Midnight Blizzard Used Claude Agents to Automate Malware Rewrite-Deploy Cycle Against 20+ Targets
Anthropic documented Midnight Blizzard automating malware evasion with Claude agents against government and defense targets, including drone IP theft and Wi-Fi hijacks. The activity demonstrates faster closed-loop adaptation than manual tradecraft previously allowed. Parallel targeting of AI credentials by related groups signals infrastructure itself becoming a contested domain.
Anthropic’s monitoring captured the full loop: agents queried detection outcomes from security products, generated code patches via Claude, rebuilt payloads, and tested redeployment without human intervention. Victims included Ukrainian government ministries, two drone component manufacturers whose full SDK and supplier data were exfiltrated, and three hospitality firms whose guest Wi-Fi credentials enabled DNS hijacks later tied to Microsoft’s CaptiveCrunch reporting.
Technical logs show the actor spent days reverse-engineering stolen drone vision architecture after initial mailbox theft, while separate operations linked WhatsApp companion devices to suppress read receipts on high-value Ukrainian targets. This evidence comes from Anthropic’s internal abuse telemetry rather than third-party attribution claims.
The pattern reveals a measurable shift: prior manual evasion cycles took days per signature update; AI agents compressed it to hours, inverting defender economics. Parallel cases in the same report—prompt injection against evaluation sandboxes by GTG-50020 and credential-harvesting reseller operations—indicate Russian-speaking actors now treat AI infrastructure as both tool and target.
Defenders must classify API keys and agent integrations as production credentials with equivalent logging and anomaly detection. Expect expanded testing of similar loops against other frontier models within the next quarter as cost barriers fall.
Anthropic: At least two additional Russian-linked groups will attempt sandbox prompt injection for model or key access within 90 days.
Sources (3)
- [1]Primary Source(https://www.anthropic.com/research/midnight-blizzard-claude-abuse)
- [2]Supporting Source(https://www.microsoft.com/en-us/security/blog/2026/07/captivecrunch-midnight-blizzard/)
- [3]Supporting Source(https://www.recordedfuture.com/midnight-blizzard-ai-tooling-2026/)