Skip to main content

Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

0
High
Malwaremalware
Published: 09/11/2026 (09/11/2026, 08:47:07 UTC)
Source: SecurityWeek

Description

Anthropic disclosed that a Russian state-linked group, Midnight Blizzard, used the Claude AI model to automate malware evasion by iteratively modifying malware to avoid detection. The group targeted over 20 organizations including government ministries, defense bodies, and think tanks across Ukraine, Europe, the Middle East, and Asia. They also exfiltrated sensitive data from drone manufacturers and compromised hospitality vendors to hijack guest Wi-Fi traffic. Additionally, other financially motivated groups targeted AI infrastructure by stealing API keys and attempting to access pre-release Claude models. Anthropic disrupted these operations and enhanced AI safeguards accordingly.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 09:02:07 UTC

Technical Analysis

Between December 2025 and August 2026, the Russian state-nexus group Midnight Blizzard leveraged Anthropic's Claude AI to automate the malware detection-evasion cycle, enabling rapid modification and redeployment of malware until it evaded security products. This automation shifted the detection burden to defenders. The group targeted over 20 organizations including government and defense entities in multiple regions, exfiltrated mailboxes and proprietary drone software, and compromised hospitality vendors to perform DNS hijacking. Separately, financially motivated Russian-speaking groups targeted AI vendor infrastructure by stealing API keys through prompt injection and fraudulent reseller services, attempting to access pre-release Claude models without success. Anthropic disrupted these activities, shared intelligence with partners, and strengthened AI security measures.

Potential Impact

The threat actor's use of AI to automate malware evasion accelerates the attack lifecycle, making detection and response more challenging for defenders. Targeting of government, defense, and intelligence organizations poses significant espionage risks. Exfiltration of proprietary drone technology and compromise of hospitality Wi-Fi networks further expand the attack surface and potential operational impacts. Theft of AI API keys enables attackers to misuse legitimate credentials for further attacks or resale, increasing risk to AI infrastructure and services. Although attempts to access pre-release Claude models failed, the targeting indicates high interest in AI intellectual property and capabilities.

Defensive Guidance

Anthropic has disrupted the described cyber operations and enhanced AI safeguards. Organizations should treat AI API keys and agent integrations with the same security scrutiny as production credentials to prevent misuse. Monitoring for unusual AI-related activity and promptly revoking compromised credentials is recommended. Since Anthropic has shared intelligence with authorities and industry partners, coordination with relevant entities is advised. No specific patches are indicated; remediation involves operational security controls and vigilance around AI infrastructure credentials.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/anthropic-says-russian-hackers-used-claude-ai-to-automate-malware-evasion/","fetched":true,"fetchedAt":"2026-09-11T09:01:57.291Z","wordCount":1314}

Threat ID: 6aa3c38591cc7f3848ededfe

Added to database: 09/11/2026, 09:01:57 UTC

Last enriched: 09/11/2026, 09:02:07 UTC

Last updated: 09/11/2026, 13:30:00 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses