Anthropic: GTG-20006 (Midnight Blizzard-aligned) used Claude to auto-evade malware detections
Anthropic’s September 2026 Threat Intelligence report (activity disrupted December 2025–August 2026) details case study GTG-20006, which Anthropic assesses as consistent with public reporting on Russian state-nexus Midnight Blizzard. Operators used Claude-driven workflows to develop, stage, and operate tooling; when monitoring agents saw malware flagged by security products, other agents autonomously modified and rebuilt it until detections were evaded, then staged the toolkit from disposable hosts. Anthropic says more than 20 organisations were in the actor’s planning/recon/live ops set (Ukrainian and European government, defence, diplomatic, think-tank and defence-industrial targets, with some Middle East and Asia reach). Observed theft includes mailboxes from at least two drone-component manufacturers and a full proprietary drone-vision SDK (architecture, BOM, suppliers). Separately the actor compromised at least three hospitality vendors’ hotel guest Wi-Fi admin paths, DNS-hijacked guest traffic (Microsoft CaptiveCrunch), and used headless-browser WhatsApp companion linking to export conversations. Anthropic disrupted the misuse and shared intelligence with partners. Primary: Anthropic TI report; wire: SecurityWeek (11 Sep 2026).
- Product
- Anthropic Claude (Haiku / Sonnet / Opus; misuse of production models)
- Versions
- n/a (account misuse / agentic workflows; not a product CVE)
- Exploited in Australia?
- unknown
- Patch to
- Defenders: do not rely on static signatures alone; hunt CaptiveCrunch/hotel Wi-Fi DNS hijack and AI-accelerated rebuild cycles. Anthropic customers: review unexpected agent/tool use
Primary: Anthropic — Detecting and countering misuse of AI (Sep 2026 TI) · Vendor: Anthropic Threat Intelligence · SecurityWeek (11 Sep 2026)
