What Actually Happened
In September 2026, Anthropic published a threat intelligence report describing how several threat actors had abused Claude between December 2025 and August 2026. The most consequential case involves Midnight Blizzard, the Russia-linked espionage group also tracked as APT29 — the same actor associated with the SolarWinds supply-chain compromise and the 2024 breach of Microsoft's corporate email.
Using AI to draft phishing emails or explain code is old news. What makes this case different is where the AI sat in the operation. Midnight Blizzard put Claude-driven agents in charge of the part of an intrusion that has always been slow, manual and expensive: staying undetected after defenders catch up.
Anthropic identified the activity, banned the accounts involved, strengthened its safeguards, and shared intelligence with authorities and industry partners.
The Evasion Loop: Detect, Rewrite, Rebuild, Redeploy
According to Anthropic, the group used Claude to monitor how well its malware evaded detection by security products. When one of its tools was flagged, AI agents took over:
- Detect — the agents tracked which implants security products were catching.
- Rewrite — the flagged code was modified automatically.
- Rebuild — a new build of the implant was produced, reportedly for both Windows and mobile tooling.
- Redeploy — the fresh build went back into the operation.
Then the cycle repeated, until the malware went undetected again. Anthropic's own framing is the sentence every SOC manager should read twice: AI now lets capable actors "close the loop" faster than defenders can respond.
Signatures Never Worked Because They Were Perfect. They Worked Because They Were Expensive to Beat.
Signature-based detection has always been a race defenders could not win outright. Its real value was friction. Every new signature forced the attacker into a costly cycle: analyze why the tool was caught, rewrite it, test it against security products, rebuild, redeploy. That took skilled developers and days or weeks of work, and every manual rewrite was a chance to make a mistake that exposed the operator. The attacker paid for each detection in time and people. Midnight Blizzard's agents moved that cost to near zero. When the rewrite cycle takes minutes and needs no human, a new signature is obsolete almost as soon as it ships, and the burden of the race shifts back onto the defender.
Who Was Targeted
The report describes a classic intelligence-gathering campaign with a modern toolchain. More than 20 organizations were targeted, including:
- Ukrainian and European government ministries, defense and intelligence bodies, embassies and think tanks, with further targeting in the Middle East and Asia.
- Two drone component manufacturers, whose mailboxes were exfiltrated and whose proprietary SDK was stolen — a direct window into the supply chain of a technology at the center of the war in Ukraine.
- A North African government authority, from which more than 300,000 national identity records were reportedly taken.
- Three hospitality vendors operating hotel guest Wi-Fi, compromised to support DNS hijacking.
Beyond Malware: Hotel Wi-Fi and WhatsApp
Hotel Guest Wi-Fi as a Delivery Channel
By compromising vendors that run guest Wi-Fi for hotels, the group could tamper with DNS for the people connecting through those networks. Reporting on the Anthropic findings links this to a technique Microsoft documented separately in July 2026 as CaptiveCrunch, in which travelers are steered toward attacker-controlled pages serving ClickFix-style lures that trick them into running malicious commands. For an espionage actor, it is an elegant filter: the victims who show up are diplomats, officials and executives on the move, on networks their IT teams do not control.
Silent WhatsApp Takeovers
The group also took over the WhatsApp accounts of at least two former high-level Ukrainian officials. The method did not rely on breaking encryption. The attackers linked the victims' accounts as companion devices through headless browsers, then suppressed read receipts so they could export conversations without the owners noticing anything unusual.
A Report With More Than One Actor
Midnight Blizzard is the headline, but it is not the only case. Anthropic's report also describes financially motivated crews using AI to scale credential harvesting and SaaS supply-chain pivoting, suspected state-linked operations running parallel agents for exploit research, and actors attempting to steal production API keys through prompt injection. The common thread is the same as in the PaperCut agent swarm documented a week earlier: AI is not inventing new attacks, it is removing the labor that used to limit how many attacks a group could run.
