Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Threat Intel

Russian spies used AI to rebuild malware after detection

Anthropic says a group linked to APT29 used Claude to automatically rebuild and redeploy its malware whenever security tools caught it.

By · Published · Updated · 4 min read

Russian spies used AI to rebuild malware after detection

A Russian state-sponsored espionage group used Anthropic's Claude to automatically rebuild its malware whenever it was detected, The Hacker News reports.

Who is behind it

Anthropic tracks the group as GTG-20006, which aligns with Midnight Blizzard — also known as APT29 or Cozy Bear, linked to Russian intelligence.

Targets

  • Military intelligence targets in Ukrainian and European governments
  • Diplomatic and defence organizations
  • People connected to US foreign policy

How the AI workflow worked

The group's toolkit included two Windows implants, a mobile exploit kit, a browser password stealer and a phishing platform. AI agents monitored whether security products had detected any deployed malware. If they had, the agents modified and rebuilt the malware to evade those detections, then staged it on disposable servers.

Victims were directed to the malware through phishing, fake CAPTCHA (ClickFix) pages and DNS hijacking.

Why it matters

Security tools often block malware by recognising known files. AI that rewrites malware on demand makes those defences far less effective, so defenders need to watch behaviour, not just signatures.

Sources

Read next