Midnight Blizzard Used Claude to Automate Malware Evasion. Anthropic Just Published the Details.
Anthropic has released a threat intelligence report detailing how it identified and shut down a cyberespionage campaign it attributes to Midnight Blizzard, the Russian state-linked group previously connected to the SolarWinds breach and attacks on Microsoft's own corporate email. The activity ran between December 2025 and August 2026.
The most technically significant finding is how the group used Claude to close the detection-evasion loop. When security tools flagged their malware, AI agents automatically modified and rebuilt it until it slipped through undetected again. Historically, new signatures forced attackers into slow, manual rewrites. That friction is now essentially gone. Anthropic is fairly direct about what this means: defenders are absorbing costs that previously fell on attackers.
The targeting list is what you'd expect from a group with Kremlin priorities. More than 20 organisations were hit, including Ukrainian and European government ministries, defence and intelligence bodies, embassies, and think tanks. Operations also extended to the Middle East and Asia.
Two drone component manufacturers had their mailboxes exfiltrated. One victim lost a complete proprietary software development kit for a drone vision system, and the attackers spent several days picking apart its architecture, hardware components, and supplier chain. Given the conflict in Ukraine, that's not a surprising priority.
The group also went after hotel Wi-Fi infrastructure. At least three hospitality vendors had their admin credentials stolen, which were then used to hijack DNS and redirect guest traffic. Microsoft documented this same technique separately in July, calling it CaptiveCrunch. Both companies link it to Midnight Blizzard.
Another strand involved WhatsApp account takeovers. The attackers linked victims' accounts as companion devices using headless browsers, suppressing read receipts while silently exporting conversations. At least two former senior Ukrainian officials were targeted this way.
AI infrastructure is now a target, not just a tool
The espionage findings are alarming enough. But Anthropic's report also covers a quieter, growing trend: attackers going after AI credentials and infrastructure directly.
One group ran a fraudulent Claude reseller service. Customers paid, got proxied to a different model without realising it, and had their Anthropic credentials harvested in the background for resale. Straightforward fraud, moderately sophisticated execution.
More interesting is the group Anthropic tracks as GTG-50020, a financially motivated Russian-speaking crew with a prior history of hitting hotel-booking and fintech platforms. This group used prompt injection against an AI vendor's automated evaluation sandbox and walked away with production API keys belonging to multiple providers.
They then ran a multi-day campaign targeting roughly 30 AI companies, with one explicit goal: get hold of a pre-release Claude model. More than a dozen approaches were attempted. None worked.
The incentives here are worth spelling out. Stolen AI credentials have resale value, provide free compute for the attacker's own operations, and offer cover, since any resulting activity gets attributed to whoever legitimately owns the keys. Anthropic's advice is blunt: treat AI API keys and agent integrations the same way you'd treat production database credentials. Which, frankly, most organisations currently do not.
The Midnight Blizzard findings sit within a broader report covering seven categories of misuse Anthropic says it has disrupted, including influence operations, surveillance tools, and both biological and conventional weapons research. The company notes this connects to separate Frontier Red Team work on AI capabilities for weapons development and intelligence targeting.
The full picture is not particularly reassuring. Nation-state actors are iterating on AI-assisted tradecraft faster than most defenders are adapting, and the infrastructure underpinning AI services is itself becoming a target worth compromising.