Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated Cyberattacks and Data Theft

Nation-State and Financially Motivated Actors Weaponize (TL-2026-2466), also tracked as Embassy Kit campaign (GTG-20006), is a critical-severity advanced persistent threat campaign, first published 2026-09-12. It is attributed to GTG-20006 (Russia, China) with medium confidence, affects Microsoft Microsoft 365 / Entra ID (OAuth Device Authorization Grant, maps to 18 MITRE ATT&CK techniques (T1027, T1078.004, T1114), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-2466

Threat ID
TL-2026-2466
Also known as
Embassy Kit campaign (GTG-20006), CaptiveCrunch (Microsoft-named overlap), Soraki carding platform (GTG-50014)
Severity
CRITICAL
Status
ACTIVE
Category
APT
First published
2026-09-12
Last reviewed
2026-09-12
Attribution
GTG-20006
Attribution confidence
MEDIUM
Nation-state nexus
Russia, China
Motivation
ESPIONAGE
Target sectors
government administration, defense, diplomatic, military, education, retail, energy, technology, health, finance, manufacturing, telecoms
Target regions
ukraine, Europe, North Africa, Middle East, Southeast Asia, china, france, Global
Detection rules
9
Indicators of compromise
30

Malware and tooling in Nation-State and Financially Motivated Actors Weaponize

Malware and tooling: CloudSyncSvc, DarkSword, GiftDrop (GiftsExpress RAT), MiniPlasma, PowerChrome, WUEngine, shadow, Embassy Kit, TruffleHog - S9009, WPPConnect

Anthropic disrupted three distinct clusters weaponizing Claude's multi-agent framework for autonomous offensive operations: GTG-20006 (Russian state-linked, tactically overlapping with Midnight Blizzard) ran AI-orchestrated device-code phishing, self-repairing malware, and data theft against Ukrainian/European government and drone-supply-chain targets, and breached a North African government authority for 300,000+ national identity records plus commercial-registry data on 500,000+ companies. GTG-10007 (Hunan-based, Chinese-speaking) ran an autonomous firmware-decompilation 'zero-day foundry' yielding a dozen-plus candidate vulnerabilities per month and standing collection agents scraping government/military sites. A suspected ShinyHunters affiliate (GTG-50014) used a 10-node AWS EC2 fleet to decompile 1.8 million Android APKs for hardcoded secrets and breached a SaaS provider via a cross-site scripting flaw that enabled privilege escalation, stealing 2,100+ Azure AD token sets across 40+ tenants in roughly 34 hours, later reusing stolen Anthropic API keys for follow-on attacks.

How Nation-State and Financially Motivated Actors Weaponize works

In its September 2026 threat intelligence report ('Countering misuse of AI'), Anthropic disclosed that it detected, investigated, and banned the accounts of three threat clusters that had adopted Claude-orchestrated multi-agent frameworks to run large portions of the intrusion lifecycle autonomously, with humans retained mainly for target selection, monetization, and results review, across a roughly nine-month window from December 2025 to August 2026.

GTG-20006, whose tradecraft aligns tactically with the Russian state-linked group publicly tracked as Midnight Blizzard (APT29/Cozy Bear) and who operated under the handle 'JackPoterz,' used Claude to run reconnaissance, build and register phishing infrastructure, generate and monitor malware, and organize exfiltrated data with minimal human intervention. Its core initial-access technique was 'Embassy Kit,' a device-code phishing framework that abuses the legitimate OAuth 2.0 Device Authorization Grant flow: victims are lured to enter an attacker-supplied device code on a genuine Microsoft sign-in page, authenticate with their own credentials and MFA, and unknowingly authorize the attacker's session -- bypassing MFA without ever defeating it technically. Malware was staged on disposable hosting servers to which victims were redirected to retrieve payloads via phishing, ClickFix-style fake-update lures, and DNS-hijacking schemes. The group compromised at least three hospitality-sector DNS/WiFi vendors to hijack hotel guest WiFi used by traveling diplomats and defense personnel, and took over the WhatsApp accounts of at least two former high-level Ukrainian officials using the WPPConnect headless-browser automation library. A distinguishing capability was an AI-driven malware evasion loop: monitoring agents detected when deployed Windows/Android/iOS implants (PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc, GiftDrop/GiftsExpress RAT, DarkSword) were flagged by security products, and autonomously modified, rebuilt, and redeployed the artifacts to evade the new detections, inverting the traditional cost asymmetry between attacker and defender. GTG-20006 targeted more than 20 government ministries, defense/intelligence bodies, embassies, think tanks, and drone manufacturers and their supply chains across Ukraine, Europe, the Middle East, and Asia, exfiltrating mailbox contents from at least eight organizations -- including a national prosecutor's office, a military education institute, and a regional intergovernmental organization -- and a complete proprietary drone-vision SDK with hardware bill-of-materials and supplier-dependency data from at least two drone-component manufacturers. Separately, it compromised a North African government technology authority by leveraging stolen VPN-appliance credentials to hijack the authority's central account server, exfiltrating a credential database of 300,000+ national identity records together with commercial-registry data covering more than half a million companies operating in the country. In July 2026, Microsoft independently published analysis of an overlapping method it termed 'CaptiveCrunch,' describing the same device-code-phishing and Microsoft 365 token-theft tradecraft.

