Anthropic Disrupts Russian Hackers' AI Malware Workflow — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic disclosed it disrupted GTG-20006 — a cluster linked to APT29 (Midnight Blizzard/Cozy Bear) — which built an AI-assisted workflow that detects when its malware is flagged by security products, then autonomously rewrites and redeploys it.
- GTG-20006 targeted more than 20 organizations across government ministries, defense and intelligence bodies, embassies, think tanks, and defense-industrial firms — primarily in Ukraine and Europe, with additional hits in the Middle East and maritime-related agencies in Asia.
- The threat actor's toolkit included two Windows implants (PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc), an Android surveillance RAT called GiftDrop, an iOS implant dubbed DarkSword, a credential stealer for browser password stores, and a phishing platform with an administrative console.
- GTG-20006 compromised at least three hotel guest-WiFi vendors via DNS hijacking, redirecting travelers' traffic through actor-controlled servers and serving device-tailored ClickFix lures — then used stolen hotel data to identify further targets tied to Ukraine, including government officials and drone manufacturers.
- The campaign also exfiltrated over 300,000 national identity records and commercial registry data for 500,000+ companies from a North African government technology authority, and stole Microsoft 365 mail from at least eight organizations — including a national prosecutor's office and a military education institute — using a device-code phishing framework called Embassy Kit.
- Anthropic said the actor 'used AI at every point in their operations' — from registering domains and sending phishing emails to monitoring stealth and persistence on victim machines — arguing this 'has inverted the cost back onto defenders' since static detections can no longer slow attacker tempo.
Why it matters: Anthropic says AI has 'inverted the cost back onto defenders': GTG-20006 used Claude to autonomously rebuild malware whenever security tools flagged it, hitting 20+ government and defense organizations. With AI embedded across phishing delivery, infrastructure setup, credential theft, and C2 monitoring, static detections no longer slow attacker tempo — defenders must now match AI-driven adaptation speed or lose ground.
Ask SkimNews



