ANTHROPIC has revealed that a Russian state-sponsored threat group, dubbed GTG-20006 (Generative Threat Group 20006), used an AI-assisted workflow to automatically rebuild and redeploy their malware after detection. The group’s aim was to stay ahead of static detection methods by employing Claude for an AI-driven process that monitors how their tools evade security products and then autonomously modifies and rebuilds them to defeat those detections.
The operation is linked—through broader reporting—to the Midnight Blizzard cluster (also known as APT29/Cozy Bear) and targeted foreign intelligence–related entities, with victims including Ukrainian and European military intelligence, government ministries, defence and diplomatic bodies, think tanks, and defence-industrial firms.
The attackers’ toolkit reportedly comprises two Windows implants, a mobile exploitation kit, a browser credential-stealer, a phishing platform, and an administrative console for compromised accounts.
Anthropic notes that GTG-20006 staged artefacts on disposable hosting servers once they could bypass detection, redirecting victims via phishing, ClickFix-like campaigns, and DNS hijacking. The group allegedly used AI to register domains, set up hosting infrastructure to send phishing emails, and to monitor C2 channels.
The operation extended to more than 20 organisations, including hotel chains where compromised admin credentials were used to alter DNS records to point to the attackers’ services, enabling traffic and data exfiltration from guests’ devices. The actors also pursued Windows, Android, and iOS malware delivery, used data from hotel systems to identify additional targets such as Ukrainian government figures and drone manufacturers, and attempted to take over WhatsApp accounts and access surveillance platforms.
The report notes pervasive AI use at every stage, arguing that such automation has shifted costs back onto defenders by raising attackers’ operational tempo.