Russian Hackers Use AI to Rebuild Malware After Detection

Russian state-sponsored hackers, identified as GTG-20006, leveraged Anthropic's Claude to autonomously rebuild malware after detection, targeting over 20 organizations across Europe, Ukraine, and the Middle East. New details reveal the group compromised hospitality vendors to hijack hotel Wi-Fi traffic, deployed multi-platform implants, and exfiltrated sensitive communications from high-profile diplomatic and defense figures.
Anthropic disclosed that the threat actor, linked to Midnight Blizzard, compromised hotel guest Wi-Fi networks to hijack DNS records and deploy device-specific malware via ClickFix lures, according to GN geopolitics/cyber (en-US). The group also exploited flaws in camera streaming services and used headless browsers to bulk-export WhatsApp conversations from targeted officials and drone manufacturers.
Source: The Hacker NewsA Russian state-sponsored group used Anthropic's AI to automatically modify malware when security tools caught it, targeting government and diplomatic figures across Europe and beyond.
Source: The Hacker News






