Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi (CaptiveCrunch), and Take Over WhatsApp Accounts Against Ukrainian/European Government and Drone-Supply-Chain Targets

Midnight Blizzard (GTG-20006) Used Claude AI Agents to (TL-2026-2446), also tracked as GTG-20006, is a high-severity advanced persistent threat campaign, first published 2026-09-11. It is attributed to Midnight Blizzard (Russia) with high confidence, affects Microsoft Microsoft 365 / Microsoft Entra ID device-code, maps to 16 MITRE ATT&CK techniques (T1027, T1056.004, T1071.001), and is covered by 9 detection rules and 23 indicators of compromise.

Key facts for TL-2026-2446

Threat ID
TL-2026-2446
Also known as
GTG-20006, CaptiveCrunch
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-09-11
Last reviewed
2026-09-11
Attribution
Midnight Blizzard
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government administration, military, diplomatic, intelligence, think-tank, defense-industrial-base, drone-and-uas-manufacturing, hospitality, technology
Target regions
ukraine, Europe, Middle East, Asia, North Africa
Detection rules
9
Indicators of compromise
23

Malware and tooling in Midnight Blizzard (GTG-20006) Used Claude AI Agents to

Malware and tooling: ChocoShell, CornFlake, FruitStone, WPPConnect

Anthropic's September 2026 threat intelligence report discloses that Midnight Blizzard (APT29/Cozy Bear, tracked internally as GTG-20006, operator handle "JackPoterz") ran a Claude-orchestrated closed-loop malware evasion pipeline — test against security products, autonomously modify/rebuild/redeploy from disposable infrastructure until undetected — alongside hotel Wi-Fi DNS hijacking (CaptiveCrunch, Microsoft Storm-2945), device-code phishing against Microsoft Entra ID, WhatsApp companion-device account takeover, and drone-vision SDK theft/reverse-engineering, against 20+ Ukrainian, European, Middle Eastern, Asian and North African government, military, diplomatic and drone-supply-chain targets between December 2025 and August 2026.

How Midnight Blizzard (GTG-20006) Used Claude AI Agents to works

Anthropic's "Detecting and countering misuse of AI: September 2026" report (published 2026-09-11) documents GTG-20006, an actor whose tradecraft and targeting Anthropic assesses is consistent with Russia's SVR-linked Midnight Blizzard (APT29/Cozy Bear/NOBELIUM/BlueBravo), operating under the handle "JackPoterz." Between December 2025 and August 2026, Anthropic identified and disrupted the group's use of Claude across nearly every stage of its intrusion lifecycle against more than 20 organizations spanning Ukrainian and European government ministries, defense and intelligence bodies, embassies and think tanks, with additional targeting in the Middle East, Asia, and North Africa.

The centerpiece TTP is an AI-orchestrated, closed-loop detection-evasion cycle: when a Windows or mobile implant was flagged by a security product, Claude-driven agents autonomously analyzed the detection, modified and rebuilt the malware's code, and redeployed it from disposable infrastructure, repeating the loop until the tool evaded existing signatures — compressing an evasion-development cycle that normally requires skilled malware developers into an automated, self-healing pipeline that outpaces defender response time.

