ANTHROPIC has disclosed details of a cyber-espionage operation aligned with the Russian state-nexus group Midnight Blizzard. The attackers reportedly used Claude to monitor how effectively their malware evaded detection, automatically regenerating and redeploying it when security tools flagged it, until it went undetected.
The activity, identified by Anthropic and shut down between December 2025 and August 2026, targeted more than 20 organisations across Ukrainian and European government ministries, defence and intelligence bodies, embassies and think tanks, with additional activity in the Middle East and Asia. Among the seized material, the group exfiltrated mailboxes from two drone-component manufacturers and stole a complete proprietary software development kit for a drone-vision system.
They also compromised at least three hospitality vendors operating hotel guest Wi‑Fi, using stolen admin credentials to redirect guest traffic via DNS hijacking, a method Microsoft has associated with Midnight Blizzard as CaptiveCrunch.
Anthropic’s report also highlights a broader trend: threat actors are increasingly aiming at AI credentials and infrastructure, not just using AI as a tool. In one case, GTG-50021 ran a fraudulent Claude reseller service that proxied paying customers to another model while harvesting Anthropic account credentials for resale.
In a separate instance, GTG-50020, a Russian-speaking group with a history in hotel-booking and fintech breaches, allegedly used prompt injection against an AI vendor’s evaluation sandbox to obtain production API keys for multiple providers. Although the attackers pursued access to a pre-release Claude model, Anthropic says none of the attempts succeeded.
The firm notes that stolen AI credentials can be resold or used to obtain free compute, and urges organisations to treat AI API keys with the same scrutiny as production credentials. The material forms part of a broader threat intelligence report published by Anthropic.