Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
Anthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model. The post Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion appeared first on SecurityWeek.
Anthropic disrupted a cyberespionage operation whose tradecraft and targeting match the Russian state-nexus group tracked as Midnight Blizzard, the company said in a threat intelligence report published this week.
The report covers activity the company identified and shut down between December 2025 and August 2026.
According to Anthropic, Midnight Blizzard used Claude to monitor how well its malware evaded detection by security products. When a tool was flagged, AI agents automatically modified and rebuilt it, then redeployed it, repeating the process until the malware went undetected again.
Related breach coverage
- AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns2026-09-09
Criminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG. The post AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns appeared first on SecurityWeek.
- Anthropic Warns Claude Users of Infostealer Malware Infections2026-08-31
The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage. The post Anthropic Warns Claude Users of Infostealer Malware Infections appeared first on SecurityWeek.
- Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware2026-08-17
Anthropic has been conducting tests to identify issues in how AI agents interact with each other. The post Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware appeared first on SecurityWeek.
- Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows2026-09-17
Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek.