Russian State Hackers Used Claude Agents to Rewrite Their Malware Every Time It Got Caught

Anthropic's latest threat intelligence report shows Midnight Blizzard, the Russia-linked group also tracked as APT29, running AI agents that watched how security products detected its implants, then modified, rebuilt and redeployed them until they went undetected again. More than 20 organizations were targeted. The detection-evasion loop defenders have relied on for decades just became automatic.

What Actually Happened

In September 2026, Anthropic published a threat intelligence report describing how several threat actors had abused Claude between December 2025 and August 2026. The most consequential case involves Midnight Blizzard, the Russia-linked espionage group also tracked as APT29 — the same actor associated with the SolarWinds supply-chain compromise and the 2024 breach of Microsoft's corporate email.

Using AI to draft phishing emails or explain code is old news. What makes this case different is where the AI sat in the operation. Midnight Blizzard put Claude-driven agents in charge of the part of an intrusion that has always been slow, manual and expensive: staying undetected after defenders catch up.

Anthropic identified the activity, banned the accounts involved, strengthened its safeguards, and shared intelligence with authorities and industry partners.

20+ Organizations targeted across government, defense, diplomacy and industry
9 months Activity window, from December 2025 to August 2026
300K+ National identity records reportedly taken from a North African government authority
0 Humans needed in the loop to rewrite an implant after detection

The Evasion Loop: Detect, Rewrite, Rebuild, Redeploy

According to Anthropic, the group used Claude to monitor how well its malware evaded detection by security products. When one of its tools was flagged, AI agents took over:

  1. Detect — the agents tracked which implants security products were catching.
  2. Rewrite — the flagged code was modified automatically.
  3. Rebuild — a new build of the implant was produced, reportedly for both Windows and mobile tooling.
  4. Redeploy — the fresh build went back into the operation.

Then the cycle repeated, until the malware went undetected again. Anthropic's own framing is the sentence every SOC manager should read twice: AI now lets capable actors "close the loop" faster than defenders can respond.

01
The Economics Read

Signatures Never Worked Because They Were Perfect. They Worked Because They Were Expensive to Beat.

Signature-based detection has always been a race defenders could not win outright. Its real value was friction. Every new signature forced the attacker into a costly cycle: analyze why the tool was caught, rewrite it, test it against security products, rebuild, redeploy. That took skilled developers and days or weeks of work, and every manual rewrite was a chance to make a mistake that exposed the operator. The attacker paid for each detection in time and people. Midnight Blizzard's agents moved that cost to near zero. When the rewrite cycle takes minutes and needs no human, a new signature is obsolete almost as soon as it ships, and the burden of the race shifts back onto the defender.

Who Was Targeted

The report describes a classic intelligence-gathering campaign with a modern toolchain. More than 20 organizations were targeted, including:

Beyond Malware: Hotel Wi-Fi and WhatsApp

Hotel Guest Wi-Fi as a Delivery Channel

By compromising vendors that run guest Wi-Fi for hotels, the group could tamper with DNS for the people connecting through those networks. Reporting on the Anthropic findings links this to a technique Microsoft documented separately in July 2026 as CaptiveCrunch, in which travelers are steered toward attacker-controlled pages serving ClickFix-style lures that trick them into running malicious commands. For an espionage actor, it is an elegant filter: the victims who show up are diplomats, officials and executives on the move, on networks their IT teams do not control.

Silent WhatsApp Takeovers

The group also took over the WhatsApp accounts of at least two former high-level Ukrainian officials. The method did not rely on breaking encryption. The attackers linked the victims' accounts as companion devices through headless browsers, then suppressed read receipts so they could export conversations without the owners noticing anything unusual.

None of these techniques is new on its own. DNS hijacking, social-engineering lures and abuse of linked devices have all been documented before. What the report shows is orchestration: an AI layer running phishing infrastructure, malware builds and evasion as one continuous, largely automated workflow.

A Report With More Than One Actor

Midnight Blizzard is the headline, but it is not the only case. Anthropic's report also describes financially motivated crews using AI to scale credential harvesting and SaaS supply-chain pivoting, suspected state-linked operations running parallel agents for exploit research, and actors attempting to steal production API keys through prompt injection. The common thread is the same as in the PaperCut agent swarm documented a week earlier: AI is not inventing new attacks, it is removing the labor that used to limit how many attacks a group could run.

02
The Visibility Read

We Know About This One Because It Ran on a Platform That Was Watching

This operation was caught because Midnight Blizzard built it on a commercial AI service with abuse monitoring, account controls and a threat intelligence team. That is also its biggest limitation as a warning. The same evasion loop can run on open-weight models hosted on the attacker's own hardware, where no provider sees the prompts, bans the account or publishes a report. Disclosures like this one are the visible fraction of a trend, not its full size. Defenders should read them as a preview of techniques that will increasingly run where nobody is looking.

What we do not know yet. Public reporting does not detail exactly how the agents measured detection, which security products were involved, or how many rebuild cycles ran before implants went quiet again. Several figures in this article come from secondary coverage of Anthropic's report, and full indicators of compromise were shared with partners rather than published in full. Check the original report and your threat intelligence feeds before briefing anyone on specifics.

