Russian Cyber Espionage Group Uses Claude To Evade Malware Detection

Russian Cyber Espionage Group Uses Claude To Evade Malware Detection

Anthropic has disclosed that it disrupted a cyber campaign carried out by a Russian state sponsored threat actor that allegedly used its Claude artificial intelligence platform to automate and enhance cyber espionage operations. The company attributed the activity to a cluster it tracks as GTG 20006, with GTG referring to Generative Threat Group. Anthropic said the activity aligns with broader industry reporting associated with Midnight Blizzard, also known as APT29 and Cozy Bear. According to the company, the threat actor developed an AI assisted workflow capable of automatically rebuilding and redeploying malware whenever security products detected it. This process enabled the group to rapidly modify malicious software, making static detection methods less effective while maintaining the pace of its operations. Anthropic stated that the campaign primarily targeted military intelligence organizations in Ukraine and Europe, along with diplomatic missions, defense institutions, and individuals connected to United States foreign policy.

According to Anthropic, the threat actor relied on artificial intelligence throughout the attack lifecycle, extending beyond malware development into infrastructure management and operational monitoring. The toolkit reportedly included Windows based implants, a mobile exploitation framework, a browser credential stealing utility, phishing infrastructure designed to imitate government organizations, and an administrative console for managing compromised accounts. The company explained that AI agents continuously monitored deployed malware to determine whether it had been identified by security products. Whenever detections occurred, the agents automatically modified the malicious code, rebuilt the software, and prepared updated versions capable of bypassing existing security signatures. Once rebuilt, the malware was reportedly hosted on temporary servers and delivered through phishing campaigns, ClickFix style social engineering techniques, and DNS hijacking operations. Anthropic also stated that AI workflows were used to register domains, establish phishing infrastructure, distribute emails, and monitor command and control channels for successful compromises.

The campaign reportedly involved reconnaissance and operational activity targeting more than 20 organizations, including government ministries, intelligence agencies, embassies, diplomatic missions, defense contractors, think tanks, and maritime related government agencies across Ukraine, Europe, the Middle East, and parts of Asia. Anthropic said the activity overlapped with the CaptiveCrunch campaign documented earlier this year by ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs. As part of the operation, the threat actor allegedly compromised hospitality vendors responsible for hotel guest Wi Fi services and modified DNS records to redirect network traffic through infrastructure under its control. Hotel guests connecting to affected networks reportedly had traffic, device identifiers, and IP addresses redirected before being presented with ClickFix themed prompts delivering malware tailored to Windows, Android, or iOS devices. Anthropic also said the attackers used information obtained from hotel management systems and compromised devices to identify additional individuals of interest, particularly government officials and drone manufacturers associated with Ukraine. The activity reportedly extended to attempts to gain unauthorized access to WhatsApp accounts through companion device linking and to harvesting conversations while suppressing read notifications. In another phase of the campaign, the group reportedly examined surveillance platforms, identifying authorization weaknesses that allowed access to live camera streams through harvested authentication tokens.

Anthropic further linked GTG 20006 to an intrusion targeting a North African government technology authority, where compromised VPN credentials were reportedly used to access a central account server and extract a credential database containing more than 300,000 national identity records alongside commercial registry information for over half a million companies. The company also described a cloud based email espionage platform that employed a device code phishing framework known as Embassy Kit to target Microsoft 365 accounts belonging to diplomatic and government personnel. According to Anthropic, this operation resulted in unauthorized access to email records from at least eight organizations, including a national prosecutor office, a military education institution, and a regional intergovernmental organization. Additional activity involved fake software update themed lures distributing Windows credential stealing tools and utilities designed to maintain remote access while interfering with security updates. Anthropic concluded that artificial intelligence played a role throughout the campaign by supporting malware development, persistence monitoring, infrastructure management, and operational decision making, illustrating how AI can significantly increase the speed and adaptability of sophisticated cyber espionage activities.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment