# Anthropic says Russian-linked group used Claude to rebuild malware after detection

_Friday, September 11, 2026 at 10:10 AM EDT · Security, AI · Latest · Tier 2 — Notable_

![Anthropic says Russian-linked group used Claude to rebuild malware after detection — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtfzeoSe_6tXrJiKsyJfN4vYk6suLsJPF3-SOJWE8LAaZ6_WixrsJVjZ0T8O6jdtB1d08IR8swK6H0B4S_m7-0YfIiJlVPHuL7guxwC-4ANLXUyNsEWfIusPzvOMPOKSBmFcBT1NBBVWIglIRlT8fs6O9Uc6ZRBRgWZNPbvgAVIj8gIXfusRwZh0tndhni/s1700-nu-rw-lo-l85-e365/claude-malware.jpg)

Anthropic said Thursday it disrupted a campaign by a Russian state-sponsored threat actor it tracks as GTG-20006, which it links to reporting on Midnight Blizzard (APT29/Cozy Bear).

According to Anthropic, the group built an AI-assisted workflow that monitored whether its deployed malware was caught by security products and then autonomously modified and rebuilt the toolkit to evade those detections. Anthropic said the actor used AI across its operations, including domain registration, phishing infrastructure, and command-and-control monitoring, and targeted more than 20 organizations in Ukraine, Europe, the Middle East, and Asia.

Anthropic also said the actor compromised at least three hotel Wi-Fi vendors and used DNS hijacking to redirect guest traffic.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html)

---
Canonical: https://techandbusiness.org/newswire/FquomCRAGA9_HmbI12uze4
Retrieved: 2026-09-12T02:48:16.305Z
Publisher: Tech & Business (techandbusiness.org)
