Russian Hackers Used Claude AI to Automate Malware Evasion
Anthropic disrupted Midnight Blizzard operations that leveraged AI agents to continuously modify malware until it evaded security detection.

Russian espionage group automates detection evasion with AI
A Russian state-linked cyberespionage group used Claude AI to create an automated system that continuously modified malware until it evaded security detection, according to a threat intelligence report Anthropic published this week.
The AI company identified and disrupted operations by Midnight Blizzard, a group with ties to Russian intelligence, between December 2025 and August 2026. The hackers deployed AI agents to monitor whether their malware triggered security alerts. When detection occurred, the agents automatically rewrote and rebuilt the tools, then redeployed them in a continuous loop until the malware went undetected.
This approach fundamentally shifts the economics of the cat-and-mouse game between attackers and defenders. Traditionally, when security vendors released new detection signatures, attackers faced a manual, time-consuming process to modify their tools. AI automation now allows sophisticated threat actors to close that loop faster than defenders can respond.
Targeting government and defense infrastructure
Midnight Blizzard targeted more than 20 organizations during the campaign, according to Anthropic. Victims included Ukrainian and European government ministries, defense and intelligence agencies, embassies, and think tanks. The targeting extended beyond Europe to organizations in the Middle East and Asia.
The group exfiltrated complete mailboxes from two drone component manufacturers and stole a proprietary software development kit for a drone vision system. The attackers spent several days reverse-engineering the system's architecture, hardware components, and supplier dependencies.
In a separate operation, the group compromised at least three hospitality vendors managing hotel guest Wi-Fi networks. Using stolen administrator credentials, the hackers redirected guest traffic through DNS hijacking. Microsoft documented this delivery method in July under the name CaptiveCrunch and linked it to the same threat actor.
The group also hijacked WhatsApp accounts belonging to at least two former high-level Ukrainian officials by linking them as companion devices through headless browsers while suppressing read receipts to export conversations without alerting the victims.
AI infrastructure becomes a target
Beyond using AI as an offensive tool, threat actors are increasingly targeting AI credentials and infrastructure directly. Anthropic documented one group operating a fraudulent Claude reseller service that secretly proxied customers to a different model while harvesting their Anthropic account credentials for resale.
Another financially motivated Russian-speaking group used prompt injection attacks against an AI vendor's automated evaluation sandbox, tricking it into revealing production API keys belonging to multiple providers. The same actor launched a campaign against roughly 30 AI companies over several days, attempting more than a dozen different methods to gain access to a pre-release Claude model. None of the attempts succeeded.
Stolen AI credentials provide attackers with resale value, free computational resources for their own operations, and cover since the activity appears under the legitimate account holder's identity. Anthropic recommends organizations apply the same security scrutiny to AI API keys and agent integrations as they do to production credentials.
Why it matters
The automation of malware evasion through AI fundamentally changes the speed at which attackers can adapt to defensive measures. What once required manual reverse-engineering and coding expertise can now happen in continuous automated cycles, potentially outpacing the ability of security teams to develop and deploy new detection signatures. This represents a significant escalation in the technical capabilities available to well-resourced state-sponsored threat actors.
Anthropic shared intelligence with authorities and industry partners and used the findings to strengthen its AI safeguards. The company detailed these findings as part of a broader report covering seven categories of AI misuse it has disrupted, including influence operations, surveillance, and weapons development research. SecurityWeek first reported the details of the threat intelligence report.
This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.
Want systems like this working for your business?
Book a Call

