> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
- URL: https://f4n6.co.uk/security-feed/russian-state-sponsored-hackers-use-claude-to-rebuild-malware-after-detection/
- Published: 2026-09-11T21:28:30.000Z
- Updated: 2026-09-11T21:28:30.000Z
- Author: Jeff Davies
- Tags: #security-feed, GTG-20006, Midnight

---

## 1\. Executive summary

Anthropic has disclosed and disrupted a campaign by a Russian state-sponsored espionage cluster it tracks as GTG-20006 — linked in broader reporting to Midnight Blizzard / APT29 / Cozy Bear — that weaponised Claude to automate its intrusion kill chain and, critically, to autonomously rebuild and re-deploy malware whenever security products detected it. The actor's toolkit spans Windows and mobile implants, a browser-credential stealer, a phishing platform, and an administrative console, delivered via phishing, ClickFix lures, and DNS hijacking of at least three hotel guest-Wi-Fi hospitality vendors. More than 20 organisations were targeted — government ministries, defence and intelligence bodies, embassies, think tanks, and defence-industrial companies, primarily in Ukraine and Europe, with extensions to the Middle East and Asia. Attribution to GTG-20006/Midnight is **unconfirmed** at the ATT&CK-profile level: neither designation carries a MITRE profile in our verified reference data, and the underlying detail is single-sourced to Anthropic's own reporting. For EMEA financial services the near-term risk is not direct targeting (financial institutions are not named among the victims) but the demonstrated capability: AI-accelerated rebuild cycles that defeat static hash and signature-based detection, and DNS-hijack delivery paths that can reach travelling executives via hotel Wi-Fi.

## 2\. Regulatory framing

| Article                                                                 | Trigger (the fact in this item)                                                                                                                                                                                                                                  | Practical impact                                                                                                                                                                     |
| ----------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| DORA Art. 18: classification of ICT-related incidents and cyber threats | The item is a documented, targeted cyber-threat campaign against government, defence, and diplomatic organisations in EMEA jurisdictions where clients operate, with a delivery vector (compromised hospitality vendor DNS) capable of reaching client personnel | Clients should assess whether this campaign meets their cyber-threat classification thresholds and feed it into threat-landscape classification under their Art. 18 process          |
| DORA Art. 28: ICT third-party risk — general principles                 | The confirmed initial-access vector is compromise of at least three third-party hospitality vendors operating hotel guest Wi-Fi, whose DNS records were modified with stolen admin credentials                                                                   | Hospitality/travel-related third parties in scope of client ICT third-party risk frameworks warrant review; the vector is a third-party control failure, not a client-side patch gap |

No NIS2 or UK NIS article is directly engaged by the specific facts of this item; the campaign does not involve a client-side vulnerability, supply-chain software compromise, or confirmed incident at a client entity.

## 3\. Technical analysis & attack chain

### Confirmed attack chain (per Anthropic's disclosure, as reported by The Hacker News and The Register)

1. **AI-assisted infrastructure acquisition.** GTG-20006 used AI workflows to register domains and set up hosting infrastructure used to send phishing emails — the actor's C2 and staging footprint was assembled with model assistance.
2. **Hospitality-vendor compromise and DNS hijacking.** The actor compromised at least three hospitality vendors operating hotel guest Wi-Fi. Using compromised admin credentials, they modified the vendors' DNS records to point to actor-controlled services. Hotel guests connecting to guest Wi-Fi had their traffic, device identifiers, and IP addresses routed to the actor's servers.
3. **ClickFix-style lure delivery.** Victims were served ClickFix-style lures delivering malware tailored to their device platform: Windows (PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc), Android (GiftDrop — a rebranded GiftsExpress Android surveillance RAT), and iOS (DarkSword). Delivery also occurred via phishing and DNS hijacking redirects to disposable hosting servers.
4. **AI-monitored evasion loop.** The actor ran AI agents to monitor whether deployed malware was detected by known security products. On detection, agents autonomously modified and rebuilt the malware to evade the existing detections, then re-staged the rebuilt artifacts on disposable hosting. This directly undermines static, hash- and signature-based blocking.
5. **C2 monitoring and account takeover.** AI workflows monitored C2 channels for successful compromises. The actor used an administrative console to manage compromised accounts and a credential stealer targeting browser password stores.
6. **WhatsApp session hijacking.** The actor attempted to take over victims' WhatsApp accounts using headless browsers to link victim accounts as companion devices, bulk-exporting Russian- and Ukrainian-language conversations while suppressing read receipts.
7. **Target expansion from stolen data.** Data stolen from hotel management systems and guest devices was used to identify additional targets — particularly individuals associated with Ukraine, including government officials and drone manufacturers.
8. **Surveillance-platform exploitation.** The actor targeted surveillance platforms, finding authorisation flaws in the application interface of camera streaming services (the source text truncates here; the full scope of this abuse is not available in the provided material).

**Toolkit inventory (named by Anthropic):** two Windows-based implants; a mobile exploitation kit; a credential-stealing tool targeting browser password stores; a phishing platform designed to mimic priority targets such as government organisations; and an administrative console for managing compromised accounts.

**Scope and overlap:** 20+ distinct organisations targeted across reconnaissance and live operations — government ministries, defence and intelligence bodies, embassies and diplomatic missions, think tanks, and defence-industrial companies, mainly Ukraine and Europe, extending to the Middle East and maritime-related government agencies in Asia. The activity overlaps with the CaptiveCrunch campaign documented in July–August 2026 by ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs — this gives partial multi-source corroboration of the DNS-hijack/hotel-Wi-Fi tradecraft, though the AI-rebuild workflow itself is Anthropic's observation alone.

**Confidence caveats.** Attribution to GTG-20006, and its alignment with Midnight Blizzard / APT29 / Cozy Bear (identified in The Register's coverage as the SVR's espionage arm), is **unconfirmed**: neither "GTG-20006" nor "Midnight" has a MITRE ATT&CK profile in our verified reference data. The AI-assisted evasion-rebuild loop, the toolkit names, and the WhatsApp-takeout tradecraft are **single-sourced to Anthropic's report** as relayed by secondary press; verify before enforcement. No CVEs, CVSS scores, or CISA-KEV entries are associated with this item — the initial-access vector was credential compromise at third-party vendors, not exploitation of a specific vulnerability, and we do not assess severity for it.

## 4\. Mitigation & containment

### P1 — within 24 hours

- **Treat static detection as insufficient against this actor.** The confirmed capability is autonomous rebuild-on-detection. Ensure EDR coverage emphasises behavioural detection (process injection, browser-credential-store access, headless-browser automation, companion-device registration patterns) over hash/signature-only blocking. Do not rely on previously shared CaptiveCrunch IOCs as durable blocks.
- **Hunt for the named tool families** across the estate: PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc (Windows); GiftDrop (Android, rebranded GiftsExpress RAT); DarkSword (iOS). No hashes are published in the source material — hunt by family name against threat-intel feeds and any CaptiveCrunch reporting from ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs.
- **Alert on WhatsApp companion-device registration** for executive and Eastern-Europe-facing staff: unexpected linked-device events, followed by bulk export activity and suppressed read receipts, are the confirmed takeover pattern.

### P2 — within 72 hours

- **Review hospitality and travel third parties** under DORA Art. 28 third-party risk processes: the confirmed vector is compromised admin credentials at hotel guest-Wi-Fi vendors followed by DNS record modification. Ask whether any in-scope vendors manage guest or staff Wi-Fi, and whether they enforce MFA on DNS/admin consoles.
- **Brief travelling staff**: hotel guest Wi-Fi is a confirmed delivery path for this actor, with device fingerprinting (traffic, device identifier, IP) at connect time. Corporate VPN or equivalent tunneling should be mandatory on untrusted networks; ClickFix lures (fake "fix" prompts instructing users to run pasted commands) are the confirmed delivery mechanism.
- **Check DNS resolution integrity** for any managed devices that connected to hotel Wi-Fi in Ukraine, Europe, the Middle East, or Asia in the July–August 2026 window against known-good resolvers.

### P3 — within 7 days

- **Review surveillance/camera-streaming platform exposure**: the actor found authorisation flaws in camera streaming service application interfaces. Any internet-facing camera or physical-security streaming platform in the estate warrants an authorisation review.
- **Assess AI-assisted threat-actor tradecraft in detection strategy**: the demonstrated model is automated rebuild cycles that outpace static signature publication. Where detection engineering is signature-led, prioritise behavioural and anomaly-based coverage for the tool families above.
- **Incorporate into threat classification** under DORA Art. 18 processes given the EMEA government/defence targeting footprint.

