Anthropic Caught a Russian Spy Unit Using Claude to Rewrite Its Own Malware Past Antivirus
Cybersecurity

Anthropic Caught a Russian Spy Unit Using Claude to Rewrite Its Own Malware Past Antivirus

Anthropic disrupted a Midnight Blizzard campaign that used Claude to monitor detection results and automatically rebuild malware until it evaded antivirus, compressing an evasion cycle that used to take human operators days into something closer to real time.

PublishedSeptember 19, 2026
Read time6 min read
Share

What Anthropic disclosed

Anthropic published findings on September 11, 2026 describing how it disrupted a cyberespionage operation run by Midnight Blizzard, the Russian state-nexus group, between December 2025 and August 2026. The group had been using Claude not to write malware from scratch but to manage an ongoing evasion loop: when a security product flagged their malware, AI agents automatically modified and rebuilt it, then redeployed it, repeating the cycle until the updated version slipped past detection again.

Anthropic's own language for this is that the technique let attackers close the loop faster than defenders can respond. That framing matters because it describes a change in tempo, not just a change in tooling. The bottleneck that used to slow down malware iteration, a human operator manually adjusting code after each detection, is what got automated here, and automation removes the natural pacing that gave defenders a fighting chance to catch up.

The target list reveals the real scope of intent

More than 20 organizations were hit across a broad set of sectors, and the split between them is informative on its own. Ukrainian and European government ministries, defense and intelligence bodies, embassies, and think tanks fit the traditional Midnight Blizzard profile of state espionage that security researchers have tracked from this group for years. What stands out is the rest of the list, which included drone component manufacturers, hospitality and hotel WiFi vendors, and additional targets spread across the Middle East and Asia.

Hotel WiFi vendors and drone component suppliers function as supply chain nodes rather than as end targets in their own right, meaning compromising one vendor gives an attacker access to the guests, executives, or downstream manufacturers that pass through its infrastructure every day. That target selection pattern shows the group using AI-accelerated tooling to expand into softer, less-monitored parts of a supply chain, rather than spending its effort exclusively hardening attacks against a shorter list of well-defended primary government targets.

Why this is a different category of risk than shadow AI

It is easy to fold this into the general conversation about ungoverned AI tool use inside organizations, but that framing understates what actually happened here. This describes a state-linked intelligence unit using a legitimate, widely deployed commercial AI product as an operational component of an active espionage campaign, with the vendor itself having to detect and disrupt the abuse from the outside after the fact. That is a materially different scenario from an employee quietly pasting sensitive data into an unsanctioned chatbot during their workday.

That distinction matters directly for how you brief your board on this topic. The shadow AI conversation centers on governance controls a company can put in place internally, such as approved tool lists, data loss prevention rules, and usage policies enforced through IT. This incident sits in a different category entirely, a threat actor class that internal governance cannot address on its own, because the capability lives inside a product your own teams may also rely on for legitimate work, and the vendor's trust and safety function is now effectively part of your threat landscape whether you asked for that or not.

The compressed timeline problem

Security programs built over the last decade generally assume that malware evolves on a timescale measured in days or weeks, giving signature-based and behavior-based detection systems a reasonable window to catch up after each wave of updates from an adversary. An automated evasion loop of the kind Anthropic describes collapses that window toward something closer to the time it takes to run an API call and a build script, which is a matter of minutes rather than days, removing the buffer most detection architectures were quietly designed around.

Anthropic's own assessment, that the gap between a lone operator and a nation-state actor has mostly closed, is worth taking at face value coming from the company best positioned to see this dynamic firsthand across its own platform. If that assessment holds more broadly across the industry, detection strategies leaning primarily on known signatures or previously observed behavior patterns will degrade faster than most current security roadmaps account for in their planning, and the case for prioritizing genuinely behavioral, anomaly-based detection gets substantially stronger as a budget priority for next year.

The vendor responsibility question this raises

Anthropic gets real credit here for finding this activity, disrupting it, strengthening its safeguards in direct response, and publishing detailed findings rather than quietly patching the issue and staying silent about what happened. That transparency is genuinely useful to defenders trying to understand the shape of this new threat category. It also previews an uncomfortable dynamic worth sitting with: AI vendors are now a frontline party in state-sponsored cyberespionage, discovering abuse of their own platforms only after attackers have already used that access operationally for the better part of a year.

That puts a new item on the vendor risk checklist for any AI platform your organization depends on for coding, security tooling, or operations: what is the vendor's demonstrated track record of detecting and disrupting malicious use of their own product, and how quickly do they disclose it. This incident is a reasonably strong data point in Anthropic's favor, but it is a question every enterprise AI buyer should now be asking of every vendor, not just the one with the good story.

The decision this puts on your desk

Revisit your detection strategy's dependence on signature and known-pattern matching, and push your security team or MSSP for a clear, specific answer on how much of your current coverage is genuinely behavioral versus purely signature-based, because that ratio is the one this incident most directly argues should shift over the next planning cycle. If your organization touches supply chain categories like hospitality, logistics, or component manufacturing that have historically felt peripheral to classic state-sponsored espionage targeting, treat that assumption as outdated starting now rather than waiting for direct evidence.

Finally, add AI vendor trust and safety track record as a formal line item in your AI procurement and risk review process going forward, alongside the usual questions about uptime, data handling, and model behavior. The next disclosure like this one may not involve a vendor that caught and disrupted the abuse before you had to find out the hard way through your own incident response process instead, and knowing which vendors have that track record before you sign a contract is worth far more than learning it afterward.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#Midnight Blizzard#Anthropic#Claude#AI-powered-attacks#state-sponsored#malware-evasion