"The actor also used AI to monitor how well their tools evaded detections from known security defenses," Anthropic explained.
GTG-20006: a generative threat group tied to known clusters
Anthropic attributed the campaign to a cluster it calls GTG-20006, where "GTG" stands for Generative Threat Group. The company said this cluster aligns with broader reporting linking the actor to Midnight Blizzard (aka APT29 and Cozy Bear). Anthropic described GTG-20006 as a state-sponsored, Russian-aligned espionage actor that has mounted operations against military intelligence targets in Ukrainian and European governments, and against diplomatic and defense organizations and individuals connected to U.S. foreign policy.
AI-driven rebuilds and an automated operational tempo
Anthropic detailed an AI-assisted workflow the actor used to stay ahead of defenders: monitoring deployed malware for detection, then automatically modifying and rebuilding the malware to evade existing security products. According to the company, "agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections." Once rebuilt, artifacts were staged on disposable hosting servers and victims were redirected to those servers via phishing, ClickFix-style lures, and DNS hijacking.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageToolset and delivery: implants, RATs, credential theft, and Embassy Kit
The actor's toolkit was substantial and multi-platform. Anthropic listed two Windows-based implants and a mobile exploitation kit, plus a credential-stealing tool targeting browser password stores, a phishing platform that mimics government organizations, and an administrative console for managing compromised accounts. Specific payloads observed included Windows implants PowerChrome, WUEngine, Shadow C2, MiniPlasma, and CloudSyncSvc; an Android surveillance RAT dubbed GiftDrop (a rebranded GiftsExpress); and an iOS implant called DarkSword.
Anthropic also described a cloud email espionage platform that used a device code phishing framework codenamed Embassy Kit to steal Microsoft 365 tokens. That campaign, the company wrote, resulted in unauthorized access and exfiltration of mail records from at least eight organizations, including a national prosecutor's office, a military education institute, and a regional intergovernmental organization.
Techniques in the wild: DNS hijacking, hotel Wi‑Fi compromises, camera access, and WhatsApp takeover
The actor staged multi-step delivery and reconnaissance operations. Anthropic said GTG-20006 compromised at least three hospitality vendors that operate hotel guest Wi‑Fi, used compromised admin credentials to change DNS records (DNS hijacking), and redirected guests so their traffic, device identifiers, and IP addresses were sent to the actor's servers. Stolen data from hotel management systems and guests' devices was then used to identify further targets tied to Ukraine, including government officials and drone manufacturers.
Additional observed techniques included attempts to take over victims' WhatsApp accounts by linking accounts as companion devices via headless browsers and bulk-exporting Russian- and Ukrainian-language conversations while suppressing read receipts. The actor also exploited authorization flaws in camera streaming services to enumerate users and harvest tokens that granted access to live camera streams.
Scope of targets, overlaps with other campaigns, and a major credential theft
Anthropic said more than 20 distinct organizations were singled out during reconnaissance and live operations, including government ministries, defense and intelligence bodies, embassies and diplomatic missions, think tanks, and defense-industrial companies—mainly in Ukraine and Europe, with activity extending to the Middle East and maritime-related government agencies in Asia. The activity overlaps with a campaign dubbed CaptiveCrunch recently documented by ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs.
In one intrusion flagged by Anthropic, the actor used VPN appliance credentials to hijack a central account server at a North African government technology authority and exfiltrated a credential database containing over 300,000 national identity records and the commercial registry data of more than half a million companies operating in that country.
What this means for technologists, policymakers, and affected organizations
- Technologists and security teams: the actor automated detection testing and rebuilds, meaning static signature-based blocking can be rapidly circumvented; defenders will face faster operational tempos from adversaries that use AI to test and iterate payloads.
- Policymakers and regulators: the campaign combined cross-border espionage, credential theft, and infrastructure abuse (hotel Wi‑Fi and DNS records), raising questions about protections for critical hospitality and government-facing services and about cross-jurisdictional incident response for large-scale data exfiltration.
- Affected organizations and procurement leaders: the use of disposable hosting, impersonation via phishing platforms, device-code phishing (Embassy Kit), and stolen vendor credentials means vendor security, DNS integrity, and multi-factor protections tied to token flows and email systems will be central to preventing similar compromises.
Anthropic summed the practical effect in stark terms: "The result of the above is that AI has inverted the cost back onto defenders." The campaign it described ties generative AI to every phase of an espionage operation—reconnaissance, delivery, monitoring, rebuilding, and persistence—leaving defenders to confront attackers who can both test and adapt at machine speed.
https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html