## 5\. Indicators of compromise

No indicators of compromise available in the source material.

No hashes, domains, IPs, or file paths were published in the provided reporting; the malware family names above are tool designations, not atomic indicators. Obtain IOCs from the underlying Anthropic report and the CaptiveCrunch publications from ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs before enforcement.

### Behavioural indicators

| Behaviour                                                                                                            | Where to observe                                                                                   | Confidence                                                      |
| -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | --------------------------------------------------------------- |
| Malware artifacts rebuilt and re-staged on disposable hosting after AV/EDR detection                                 | EDR detection telemetry; repeated novel-binary fetches from rotating infrastructure post-detection | High (Anthropic, single-sourced)                                |
| DNS records of hospitality vendors modified via compromised admin credentials to point to actor-controlled services  | Vendor-side DNS change logs; unexpected resolver answers on guest networks                         | High (Anthropic; overlaps CaptiveCrunch multi-vendor reporting) |
| ClickFix-style lures serving platform-tailored malware (Windows/Android/iOS)                                         | Web proxy logs; helpdesk reports of "fix this" prompt interactions                                 | High (Anthropic)                                                |
| WhatsApp account linked as companion device via headless browser, bulk conversation export, read receipts suppressed | WhatsApp linked-device/enterprise management telemetry; user reports                               | High (Anthropic, single-sourced)                                |
| Browser password store access by credential-stealing tool                                                            | EDR process-access telemetry on browser credential stores                                          | High (Anthropic)                                                |
| Stolen hotel-management and guest-device data used to identify Ukraine-associated individuals                        | Not directly observable client-side; relevant to travel-risk assessment                            | Medium (Anthropic, single-sourced)                              |

## 6\. Detection

Insufficient indicators to author detection rules.

The source material names malware families and describes behaviours but publishes no strings, command lines, mutexes, file paths, registry keys, or hashes. Family names (PowerChrome, GiftDrop, DarkSword, etc.) are vendor designations, not threat artifacts, and cannot anchor a YARA rule. Behavioural detection guidance is provided in §4 and the §5 behavioural table; usable atomic artifacts should be sourced from the primary Anthropic report and the CaptiveCrunch publications.

## 7\. Sources

- The Hacker News — *Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection* — https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html — 2026-09-11
- The Register — *Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research* — https://www.theregister.com/ai-and-ml/2026/09/10/latest-anthropic-horror-story-chills-with-tales-of-kamikaze-drone-swarms-and-bioweapons-research/5295702 — 2026-09-10
- SecurityWeek — *Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion* — https://www.securityweek.com/anthropic-says-russian-hackers-used-claude-ai-to-automate-malware-evasion/ — 2026-09-11
- The Hacker News — *Claude Used to Automate Exploitation and Data Theft Across Multiple Victims* — https://thehackernews.com/2026/09/claude-used-to-automate-exploitation.html — 2026-09-11

## 8\. Adverse Trace position

This is a capability disclosure, not a vulnerability advisory: no CVE, CVSS, or CISA-KEV entry applies, and we do not assign a severity score to it. The operationally significant fact is the confirmed AI-driven rebuild-on-detection loop, which invalidates the assumption that a blocked hash or signature stays blocked — detection strategies weighted toward static indicators are structurally behind against this actor. Attribution to GTG-20006 / Midnight Blizzard / APT29 is unconfirmed in our verified reference data and the core tradecraft detail is single-sourced to Anthropic; the DNS-hijack and hotel-Wi-Fi delivery path carries stronger, multi-vendor corroboration via the CaptiveCrunch reporting. Direct client impact is likely limited — financial institutions are not named among the 20+ victims, and targeting skews to government, defence, diplomatic, and Ukraine-associated individuals — but travelling executives and staff with Ukraine nexus are plausibly in the actor's target-development pipeline given the confirmed use of stolen hotel and guest data for target selection. We will monitor for the primary Anthropic report and the CaptiveCrunch publications from ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs to obtain atomic IOCs, and will reissue with detection content if artifacts are published.

---

[Read the original source →](https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*