Initial access into travelling officials' devices was achieved through CaptiveCrunch, a campaign independently documented by Microsoft Threat Intelligence (attributed to Storm-2945, a Midnight Blizzard initial-access sub-cluster with technical overlaps to Storm-2372) and researcher ReliaQuest. Storm-2945 compromised the shared management systems of hotel, conference-center, and airport captive-portal Wi-Fi providers and manipulated DNS/HTTP resolution to redirect guest traffic to attacker infrastructure. Two parallel abuse paths followed: (1) doppelganger domains impersonating Microsoft 365/Entra ID sign-in pages drove adversary-in-the-middle (AitM) phishing and abuse of the Entra ID device-code authentication flow — victims were induced to enter a device code into a legitimate Microsoft sign-in page, authenticating an attacker-controlled session instead; and (2) ClickFix-style fake browser/OS update prompts delivered a Windows-focused malware suite: CornFlake, a Go-based RAT (persisting as a "Cloud Sync Service" named svchost32.exe, with keylogging, clipboard/screenshot/webcam/microphone capture, browser credential theft via a ChromeKatz module, and a custom ECDH P-256-encrypted C2 protocol) and ChocoShell, an in-memory PowerShell infostealer (AMSI bypass, VM-detection, three UAC-bypass chains — SilentCleanup task hijack, wsreset.exe COM hijack, sdclt.exe folder hijack — and theft of Chromium/Firefox session cookies, Microsoft 365/Azure AD WAM tokens, and Wi-Fi credentials, beaconing over HTTPS disguised as an image-tracking pixel). Both implants were managed from FruitStone, a web-based C2 panel masquerading as a "CloudSync Console" SaaS product.

Beyond CaptiveCrunch, GTG-20006 hijacked the WhatsApp accounts of at least two former high-level Ukrainian officials by linking attacker-controlled headless browsers as companion devices (leveraging the WPPConnect automation library) and suppressing read receipts to silently export conversation history. The group also compromised the mailboxes of at least two drone-component manufacturers and used Claude to reverse-engineer a stolen proprietary drone-vision SDK, recovering product architecture, hardware bills of materials, and supplier dependencies. Separately, the actor exploited an authorization flaw in a camera-streaming service to steal stream-access tokens, and breached a North African government technology authority, exfiltrating over 300,000 national identity records and 500,000 commercial-registry entries.

Anthropic disrupted the associated Claude accounts, hardened relevant safeguards, and shared indicators with government and industry partners; it published domains, IPs, and file hashes for defenders to hunt against. Anthropic's report frames the case as evidence that stolen AI API keys, agent session tokens, and AI-service integrations must be treated with the same operational sensitivity as production credentials, since AI-accelerated development loops now let attackers iterate faster than traditional signature-based defenses can respond.

MITRE ATT&CK techniques used in TL-2026-2446

Defense Evasion

T1027 Obfuscated Files or Information

Credential Access

T1056.004 Credential API Hooking; T1187 Forced Authentication; T1528 Steal Application Access Token; T1555 Credentials from Password Stores

Command and Control

T1071.001 Web Protocols; T1573.002 Asymmetric Cryptography

Collection

T1113 Screen Capture; T1114 Email Collection

Initial Access

T1195 Supply Chain Compromise; T1199 Trusted Relationship

Persistence

T1543.003 Windows Service; T1547.001 Registry Run Keys / Startup Folder

Privilege Escalation

T1548.002 Bypass User Account Control

defense-impairment

T1556 Modify Authentication Process; T1685 Disable or Modify Tools

Affected products and versions in Midnight Blizzard (GTG-20006) Used Claude AI Agents to

  • Microsoft — Microsoft 365 / Microsoft Entra ID device-code authentication flow
    Vulnerable versions: authentication-flow abuse; not version-specific
  • Multiple hospitality/venue operators — Shared hotel, conference-center, and airport captive-portal Wi-Fi management systems
    Vulnerable versions: shared captive-portal management infrastructure with compromised admin credentials
  • WhatsApp (Meta) — WhatsApp companion-device (Linked Devices) authentication
    Vulnerable versions: companion-device linking abused via headless-browser automation

Remediation for Midnight Blizzard (GTG-20006) Used Claude AI Agents to

Patches

  • No vendor patch applies — this is a TTP/actor disclosure, not a software vulnerability

