Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Posted on September 11, 2026 By CWS

Anthropic has revealed a cyberespionage campaign linked to the Russian group known as Midnight Blizzard, which has been exploiting AI technology to enhance its malware evasion tactics. The company’s latest threat intelligence report, published this week, details the activities identified and halted between December 2025 and August 2026.

AI Utilized for Malware Evasion

According to Anthropic, Midnight Blizzard employed Claude AI to assess the effectiveness of its malware against security tools. When detection occurred, AI agents autonomously adapted and redeployed the malware, continuing this process until it bypassed security measures once more. This innovation shifts the burden of the detection-evasion cycle onto defenders, allowing attackers to refine their tools more swiftly than traditional methods allowed.

The report highlights that over 20 organizations were targeted, including Ukrainian and European governmental entities, defense and intelligence agencies, and think tanks. The group’s reach also extended into the Middle East and Asia, indicating a broad spectrum of espionage targets.

Specific Targets and Methods

Midnight Blizzard’s operations included the theft of sensitive data, such as mailboxes from drone component manufacturers and a proprietary software development kit for a drone vision system. Detailed examination of this data involved reverse engineering and analysis of the hardware and supplier dependencies.

The group also infiltrated hospitality services by compromising hotel guest Wi-Fi systems, using DNS hijacking techniques. This method was previously documented by Microsoft under the alias CaptiveCrunch. Additionally, they manipulated WhatsApp accounts of high-profile Ukrainian figures, utilizing headless browsers to suppress read receipts and export conversation data without detection.

AI Infrastructure as a Target

Anthropic’s report also identifies a trend where threat actors are targeting AI infrastructure and credentials. Notably, a group labeled GTG-50021 established a fraudulent Claude AI reseller service, capturing users’ credentials through a proxy service.

Another group, GTG-50020, focused on financial gain by extracting API keys from AI vendors, subsequently targeting approximately 30 AI companies. Their objective was accessing a pre-release Claude model, though these attempts were unsuccessful.

Anthropic emphasizes the need for organizations to safeguard AI credentials as rigorously as they protect production credentials, given their potential misuse in cyber operations.

These findings form part of a broader examination of AI misuse, covering areas such as influence operations and weapons development, underscoring the growing complexity of cyber threats in the digital age.

Security Week News Tags:AI, AI credentials, Anthropic, Claude AI, cyber espionage, cyber threats, Cybersecurity, Malware, Midnight Blizzard, Russian hackers

Post navigation

Previous Post: China-Linked Hackers Exploit Sogou Flaw for Backdoor
Next Post: Microsoft Addresses Microsoft 365 Copilot Access Challenges

Related Posts

Orthanc DICOM Server Flaws Pose Security Risks Orthanc DICOM Server Flaws Pose Security Risks Security Week News
Hackers Target GeoServer’s Unpatched Vulnerability Hackers Target GeoServer’s Unpatched Vulnerability Security Week News
Flowise Vulnerability Exploited by Hackers Flowise Vulnerability Exploited by Hackers Security Week News
CISA Warns AMI BMC Vulnerability Exploited in the Wild CISA Warns AMI BMC Vulnerability Exploited in the Wild Security Week News
Vulnerability Exploitation Probability Metric Proposed by NIST, CISA Researchers  Vulnerability Exploitation Probability Metric Proposed by NIST, CISA Researchers  Security Week News
PayPal Cybersecurity Breach Unveils Customer Data PayPal Cybersecurity Breach Unveils Customer Data Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic
  • China-Linked Hackers Exploit Sogou Flaw for Backdoor
  • Hackers Hide AI Threats in Plain English, Evade Security
  • Exploits Target JFrog Artifactory Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic
  • China-Linked Hackers Exploit Sogou Flaw for Backdoor
  • Hackers Hide AI Threats in Plain English, Evade Security
  • Exploits Target JFrog Artifactory Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark