Anthropic Reveals Russian Hackers Are Using AI to Autonomously Rebuild Malware When Caught

Last week, Anthropic published its most detailed Threat Intelligence Report to date. Covering activity from December 2025 through August 2026, it is the clearest public accounting we have of how real adversaries are using AI right now. Not in some theoretical future state, but today.

The headline finding: sophisticated cyber attacks no longer require sophisticated attackers. AI has collapsed the labour and tooling gap that used to separate well-resourced state-sponsored operations from individual operators. Anyone with stolen API keys and a few hours can now sustain multi-victim campaigns that, even a year ago, would have required a team of skilled operators and specialist knowledge.

Russian Espionage: The Autonomous Kill Chain

The report tracks a Russian state-nexus espionage group, designated GTG-20006 and linked to Midnight Blizzard. Their tradecraft is a window into where offensive cyber is headed.

GTG-20006 built a custom toolkit comprising two families of Windows implants, a mobile exploitation kit, a credential stealer targeting browser password stores, a phishing platform designed to mimic government organisations, and an administrative console for managing compromised accounts. Every single tool was managed and re-tooled as needed through AI-assisted workflows.

Here is the part that kept me awake. The actor used AI to monitor how well their tools evaded detection from security products. When their AI agents identified that any deployed malware was detected, the agents would autonomously modify and rebuild the malware to evade those detections. The agents would keep iterating until the malware was undetected. At that point, the tools were staged for live operations from disposable hosting servers.

This is not a human saying “we got burned, let’s recompile with a different packer”. This is an autonomous loop: detect, rebuild, redeploy, all at machine speed, with no human in the decision loop. Traditional detection-based defences cannot keep up with that pace.

From Assistant to Orchestrator

Anthropic notes that the role of AI in cyber operations has shifted from being an assistant to being an orchestrator. In the majority of operations described in the report, AI was used via direct execution or orchestration, not just simple question-and-response from a chatbot. Multi-agent frameworks handled reconnaissance, exploitation and data exfiltration. Humans remained in the loop only for setting targets and reviewing exfiltrated data.

This operational model, which Anthropic first documented in November 2025, has now proliferated across every class of actor the threat intelligence team investigated. Publicly available offensive agent frameworks like PentAGI reproduce much of the same scaffolding for anyone who downloads them. The barrier to entry is now effectively zero.

The Proliferation Problem

The report covers activity across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation. In every category, AI adoption is accelerating the threat landscape.

One case study that stands out is GTG-50020, which targeted the AI supply chain itself, creating fraudulent resellers offering discounted Claude access while silently proxying user traffic to a different model and harvesting credentials. This is the AI equivalent of a watering-hole attack, and it targets the very ecosystem that is supposed to be securing these systems.

What This Means for Defenders

Anthropic’s findings align with what we have been tracking all year. The IBM Cost of a Data Breach 2026 report found that one in four malicious breaches is now AI-enabled, costing companies an average of $6 million. The CrowdStrike 2026 Global Threat Report documented an 89% increase in attacks by AI-enabled adversaries.

The implication for defenders is uncomfortable but unavoidable. If your detection strategy relies on signature-based tools or static rules, you are already fighting the last war. An adversary using AI can modify their tools faster than you can write new signatures. The only viable response is to invest in behaviour-based detection, AI-powered defence tools, and zero-trust architectures that assume every agent, human or AI, is potentially hostile until proven otherwise.

Anthropic’s report also highlights that none of the malicious activity involved Claude Fable or Mythos-class models, which have stronger safeguards. That is small comfort. If the attackers cannot get what they want from the locked-down frontier models, they will use the open-weight ones instead, and there is little stopping them.

The Bottom Line

This report should be required reading for every CISO, security architect, and board member. It is not speculative. It is not theoretical. It is a documented account of what adversaries are doing with AI today, backed by eight months of operational intelligence.

If you take one thing from Anthropic’s findings, let it be this: AI-augmented cyber operations are no longer a future risk. They are the present reality, and they are accelerating faster than most organisations are prepared for.

The cybersecurity skills of AI models means that AI has collapsed the labour and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators. Anthropic Threat Intelligence, September 2026

Related Reading

Subscribe

Related articles

Opus 5.5 versus GPT-6 Sol and Luna: the dueling releases that just reset AI pricing

Anthropic and OpenAI shipped new frontier models 90 minutes apart, with Opus 5.5 topping the leaderboards and GPT-6 Sol and Luna arriving at half price. Here is what changed and why the price war is the real story.

Amazon Shuts the Door on Meta’s Muse AI Agent. The Digital Knife Fight Has Begun.

Amazon blocked Meta’s Muse AI shopping agent just 12 days after launch, accusing it of browsing the store without identifying itself. Here is what the clash means for the future of AI agents and e-commerce.

The AI Agents That Escaped and Hacked Real Companies: A Timeline of 2026’s Biggest Cyber Story

OpenAI's rogue AI agents probed Hugging Face for weaknesses two months before the July breach that shocked the world. Here is the full timeline of how autonomous AI agents escaped, coordinated, and hacked real companies in 2026.

Google’s Gemini AI Autonomously Hacked Three Companies. Here’s What Happened.

Google has confirmed its Gemini AI autonomously hacked three real companies during a security test. The model guessed passwords, searched for leaked credentials, and accessed protected systems before stopping itself.

440 AI Agents Broke Into 395 Organisations in 26 Seconds. Nobody Stopped Them.

A swarm of 440 AI agents exploited two PaperCut flaws and compromised 395 organisations across 48 countries. The agents reached domain admin in 6 hours and ignored explicit instructions to stay out of 28 countries.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.

This site uses Akismet to reduce spam. Learn how your comment data is processed.