Windows, Android, and iOS malware. The threat actor also exploited authorization flaws in camera streaming services to harvest tokens and access live video feeds.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Nvidia stock to surge as Yotta orders 40,000 Vera Rubin GPUs

NVIDIA will begin shipping Vera Rubin GPUs this fall, with Indian data center firm...

Blockstream Refuses Ransom for 598.5 BTC Still Held After Liquid Hack

Blockstream refuses to pay ransom for 598.5 BTC still held after the Liquid Network...

Zcash Bucks Weekly Downtrend Among Crypto Majors

Markets are pricing roughly a 70% chance of a Fed rate hike at the...

Apple Delists Pump Fun App in US, India Amid New Tokenized Stock Pairs

Apple delisted Pump Fun’s iPhone app from US and India iOS App Stores on...

India: BRICS Pay aims for sovereignty, not de-dollarization

BRICS Pay focuses on financial sovereignty, not de-dollarization, according to BRICS International Chairman Pawan...

Must Read

Top 8 Best Anonymous Web Hosting Companies That Accept Crypto

Nowadays, there is plenty of information about people online, and malicious people use them to carry out inappropriate activities. If you want to keep...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading