Russia-Linked Hackers Taught Claude to Rebuild Their Malware

Russia-Linked Hackers Taught Claude to Rebuild Their Malware

By David V. | Category Vulnerabilities | 9/29/2026

How the Rebuild Loop Worked

For years, malware evasion ran on human time. An attacker ships a tool. A security vendor spots it, writes a signature, and pushes an update. The attacker's developers rework the code and try again. That cycle could take days or weeks, and every round cost the attacker time and money.

GTG-20006 squeezed that cycle down. According to Anthropic's September threat report, the group ran AI agents that watched its own implants inside victim networks. When a security product flagged one, the operators used Claude to find the flagged piece, modify it, rebuild it, and push it back out. They repeated this until the alerts stopped. The cleaned-up tools then went onto throwaway servers for phishing, ClickFix lures, and DNS hijacking.

Picture a burglar with a key-cutting machine in his van. You change the lock. He cuts a new key in your driveway.

Anthropic put it plainly: AI has pushed the cost back onto defenders. A new detection rule used to slow an attacker down for a while. Now a capable group can rebuild faster than defenders can write new rules.

Who Is GTG-20006? APT29 With a New Name Tag

Anthropic labels the groups it tracks "GTG," short for Generative Threat Group. It says GTG-20006's tradecraft and targeting match public reporting on Midnight Blizzard, also known as APT29 or Cozy Bear. Western governments tie that group to Russia's SVR foreign intelligence service. If the name sounds familiar, you probably remember it from the SolarWinds hack.

The campaign ran from about December 2025 through August 2026 and hit more than 20 organizations, mostly in Europe and Ukraine. The targets included government ministries, defense and intelligence bodies, embassies, think tanks, drone supply-chain companies, and people connected to U.S. foreign policy.

They Automated a Lot More Than Malware

The rebuild loop got the headlines. Anthropic says the group also used AI across most of the operation: building tools, buying infrastructure, phishing, keeping access, running command-and-control, and exfiltrating data.

Three cases from the report stand out.

Hotel Wi-Fi. The group broke into at least three vendors that run guest Wi-Fi for hotels. With stolen admin credentials, they changed DNS records so guests' traffic, device IDs, and IP addresses flowed to servers the group controlled. You check in, join the Wi-Fi, and a foreign intelligence service logs your laptop.

WhatsApp takeovers. Using a headless browser, the group linked its own "companion device" to victims' WhatsApp accounts, exported their conversations, and suppressed read receipts so nothing looked off. At least two former senior Ukrainian officials were targeted.

Bulk data theft. One victim, a North African government technology authority, lost more than 300,000 national identity records plus registry data on over half a million companies.

The Part Most Articles Skip

Some coverage frames this as fully autonomous hacking with no human involved. Anthropic's report says otherwise: a person made each targeting decision, and the AI carried out the work. That's still a big shift, but it's a speed upgrade for skilled operators, not robots choosing who to hack.

The loop also has a limit. It defeats static detection, the signature-matching that older antivirus leans on. A rebuilt implant still has to call home, move files, and grab credentials. Security tools that watch behavior can catch those actions no matter how many times the code changes.

One more detail worth sitting with. The group built its pipeline on a commercial AI service that monitors for abuse, and that monitoring is how Anthropic caught them. A group running an open-weight model on its own hardware would leave no such trail.

What You Should Actually Do

You're probably not on the SVR's target list. These techniques trickle down to criminal groups anyway, usually within a year or two.

  1. Small business owners: If your protection is signature-based antivirus alone, move to an endpoint tool with behavior-based detection (often sold as EDR). Ask your IT provider which one you have.
  2. Traveling: Treat hotel Wi-Fi like a coffee shop's. Use a reputable VPN, or tether to your phone for anything sensitive.
  3. WhatsApp users: Open Settings, then Linked Devices. Remove anything you don't recognize.
  4. Everyone: If a website tells you to paste a command into Run, PowerShell, or Terminal to "prove you're human," close the tab. That's ClickFix.

For more on how attackers trick people into running their own malware, read [internal link: Cybro ClickFix or social engineering article].

🔑 Key Terms

APT (Advanced Persistent Threat) — a sustained, targeted hacking operation, usually run by nation-states. They aim to stay hidden long-term, not smash-and-grab.

APT29 / Midnight Blizzard / Cozy Bear — a Russian espionage group Western governments link to the SVR. Different security companies give it different names.

SVR — Russia's Foreign Intelligence Service, its main civilian spy agency.

Implant — malware placed on a compromised machine to give attackers ongoing access.

Static detection — spotting malware by matching its code against known signatures. Change the code, and the match can fail.

EDR (Endpoint Detection and Response) — security software that watches what programs do, not just what they look like.

DNS hijacking — changing the "address book" that turns website names into server addresses, so traffic goes somewhere the attacker controls.

C2 (Command-and-Control) — the servers attackers use to send orders to their malware and receive stolen data.

ClickFix — a lure that tricks you into copying and running a malicious command yourself, often disguised as a CAPTCHA or fix.

Headless browser — a web browser that runs without a visible window, controlled by code. Useful for automation, and for abuse.

📚 Sources

https://www.anthropic.com/threat-intelligence-report-september-2026
The Hacker News — Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
UV Cyber — Threat Advisory: The Historical and Ongoing Threat of APT29