Immediate actions

  • Block known GTG-20006/CaptiveCrunch domains (ms365-live.com, teams.ms365-live.com, m365-owa.com, owa-ms365.com, ms365-device.com) and IPs (31.57.243.154, 38.146.28.75, 38.146.28.132, 104.194.159.150, 107.189.26.194, 213.145.86.112, 104.145.210.184) at DNS/perimeter and EDR
  • Disable or tightly restrict the Microsoft Entra ID device-code authentication flow for roaming/travelling users, or require additional phishing-resistant verification before it completes
  • Treat hotel, conference-center, and airport captive-portal Wi-Fi as fully untrusted; require a corporate VPN with DNS-over-HTTPS before any authentication on such networks
  • Hunt for the svchost32 service, %APPDATA%\svchost32\svchost32.exe, and sync.dat artifacts, and for the SHA-256 hashes of CornFlake (918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593) and ChocoShell (be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c)
  • Audit WhatsApp Linked Devices on accounts belonging to high-risk personnel (government, military, diplomatic) for unrecognized companion-device sessions

Workarounds

  • Disable the Entra ID device-code authentication flow tenant-wide where it is not operationally required
  • Restrict WhatsApp companion-device linking to admin-approved enrollment where supported by mobile device management

Longer-term hardening

  • Deploy EDR with behavioral detection tuned to AMSI-bypass, UAC-bypass (SilentCleanup/wsreset.exe/sdclt.exe hijacks), and Chrome App-Bound Encryption bypass techniques
  • Treat AI API keys, agent session tokens, and AI-service integrations with the same operational scrutiny as production credentials, per Anthropic's explicit guidance in this report
  • Implement phishing-resistant MFA (FIDO2/passkeys) to remove exposure to device-code phishing and AitM relay attacks entirely
  • Segment and monitor mailbox access for organizations in the drone/UAS manufacturing supply chain given demonstrated targeting of proprietary SDK and BOM data

Timeline of Midnight Blizzard (GTG-20006) Used Claude AI Agents to

  • Start of the activity window Anthropic identifies and later discloses for GTG-20006 (Midnight Blizzard), covering Claude-orchestrated malware evasion, drone SDK reverse-engineering, and WhatsApp takeover operations.
  • Microsoft assesses AI-augmented device-code/OAuth-code phishing operations tied to this activity begin, predating the DNS/HTTP traffic-manipulation phase of CaptiveCrunch.
  • IP 107.189.26.194, later used as a ChocoShell C2/DNS resolver node, is first observed in Microsoft's telemetry.
  • IP 104.194.159.150, used for adversary-in-the-middle phishing infrastructure, is first observed.
  • Doppelganger domain ms365-live.com, used for device-code-flow redirects, is first observed; DNS/HTTP traffic manipulation across compromised hospitality captive portals escalates through early May 2026 (CaptiveCrunch).
  • IP 213.145.86.112 (ChocoShell C2) and IP 38.146.28.75 (AitM infrastructure) are first observed.
  • CornFlake RAT sample (SHA-256 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593) first observed in the wild.
  • ChocoShell infostealer sample (SHA-256 be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c) first observed.
  • Abuse of the Microsoft Entra ID device-code authentication flow is integrated into the CaptiveCrunch attack chain; domain owa-ms365.com first observed.
  • Security firm ReliaQuest publishes initial public research on the hotel Wi-Fi traffic-manipulation activity; domain ms365-device.com first observed.
  • Microsoft Threat Intelligence publishes its CaptiveCrunch analysis, attributing the campaign to Storm-2945, a Midnight Blizzard initial-access sub-cluster, and details the CornFlake/ChocoShell/FruitStone toolset.
  • Anthropic's tracked disruption window for GTG-20006's Claude misuse closes (December 2025 - August 2026); Anthropic disables associated accounts and hardens safeguards.
  • Anthropic publishes "Detecting and countering misuse of AI: September 2026," publicly disclosing GTG-20006's AI-orchestrated malware evasion loop, WhatsApp companion-device takeovers, and drone-vision SDK reverse-engineering; The Record, SecurityWeek, Rappler, and other outlets report the disclosure the same day.

Sources cited for Midnight Blizzard (GTG-20006) Used Claude AI Agents to

More in apt

Detection coverage for TL-2026-2446

As of 2026-09-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2446 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats