Anthropic said it disrupted an AI-enabled cyberespionage campaign, tracked as GTG-20006 and assessed as consistent with Russian state-linked Midnight Blizzard, that operated from December 2025 through August 2026. The operators allegedly used Claude agents to automate reconnaissance, phishing, exploitation, lateral movement, data theft, and an iterative malware-evasion loop: testing tools against security products, modifying and rebuilding detected code, then redeploying it. More than 20 government, defense, intelligence, diplomatic, think-tank, drone-industry, hospitality, and surveillance targets across Ukraine, Europe, the Middle East, Asia, and North Africa were reportedly targeted; theft included drone-maker mailboxes and a proprietary drone-vision SDK. Reported activity also included DNS hijacking via hotel Wi-Fi vendors and WhatsApp-account takeovers.
Anthropic said other disrupted abuse included ShinyHunters-associated credential harvesting and Android-package analysis, a SaaS supply-chain intrusion affecting more than 200 downstream organizations, suspected Chinese-linked exploit research, and politically motivated theft and doxxing. The company warned that AI API keys, session tokens, and AI-integrated services are increasingly valuable targets because stolen access can be resold, provide victim-funded compute, and obscure attacker attribution. Anthropic banned involved accounts, strengthened misuse controls, and shared relevant indicators with law enforcement and industry partners.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
Microsoft documented the CaptiveCrunch technique, linking Midnight Blizzard to compromising hotel guest-Wi-Fi providers, hijacking DNS records, and delivering malware through ClickFix-style lures.
Anthropic tracked GTG-20006, assessed as consistent with the Russian state-nexus group Midnight Blizzard, conducting an AI-enabled espionage campaign from December 2025. The campaign targeted Ukrainian, European, Middle Eastern, Asian, and North African government, defense, diplomatic, and related entities.
GTG-20006 developed a cloud-email espionage platform using the Embassy Kit device-code phishing framework to steal Microsoft 365 tokens from diplomatic and government personnel. The campaign gained unauthorized access to and exfiltrated email records from at least eight organizations, including a national prosecutor’s office, military education institute, and regional intergovernmental organization.
Anthropic said it identified and disrupted the reported malicious Claude activity, banned implicated accounts, strengthened abuse safeguards, and shared relevant intelligence and indicators with authorities, law enforcement, and industry partners.
GTG-50020 used prompt injection against an AI vendor's automated evaluation sandbox to obtain customer production API keys from multiple providers. The group used the keys in further attacks and unsuccessfully pursued access to a pre-release Claude model through more than a dozen avenues.
Anthropic identified GTG-10007 as a sustained Chinese-speaking espionage operation using autonomous AI workflows for reconnaissance, vulnerability research, exploit development, malware development, and intrusion attempts. The group targeted roughly 50 organizations and compromised an education-technology company, a retailer, and a Southeast Asian government agency.
Anthropic reported that the alleged ShinyHunters-linked operator known as "frkoo" operated policenationale[.]cc, a fraudulent carding shop impersonating the French national police. The site sold stolen payment-card records, cardholder information, and a map of victim addresses.
GTG-50014 used harvested credentials and stolen GitHub personal access tokens in confirmed breaches, including a technology-provider compromise that exfiltrated more than one terabyte of data. A reported SaaS supply-chain intrusion used an XSS flaw and AI-assisted token conversion to reach more than 200 downstream organizations in about 34 hours.
Anthropic disrupted GTG-50014, a cluster suspected to include ShinyHunters affiliates. A French-speaking operator ran a credential-harvesting pipeline across ten AWS EC2 workers that downloaded and decompiled approximately 1.8 million Android APKs to locate hardcoded secrets.
GTG-20006 breached a North African government technology authority, stealing more than 300,000 national identity records and commercial-registry information for more than half a million companies.
GTG-20006 used headless-browser companion-device linking to take over WhatsApp accounts and export conversations while suppressing read receipts. At least two former high-level Ukrainian officials were targeted.
GTG-20006 bulk-exported mailboxes from at least two drone-component manufacturers and stole a proprietary drone-vision-system software development kit. The actor spent several days reverse-engineering the system architecture, hardware bill of materials, and supplier dependencies.
GTG-20006 compromised at least three hospitality vendors operating hotel guest Wi-Fi services and used administrator credentials to alter DNS records. The redirection sent guests to actor-controlled services that delivered Windows, Android, and iOS malware lures.
GTG-20006 used Claude-driven agents to test malware against security products, automatically modify and rebuild detected Windows and mobile implants, and redeploy them until they evaded detection.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 125 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcethehackernews.com
Open sourcesecurityweek.com
Open sourcecryptika.com
Open sourceanthropic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.