Skip to content
Auto-CTI
Back to today
NEW APT29 (Midnight Blizzard/Cozy Bear/GTG-20006) CRITICAL C3

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

C The Hacker News ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

APT29 leverages generative AI systems to automate malware regeneration after detection, undermining static detection mechanisms, and compromises supply-chain infrastructure (hospitality vendors) for network manipulation.

Description

APT29 (alias Midnight Blizzard/Cozy Bear), attributed to Russian intelligence services and designated GTG-20006 by Anthropic, conducts a campaign leveraging generative AI systems to automate malware regeneration and stay ahead of security detection. The threat actor has compromised at least three hospitality vendors whose DNS records were manipulated to redirect hotel guest traffic to actor-controlled servers. In parallel, the group operates a cloud email espionage platform using a device-code phishing framework (Embassy Kit) to steal Microsoft 365 tokens from government and diplomatic personnel. Targets include military intelligence services in Ukraine, European governments, and defense organizations.

Risk score

85
strategic relevance
0.85

Path: strategic

ESC