Anthropic Disrupts Russian Espionage Campaign Using Claude to Automate Malware
State-sponsored hackers used AI to rebuild detected malware in near real-time, targeting Ukrainian defense and drone supply chains.
Anthropic has disrupted a sophisticated cyber espionage campaign conducted by a Russian state-sponsored group that used the Claude AI model to automate the iteration of malware. The operation allowed attackers to bypass security detections faster than defenders could respond, marking a significant escalation in AI-driven warfare.
The threat actor, tracked as GTG-20006, is attributed to Midnight Blizzard—also known as APT29, Cozy Bear, or BlueBravo—which is linked to Russia's Foreign Intelligence Service (SVR). According to Anthropic's September 2026 Threat Intelligence Report, the group used Claude to identify, modify, and redeploy malware artifacts immediately after they were detected by security products. This "closed-loop" process enabled the group to maintain persistence by evolving their code in near real-time.
Targeted Infrastructure and Tactics
Between December 2025 and August 2026, the campaign targeted more than 20 organizations, primarily in Ukraine, focusing on government agencies, defense contractors, and drone-supply-chain entities. The group employed diverse attack vectors to gain access, including the compromise of hotel Wi-Fi providers and the manipulation of DNS records to redirect targets toward attacker-controlled infrastructure.
In one notable instance, the group used Claude to reverse-engineer a proprietary software development kit (SDK) for a drone vision system. The SDK had been stolen from a military drone manufacturer, and the AI was used to decode the proprietary system to further the group's intelligence goals.
The Shift in Cyber Defense Costs
This campaign represents a fundamental shift in the economics of cyber defense. Traditionally, security teams held an advantage once a malware signature was identified and deployed across a network, effectively slowing the attacker's operational tempo. However, the integration of AI into the "cyber kill chain" allows adversaries to neutralize these detections almost instantly.
As noted in the Anthropic Threat Report, AI has effectively inverted the cost of these operations back onto the defenders. By using AI as an orchestrator for payload modification, capable adversaries can now bypass traditional security detections faster than human defenders can develop and deploy new countermeasures.
Future Implications
This operation is part of a broader trend where state-backed actors are integrating generative AI into every stage of their operations, from initial reconnaissance to final payload delivery. The ability to automate the rebuilding of malware suggests that static detection methods are becoming increasingly obsolete against high-tier threats.
Security researchers will now be watching for similar patterns of AI-orchestrated persistence across other state-sponsored groups. While Anthropic has disrupted this specific campaign, the precedent set by Midnight Blizzard demonstrates that AI is no longer just a tool for writing initial code, but a critical component for maintaining long-term access to high-value targets.