Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi (CaptiveCrunch), and Take Over WhatsApp Accounts Against Ukrainian/European Government and Drone-Supply-Chain Targets
Midnight Blizzard (GTG-20006) Used Claude AI Agents to (TL-2026-2446), also tracked as GTG-20006, is a high-severity advanced persistent threat campaign, first published 2026-09-11. It is attributed to Midnight Blizzard (Russia) with high confidence, affects Microsoft Microsoft 365 / Microsoft Entra ID device-code, maps to 16 MITRE ATT&CK techniques (T1027, T1056.004, T1071.001), and is covered by 9 detection rules and 23 indicators of compromise.
Key facts for TL-2026-2446
- Threat ID
- TL-2026-2446
- Also known as
- GTG-20006, CaptiveCrunch
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-09-11
- Last reviewed
- 2026-09-11
- Attribution
- Midnight Blizzard
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, military, diplomatic, intelligence, think-tank, defense-industrial-base, drone-and-uas-manufacturing, hospitality, technology
- Target regions
- ukraine, Europe, Middle East, Asia, North Africa
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in Midnight Blizzard (GTG-20006) Used Claude AI Agents to
Malware and tooling: ChocoShell, CornFlake, FruitStone, WPPConnect
Anthropic's September 2026 threat intelligence report discloses that Midnight Blizzard (APT29/Cozy Bear, tracked internally as GTG-20006, operator handle "JackPoterz") ran a Claude-orchestrated closed-loop malware evasion pipeline — test against security products, autonomously modify/rebuild/redeploy from disposable infrastructure until undetected — alongside hotel Wi-Fi DNS hijacking (CaptiveCrunch, Microsoft Storm-2945), device-code phishing against Microsoft Entra ID, WhatsApp companion-device account takeover, and drone-vision SDK theft/reverse-engineering, against 20+ Ukrainian, European, Middle Eastern, Asian and North African government, military, diplomatic and drone-supply-chain targets between December 2025 and August 2026.
How Midnight Blizzard (GTG-20006) Used Claude AI Agents to works
Anthropic's "Detecting and countering misuse of AI: September 2026" report (published 2026-09-11) documents GTG-20006, an actor whose tradecraft and targeting Anthropic assesses is consistent with Russia's SVR-linked Midnight Blizzard (APT29/Cozy Bear/NOBELIUM/BlueBravo), operating under the handle "JackPoterz." Between December 2025 and August 2026, Anthropic identified and disrupted the group's use of Claude across nearly every stage of its intrusion lifecycle against more than 20 organizations spanning Ukrainian and European government ministries, defense and intelligence bodies, embassies and think tanks, with additional targeting in the Middle East, Asia, and North Africa.
The centerpiece TTP is an AI-orchestrated, closed-loop detection-evasion cycle: when a Windows or mobile implant was flagged by a security product, Claude-driven agents autonomously analyzed the detection, modified and rebuilt the malware's code, and redeployed it from disposable infrastructure, repeating the loop until the tool evaded existing signatures — compressing an evasion-development cycle that normally requires skilled malware developers into an automated, self-healing pipeline that outpaces defender response time.
Initial access into travelling officials' devices was achieved through CaptiveCrunch, a campaign independently documented by Microsoft Threat Intelligence (attributed to Storm-2945, a Midnight Blizzard initial-access sub-cluster with technical overlaps to Storm-2372) and researcher ReliaQuest. Storm-2945 compromised the shared management systems of hotel, conference-center, and airport captive-portal Wi-Fi providers and manipulated DNS/HTTP resolution to redirect guest traffic to attacker infrastructure. Two parallel abuse paths followed: (1) doppelganger domains impersonating Microsoft 365/Entra ID sign-in pages drove adversary-in-the-middle (AitM) phishing and abuse of the Entra ID device-code authentication flow — victims were induced to enter a device code into a legitimate Microsoft sign-in page, authenticating an attacker-controlled session instead; and (2) ClickFix-style fake browser/OS update prompts delivered a Windows-focused malware suite: CornFlake, a Go-based RAT (persisting as a "Cloud Sync Service" named svchost32.exe, with keylogging, clipboard/screenshot/webcam/microphone capture, browser credential theft via a ChromeKatz module, and a custom ECDH P-256-encrypted C2 protocol) and ChocoShell, an in-memory PowerShell infostealer (AMSI bypass, VM-detection, three UAC-bypass chains — SilentCleanup task hijack, wsreset.exe COM hijack, sdclt.exe folder hijack — and theft of Chromium/Firefox session cookies, Microsoft 365/Azure AD WAM tokens, and Wi-Fi credentials, beaconing over HTTPS disguised as an image-tracking pixel). Both implants were managed from FruitStone, a web-based C2 panel masquerading as a "CloudSync Console" SaaS product.