What Defenders Should Do Now

1. Shift Weight From Signatures to Behavior

An implant that changes its code on every detection will keep beating static signatures. It will not easily change what it does: spawning unusual process chains, touching credentials, beaconing out, reading mailboxes. Invest in EDR telemetry, behavioral rules and anomaly detection on outbound traffic, and measure your detection coverage by technique rather than by file hash.

2. Treat Hotel and Guest Wi-Fi as Hostile

Enforce an always-on VPN and encrypted DNS on every device that travels, especially for executives, diplomats and anyone handling sensitive projects. Train travelers that a captive portal asking them to paste or run a command is an attack, not a login step, and restrict script execution for non-administrative users where possible.

3. Audit WhatsApp and Messaging Linked Devices

Ask high-risk staff to review the linked devices on WhatsApp and similar messaging apps and remove anything they do not recognize. Make that check part of travel briefings and incident response for senior people, because a silently linked session leaves almost nothing for the victim to notice.

4. Protect the Defense and Drone Supply Chain

Suppliers are often softer than the ministries they serve. If you build components, software or SDKs for defense customers, monitor mailbox access and audit logs closely, protect source code and SDK repositories like crown jewels, and assume you are a target in your own right.

5. Lock Down AI Credentials and Usage

Inventory the AI API keys used across your organization, keep them out of code and prompts, rotate them, and alert on unusual usage. Agents and AI integrations that read untrusted content should never hold keys they can be talked into revealing.

6. Consume and Share Threat Intelligence Faster

When the attacker's rebuild cycle is measured in minutes, a quarterly intelligence review is a formality. Subscribe to vendor and government feeds, ingest indicators automatically, and share what you see with your ISAC. Collective visibility is one of the few advantages defenders can scale as quickly as attackers now scale their tooling.

The lesson is not that antivirus is dead. Signatures still stop the long tail of commodity threats. The lesson is that against capable, AI-assisted actors, signatures are no longer a strategy on their own. Detection that looks at behavior, identity and context is what still holds when the malware itself keeps changing shape.

Frequently Asked Questions

What did Anthropic reveal about Midnight Blizzard?
In a September 2026 threat intelligence report, Anthropic disclosed that Midnight Blizzard, a Russia-linked espionage group also tracked as APT29, abused Claude between December 2025 and August 2026. The group used AI agents to automatically modify, rebuild and redeploy malware whenever security products detected it, and targeted more than 20 organizations. Anthropic banned the accounts and shared intelligence with authorities and partners.
How did the AI-automated malware evasion work?
Claude was used to monitor how well the group's malware evaded detection. When a tool was flagged, AI agents modified the code, rebuilt it and redeployed it, repeating the cycle until the malware went undetected again. This removed the slow, manual rewriting that detection used to force on attackers.
Who was targeted in the campaign?
Targets included Ukrainian and European government ministries, defense and intelligence bodies, embassies and think tanks, two drone component manufacturers, three hospitality vendors running hotel guest Wi-Fi, and a North African government authority. The group also took over the WhatsApp accounts of at least two former high-level Ukrainian officials.
Does this mean antivirus software no longer works?
No. Signature-based antivirus still blocks a large volume of common threats. But against capable actors who can rewrite their tools automatically, signatures alone are not enough. Organizations should rely on behavioral detection, EDR telemetry, identity monitoring and network anomaly detection that do not depend on recognizing a specific file.
How did the attackers take over WhatsApp accounts?
They linked the victims' WhatsApp accounts as companion devices using headless browsers, then suppressed read receipts so they could export conversations without being noticed. Reviewing and removing unknown linked devices regularly is the most direct defense.
What should organizations do to protect themselves?
Prioritize behavioral detection over signatures, enforce always-on VPN and encrypted DNS for traveling staff, audit messaging-app linked devices for high-risk employees, harden defense and drone supply-chain suppliers, lock down AI API keys, and speed up the consumption and sharing of threat intelligence.

My Take

For decades, the uncomfortable truth about signature-based detection was hidden by a comfortable one: it did not need to be perfect, because it made attackers pay. Every detection cost them developer time, testing and risk. That cost was a defensive layer nobody put on an architecture diagram, and it is the layer this report shows disappearing.

I also do not want to overstate it. Anthropic caught this operation, shut it down and published the details, which is exactly what should happen when a state actor tries to build on a commercial AI platform. Credit where it is due.

But I keep coming back to the visibility problem. This is the version we know about because it ran somewhere that was watching. The next iteration of the same loop will run on open-weight models on infrastructure no provider can see or switch off, and nobody will write a report about it until the implants are found in the wild.

Attackers have automated their feedback loop. In too many organizations, the defender's side of that loop is still a human waiting for a ticket to reach the top of a queue. That asymmetry, not any single piece of malware, is the real threat.

Is your detection strategy built to outpace malware that rewrites itself every time you catch it?

Related Articles:

Kodjo Apedoh

About the Author

Kodjo Apedoh

Network Engineer & AI Entrepreneur

Founder of TechVernia & SankaraShield. Certified Network Security Engineer with 4+ years of experience specializing in network automation (Python), AI tools research, and advanced security implementations. Also builds iOS and Android applications. Holds certifications from Palo Alto Networks, Fortinet, and Cisco. Based in Arlington, Virginia.

Connect on LinkedIn →