We Know About This One Because It Ran on a Platform That Was Watching
This operation was caught because Midnight Blizzard built it on a commercial AI service with abuse monitoring, account controls and a threat intelligence team. That is also its biggest limitation as a warning. The same evasion loop can run on open-weight models hosted on the attacker's own hardware, where no provider sees the prompts, bans the account or publishes a report. Disclosures like this one are the visible fraction of a trend, not its full size. Defenders should read them as a preview of techniques that will increasingly run where nobody is looking.
What Defenders Should Do Now
1. Shift Weight From Signatures to Behavior
An implant that changes its code on every detection will keep beating static signatures. It will not easily change what it does: spawning unusual process chains, touching credentials, beaconing out, reading mailboxes. Invest in EDR telemetry, behavioral rules and anomaly detection on outbound traffic, and measure your detection coverage by technique rather than by file hash.
2. Treat Hotel and Guest Wi-Fi as Hostile
Enforce an always-on VPN and encrypted DNS on every device that travels, especially for executives, diplomats and anyone handling sensitive projects. Train travelers that a captive portal asking them to paste or run a command is an attack, not a login step, and restrict script execution for non-administrative users where possible.
3. Audit WhatsApp and Messaging Linked Devices
Ask high-risk staff to review the linked devices on WhatsApp and similar messaging apps and remove anything they do not recognize. Make that check part of travel briefings and incident response for senior people, because a silently linked session leaves almost nothing for the victim to notice.
4. Protect the Defense and Drone Supply Chain
Suppliers are often softer than the ministries they serve. If you build components, software or SDKs for defense customers, monitor mailbox access and audit logs closely, protect source code and SDK repositories like crown jewels, and assume you are a target in your own right.
5. Lock Down AI Credentials and Usage
Inventory the AI API keys used across your organization, keep them out of code and prompts, rotate them, and alert on unusual usage. Agents and AI integrations that read untrusted content should never hold keys they can be talked into revealing.
6. Consume and Share Threat Intelligence Faster
When the attacker's rebuild cycle is measured in minutes, a quarterly intelligence review is a formality. Subscribe to vendor and government feeds, ingest indicators automatically, and share what you see with your ISAC. Collective visibility is one of the few advantages defenders can scale as quickly as attackers now scale their tooling.
The lesson is not that antivirus is dead. Signatures still stop the long tail of commodity threats. The lesson is that against capable, AI-assisted actors, signatures are no longer a strategy on their own. Detection that looks at behavior, identity and context is what still holds when the malware itself keeps changing shape.
Frequently Asked Questions
My Take
For decades, the uncomfortable truth about signature-based detection was hidden by a comfortable one: it did not need to be perfect, because it made attackers pay. Every detection cost them developer time, testing and risk. That cost was a defensive layer nobody put on an architecture diagram, and it is the layer this report shows disappearing.
I also do not want to overstate it. Anthropic caught this operation, shut it down and published the details, which is exactly what should happen when a state actor tries to build on a commercial AI platform. Credit where it is due.
But I keep coming back to the visibility problem. This is the version we know about because it ran somewhere that was watching. The next iteration of the same loop will run on open-weight models on infrastructure no provider can see or switch off, and nobody will write a report about it until the implants are found in the wild.
Attackers have automated their feedback loop. In too many organizations, the defender's side of that loop is still a human waiting for a ticket to reach the top of a queue. That asymmetry, not any single piece of malware, is the real threat.
Is your detection strategy built to outpace malware that rewrites itself every time you catch it?
Related Articles:
- One Attacker, Hundreds of AI Agents: How a Swarm Breached 395 Organizations Through PaperCut
- OpenAI Rated Its Own Model "Critical" for Cyber. Google and Anthropic Moved the Same Week.
- One Line in a Repository Runs Attacker Code Inside Seven AI Coding Agents
- Project Glasswing: Anthropic's AI Finds Over 10,000 Security Flaws in One Month
- AI in Cybersecurity 2026: Weapon or Shield?