Beyond CaptiveCrunch, GTG-20006 hijacked the WhatsApp accounts of at least two former high-level Ukrainian officials by linking attacker-controlled headless browsers as companion devices (leveraging the WPPConnect automation library) and suppressing read receipts to silently export conversation history. The group also compromised the mailboxes of at least two drone-component manufacturers and used Claude to reverse-engineer a stolen proprietary drone-vision SDK, recovering product architecture, hardware bills of materials, and supplier dependencies. Separately, the actor exploited an authorization flaw in a camera-streaming service to steal stream-access tokens, and breached a North African government technology authority, exfiltrating over 300,000 national identity records and 500,000 commercial-registry entries.
Anthropic disrupted the associated Claude accounts, hardened relevant safeguards, and shared indicators with government and industry partners; it published domains, IPs, and file hashes for defenders to hunt against. Anthropic's report frames the case as evidence that stolen AI API keys, agent session tokens, and AI-service integrations must be treated with the same operational sensitivity as production credentials, since AI-accelerated development loops now let attackers iterate faster than traditional signature-based defenses can respond.
MITRE ATT&CK techniques used in TL-2026-2446
Defense Evasion
T1027 Obfuscated Files or Information
Credential Access
T1056.004 Credential API Hooking; T1187 Forced Authentication; T1528 Steal Application Access Token; T1555 Credentials from Password Stores
Command and Control
T1071.001 Web Protocols; T1573.002 Asymmetric Cryptography
Collection
T1113 Screen Capture; T1114 Email Collection
Initial Access
T1195 Supply Chain Compromise; T1199 Trusted Relationship
Persistence
T1543.003 Windows Service; T1547.001 Registry Run Keys / Startup Folder
Privilege Escalation
T1548.002 Bypass User Account Control
defense-impairment
T1556 Modify Authentication Process; T1685 Disable or Modify Tools
Affected products and versions in Midnight Blizzard (GTG-20006) Used Claude AI Agents to
- Microsoft — Microsoft 365 / Microsoft Entra ID device-code authentication flow
Vulnerable versions: authentication-flow abuse; not version-specific - Multiple hospitality/venue operators — Shared hotel, conference-center, and airport captive-portal Wi-Fi management systems
Vulnerable versions: shared captive-portal management infrastructure with compromised admin credentials - WhatsApp (Meta) — WhatsApp companion-device (Linked Devices) authentication
Vulnerable versions: companion-device linking abused via headless-browser automation
Remediation for Midnight Blizzard (GTG-20006) Used Claude AI Agents to
Patches
- No vendor patch applies — this is a TTP/actor disclosure, not a software vulnerability
Immediate actions
- Block known GTG-20006/CaptiveCrunch domains (ms365-live.com, teams.ms365-live.com, m365-owa.com, owa-ms365.com, ms365-device.com) and IPs (31.57.243.154, 38.146.28.75, 38.146.28.132, 104.194.159.150, 107.189.26.194, 213.145.86.112, 104.145.210.184) at DNS/perimeter and EDR
- Disable or tightly restrict the Microsoft Entra ID device-code authentication flow for roaming/travelling users, or require additional phishing-resistant verification before it completes
- Treat hotel, conference-center, and airport captive-portal Wi-Fi as fully untrusted; require a corporate VPN with DNS-over-HTTPS before any authentication on such networks
- Hunt for the svchost32 service, %APPDATA%\svchost32\svchost32.exe, and sync.dat artifacts, and for the SHA-256 hashes of CornFlake (918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593) and ChocoShell (be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c)
- Audit WhatsApp Linked Devices on accounts belonging to high-risk personnel (government, military, diplomatic) for unrecognized companion-device sessions
Workarounds
- Disable the Entra ID device-code authentication flow tenant-wide where it is not operationally required
- Restrict WhatsApp companion-device linking to admin-approved enrollment where supported by mobile device management
Longer-term hardening
- Deploy EDR with behavioral detection tuned to AMSI-bypass, UAC-bypass (SilentCleanup/wsreset.exe/sdclt.exe hijacks), and Chrome App-Bound Encryption bypass techniques
- Treat AI API keys, agent session tokens, and AI-service integrations with the same operational scrutiny as production credentials, per Anthropic's explicit guidance in this report
- Implement phishing-resistant MFA (FIDO2/passkeys) to remove exposure to device-code phishing and AitM relay attacks entirely
- Segment and monitor mailbox access for organizations in the drone/UAS manufacturing supply chain given demonstrated targeting of proprietary SDK and BOM data
Timeline of Midnight Blizzard (GTG-20006) Used Claude AI Agents to
- Start of the activity window Anthropic identifies and later discloses for GTG-20006 (Midnight Blizzard), covering Claude-orchestrated malware evasion, drone SDK reverse-engineering, and WhatsApp takeover operations.
