The record
Written from the 2 reports below. Nothing here is unsourced.
- Anthropic disrupted a Russian state-sponsored hacking group that used its Claude AI to build and run an automated malware operation.
- The group, tracked as GTG-20006 and linked to Midnight Blizzard, set up AI agents that automatically rebuilt their malware whenever security tools detected it.
- The campaign targeted over 20 organizations, including government ministries, defense and intelligence bodies, embassies, and think tanks mainly in Ukraine and Europe.
- The attackers also hacked hotel guest Wi-Fi networks, stole browser passwords, hijacked WhatsApp accounts, and accessed victims' live camera streams, alongside a credential theft campaign that exposed over 300,000 national identity records in a North African country.
- The case shows AI is shifting the cost of cyberattacks onto defenders, since automated rebuilding of malware can outpace traditional detection methods.
What to watch next
What changed2
Every report on this story, newest first. Times are when each outlet published.
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Anthropic
2 quotes · 1 outlet
“The actor also used AI to monitor how well their tools evaded detections from known security defenses”
In the article
…credential stealing tool that targets browser password stores - A phishing platform designed to mimic priority targets like government organizations, and - An administrative console used to manage compromised accounts " The actor also used AI to monitor how well their tools evaded detections from known security defenses ," Anthropic explained. "If their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding…
“The actor compromised at least three hospitality vendors that operate hotel guest Wi-Fi”
In the article
…government agencies in Asia. These efforts also overlapped with a campaign dubbed CaptiveCrunch that was documented in July and August 2026 by ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs. " The actor compromised at least three hospitality vendors that operate hotel guest Wi-Fi ," Anthropic said. "They used compromised admin credentials to modify DNS records so that they pointed to services owned by the actor (a technique known as DNS hijacking). Guests of hotels using the compromised vendors…
Why it matters3
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Russian state-sponsored actors operational disruption· immediate
- WordPress infrastructure vulnerability exploitation· immediate
- Enterprise networks dns monitoring required· days
Coverage1
All filed from IndiaSingle origin
Named Russia · Ukraine · United States · Awami League · Claude · ShinyHunters · Anthropic · BBS Bilisim Teknolojileri · Google · GTG-20006 · LKM Company · Lumen Black Lotus Labs · Microsoft · Midnight Blizzard
The 2 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.

