AI Kept Rebuilding This Russia-Linked Malware Until Security Tools Missed It
An espionage operator linked by Anthropic to public reporting about Midnight Blizzard used AI to watch whether security products detected its malware. When a tool was flagged, AI agents modified and rebuilt it, then kept iterating until it was no longer detected.
The finding comes from Anthropic’s September 2026 threat-intelligence report and concerns an actor the company tracks as GTG-20006. Anthropic describes one operator as Russian-speaking and says the tradecraft and targeting are consistent with Russian state-nexus espionage. That is a qualified assessment, not a definitive public attribution to a government service.
The operational change is more important than the label. Defenders have traditionally imposed a cost by detecting a custom implant and distributing a signature for it. GTG-20006 built a feedback loop intended to reduce that cost: detection became the trigger for the next rebuild.
Detection became an input to the attacker
Anthropic says the actor used AI agents to monitor whether deployed malware was being caught by known security defences. If a product detected an implant, the agents began modifying and rebuilding the malware to evade that detection. They were designed to continue until the toolkit was undetected, after which the new tools were staged on disposable hosting servers for live operations.
This does not prove that every rebuilt sample bypassed every security product. “Undetected” describes the outcome observed inside the actor’s own monitoring workflow. Anthropic does not publish a complete list of the products tested, their configurations or the independent detection rate for every variant.
It does show why a clean hash check is becoming less durable. A signature may still stop the sample it was built for, but an automated operator can use that result to produce the next sample while the campaign is still running.
The malware factory was one part of a larger workflow
GTG-20006 did not use AI only as a coding assistant. Anthropic observed customised workflows spanning development, infrastructure acquisition, phishing, persistence, command and control, and data exfiltration.
The actor’s toolkit included two families of Windows implants, a mobile exploitation kit, a credential-stealing tool aimed at browser password stores, a phishing platform built to imitate high-priority targets and an administration console for compromised accounts. AI was used to manage and rework those tools as operations changed.
Anthropic says AI workflows researched and registered phishing domains, configured hosting, sent messages and monitored command-and-control channels for successful compromises. The actor also used device-code phishing against cloud email, ClickFix-style lures and DNS hijacking.
The techniques themselves are familiar. Stolen credentials, deceptive sign-in flows, compromised infrastructure and malicious payloads remain recognisable security problems. AI changed how quickly one operator could prepare, adapt and repeat them.
More than 20 targets does not mean more than 20 breaches
Anthropic identified more than 20 distinct organisations in GTG-20006’s operational planning, reconnaissance and live operations. They included government ministries, defence and intelligence bodies, embassies, diplomatic missions, think tanks and defence-industrial companies, concentrated in Ukraine and Europe with additional targeting in the Middle East and Asia.
That figure is a target count across several stages. It is not a statement that every organisation was compromised. Anthropic separately reports particular successful activity, including bulk mailbox exports from at least two drone-component manufacturers and theft of a proprietary software-development kit for a drone vision system.
The company also attributes to the same actor compromises of hospitality providers used to redirect hotel guest traffic, cloud-email theft affecting at least eight organisations and an intrusion at a North African government technology authority. The report says that last intrusion exposed a database containing more than 300,000 national identity records and commercial-registry data for more than half a million companies.
Those are Anthropic’s investigation findings. The report does not disclose the victims’ identities, provide independent confirmation for every incident or quantify how much AI contributed to each successful compromise.
The operation was automated, but it was not human-free
Anthropic says humans remained involved in the decisions that mattered most. For GTG-20006, a human made individual targeting decisions while AI executed tasks such as running commands, harvesting credentials and exfiltrating data under the operator’s direction.
Some narrower jobs could run without continuous supervision. Anthropic observed scheduled processes renewing stolen access tokens and collecting cloud data. It also says the human operator primarily intervened to modify the Claude Code skills driving the workflows when they needed refinement.
The distinction prevents two opposite mistakes. This was more than a person asking a chatbot for a malicious script, but it was not an independent machine choosing a geopolitical mission and conducting it without human direction.
Static indicators still help, but they expire faster
Anthropic has published indicators with its report. Security teams should use them to hunt, block and add context to historical telemetry. They should not treat the absence of a listed hash or address as proof that an environment was never targeted.
The attacker deliberately used disposable hosting and variant rebuilding. Infrastructure can be replaced and file hashes can change while behaviours remain connected: credential access, suspicious device-code authentication, new device registration, bulk mailbox collection, unusual outbound staging and repeated payload replacement after a security alert.
This case also sharpens the distinction in BlackTree’s earlier analysis of AI malware that mostly remained in research and sandbox collections. GTG-20006 is not being inferred from a public sample count. Anthropic describes a live operational workflow and specific intrusions observed through its investigation.
It is also more automated than the Aurora affiliate whose exposed Cursor conversations showed AI-assisted ransomware work. Both cases retained human direction. GTG-20006 additionally placed detection monitoring and malware rebuilding inside the operating loop.
What defenders should change now
- Use Anthropic’s indicators, but hunt beyond them. Search historical endpoint, identity, email and network telemetry. Build investigations around behaviours and sequences as well as hashes, domains and addresses.
- Detect repeated variant delivery. Alert when one host or campaign path receives several changing executables from related disposable infrastructure, particularly after an earlier payload was quarantined.
- Protect cloud sign-in flows. Restrict device-code authentication where it is not required, monitor unusual device registration and token use, and use phishing-resistant authentication for high-risk users.
- Watch browser credentials and sessions. Reduce the storage of reusable secrets in browsers, harden endpoints used by privileged staff and treat infostealer alerts as identity incidents, not only malware clean-up.
- Monitor remote-access and email reconnaissance. The actor scanned both services across Ukrainian government organisations. Keep internet-facing services current, restrict reachability and alert on unusual enumeration.
- Retain the telemetry needed to connect versions. Longer endpoint and network retention can show that several different hashes share the same execution chain, infrastructure, credential use or command behaviour.
- Test detections against mutation. When validating a rule, vary packaging, filenames and low-level artefacts while preserving the malicious behaviour. A control that works only on one frozen sample may provide a false sense of durability.
- Prepare faster containment decisions. If variant churn is occurring during an incident, isolate the delivery route, revoke compromised identities and block the underlying behaviour instead of waiting for a perfect signature for every new sample.
What remains unknown
Anthropic has not disclosed the actor’s complete identity, the number of operators, a full victim list, total stolen-data volume or a precise timeline for GTG-20006. Its linkage to Midnight Blizzard is explicitly framed as consistent with public reporting, not a definitive attribution.
The company says it disrupted the activity and strengthened its safeguards. That does not establish that every compromised account, implant or external server was eliminated, or that the actor cannot use other models and infrastructure.
The defensible conclusion is narrower and still significant. One espionage operation put AI inside the cycle between malware detection and malware replacement. Security teams do not need to abandon signatures. They do need controls that keep working when the file in front of them is already the next version.
Sources
- Anthropic: Detecting and countering misuse of AI, September 2026, published 10 September 2026, exact time not stated. The report covers disrupted activity observed from December 2025 through August 2026.
- Anthropic’s complete September 2026 threat-intelligence report in PDF.
- Anthropic’s indicator file accompanying the September 2026 report.