- Microsoft assesses AI-augmented device-code/OAuth-code phishing operations tied to this activity begin, predating the DNS/HTTP traffic-manipulation phase of CaptiveCrunch.
- IP 107.189.26.194, later used as a ChocoShell C2/DNS resolver node, is first observed in Microsoft's telemetry.
- IP 104.194.159.150, used for adversary-in-the-middle phishing infrastructure, is first observed.
- Doppelganger domain ms365-live.com, used for device-code-flow redirects, is first observed; DNS/HTTP traffic manipulation across compromised hospitality captive portals escalates through early May 2026 (CaptiveCrunch).
- IP 213.145.86.112 (ChocoShell C2) and IP 38.146.28.75 (AitM infrastructure) are first observed.
- CornFlake RAT sample (SHA-256 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593) first observed in the wild.
- ChocoShell infostealer sample (SHA-256 be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c) first observed.
- Abuse of the Microsoft Entra ID device-code authentication flow is integrated into the CaptiveCrunch attack chain; domain owa-ms365.com first observed.
- Security firm ReliaQuest publishes initial public research on the hotel Wi-Fi traffic-manipulation activity; domain ms365-device.com first observed.
- Microsoft Threat Intelligence publishes its CaptiveCrunch analysis, attributing the campaign to Storm-2945, a Midnight Blizzard initial-access sub-cluster, and details the CornFlake/ChocoShell/FruitStone toolset.
- Anthropic's tracked disruption window for GTG-20006's Claude misuse closes (December 2025 - August 2026); Anthropic disables associated accounts and hardens safeguards.
- Anthropic publishes "Detecting and countering misuse of AI: September 2026," publicly disclosing GTG-20006's AI-orchestrated malware evasion loop, WhatsApp companion-device takeovers, and drone-vision SDK reverse-engineering; The Record, SecurityWeek, Rappler, and other outlets report the disclosure the same day.
Sources cited for Midnight Blizzard (GTG-20006) Used Claude AI Agents to
- Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
- Anthropic disrupts Russian, Chinese AI campaigns targeting its Claude models
- Midnight Blizzard-Linked Actor Used Claude AI to Automate Malware Detection Evasion
- Countering misuse of AI: September 2026
- Detecting and countering misuse of AI: September 2026 (full report PDF)
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
- Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware
- Midnight Blizzard Used Claude Agents to Automate Malware Evasion
- Hackers Use Claude AI Agents to Automate Cyberattacks, Develop Zero-Days and Evade Detection
More in apt
- Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated Cyberattacks and Data Theft
- Iran Exploits SS7 Roaming Infrastructure and Commercial Ad-Tech to Track US Military Smartphones During Operation Epic Fury
- China-Based AI Companies Conducting Industrial-Scale Knowledge Distillation Campaigns Against U.S. Frontier AI Models
- China-Nexus and India-Nexus Espionage Groups Converge on Pakistani Law Enforcement Digitalization Platforms ("One Target, Two Flags")
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign
Detection coverage for TL-2026-2446
As of 2026-09-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2446 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.