Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
C The Hacker News ·
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
APT29 leverages generative AI systems to automate malware regeneration after detection, undermining static detection mechanisms, and compromises supply-chain infrastructure (hospitality vendors) for network manipulation.
Description
APT29 (alias Midnight Blizzard/Cozy Bear), attributed to Russian intelligence services and designated GTG-20006 by Anthropic, conducts a campaign leveraging generative AI systems to automate malware regeneration and stay ahead of security detection. The threat actor has compromised at least three hospitality vendors whose DNS records were manipulated to redirect hotel guest traffic to actor-controlled servers. In parallel, the group operates a cloud email espionage platform using a device-code phishing framework (Embassy Kit) to steal Microsoft 365 tokens from government and diplomatic personnel. Targets include military intelligence services in Ukraine, European governments, and defense organizations.
Risk score
- strategic relevance
- 0.85
Path: strategic