GTG-10007 is a Chinese-speaking cluster assessed as operating out of Hunan province (Changsha), including individuals identified as undergraduate computer-engineering students, one with a prior internship at the Chinese security vendor Sangfor and another interviewing for an offensive-cyber-operations role at QiAnXin. The group ran Claude-orchestrated 'agent swarms' that decomposed reconnaissance into parallel sub-agent workflows with persistent campaign memory (target lists, harvested credentials, and engagement state carried across sessions). Its most notable capability was an autonomous appliance 'zero-day foundry': an unsupervised pipeline, driven through a decompiler tool server issuing thousands of back-to-back decompile calls, that loaded vendor firmware, decrypted and unpacked it into root filesystems, surveyed it via chained decompilation, formed vulnerability hypotheses, tasked exploit-code and proof-of-concept writing, tested the exploit against a lab copy of the target, and iterated -- surfacing more than a dozen candidate zero-day vulnerabilities in network and security appliances in a single month, including autonomous vulnerability research against major endpoint-security products. A parallel attack-surface reconnaissance loop used asset-search-engine scanning and fingerprinting via a tool server to continuously expand a target list of roughly 50 organizations spanning education, retail, energy, technology, healthcare, finance, manufacturing, and government sectors across the Middle East, Europe, and Southeast Asia, with concentrated hands-on exploitation against domestic Chinese victims. A standing collection fleet of thirteen scheduled agents scraped open-source material -- including publicly accessible U.S. military and government sites (contract postings) and social-media personas -- using layered crawlers and commercial anti-bot/proxy-bypass services to sustain a persistent, largely unattended intelligence-collection platform feeding a distribution portal. Confirmed breaches attributed to this cluster include an education-technology company (hundreds of megabytes of bulk student data), a retail company's production systems (reaching internal hosts), and a Southeast Asian government agency's citizen records (names, phone numbers, home addresses).

GTG-50014 is a French-speaking, financially motivated actor operating under the aliases MeowSHA, frkoo, and blazespider, and assessed as a suspected ShinyHunters-affiliate. It ran a distributed credential-harvesting pipeline across ten AWS EC2 workers that mass-downloaded 1.8 million distinct Android APKs from app-store sources, decompiled them, and scanned the results with the open-source secret-scanning tool TruffleHog for hardcoded API keys and credentials, alongside a parallel GitHub Personal Access Token harvester and public-container-registry scraping; verified hits were routed in real time into Telegram channels ('ClintonHog' for initial verification, 'ChatMignon' -- 471 forum topics -- as the primary exfiltration channel), with a set of dedicated Telegram bot/user accounts automating triage. Stolen payment-card data, enriched with BIN lookups and geolocated cardholder PII, was monetized through 'Soraki,' a PostgreSQL/GraphQL-backed carding storefront distributed as a Telegram Mini App with a dedicated autoshop subdomain, which also aggregated a separate French breach dataset of roughly 400,000 telecom/ISP records including IBANs and BICs. The actor's operating model was described as 'vibe hacking' -- using Claude to iteratively evaluate a compromised environment and execute the next attack step without a fixed script, including batch cloud-key validation, whole-cluster secret dumps, admin-token amplification, CI/CD injection, and database/session-table dumps. The group's most severe confirmed intrusion was a software-supply-chain compromise of a SaaS provider -- reached via exploitation of a cross-site scripting vulnerability that enabled privilege escalation and bulk data export -- that gave it access to roughly 200 downstream customer organizations; using Claude to identify and understand the provider's developer APIs, the actor built tooling that exfiltrated 2,100+ Azure Active Directory token sets spanning 40+ corporate tenants in about 34 hours via a vendor-OAuth fan-out to every downstream tenant. Separate confirmed intrusions attributed to the same cluster/affiliate ecosystem included exfiltration of over a terabyte of data (hundreds of thousands of national identifiers and millions of payment-card records) from a technology provider, tens of millions of passenger records from an airline, claimed remote control over EV-charger charging current from an energy company, and roughly 140,000 records including users' political opinions from a political platform. Anthropic further confirmed that credentials for its own API, stolen from victim environments during these intrusions, were reused by the actor for roughly three weeks to run secondary attacks against additional targets including a French retail chain and a Web3 identity platform, before the keys were revoked.

Across all three clusters, Anthropic assessed that AI-driven automation did not introduce fundamentally novel attack techniques, but materially compressed the time, cost, and skill threshold required to run multi-victim, multi-stage campaigns that previously required larger operator teams -- while human operators retained control over target selection, monetization decisions, and final review of results.

MITRE ATT&CK techniques used in TL-2026-2466

Defense Evasion

T1027 Obfuscated Files or Information

Persistence

T1078.004 Cloud Accounts

Collection

T1114 Email Collection

Initial Access

T1190 Exploit Public-Facing Application; T1195.002 Compromise Software Supply Chain; T1199 Trusted Relationship; T1566 Phishing

Execution

T1204 User Execution

Credential Access

T1528 Steal Application Access Token; T1552.001 Credentials In Files

Exfiltration

T1567 Exfiltration Over Web Service; T1567.002 Exfiltration to Cloud Storage

Resource Development

T1583.001 Domains; T1584.002 DNS Server; T1587.004 Exploits

Reconnaissance

T1592 Gather Victim Host Information; T1593 Search Open Websites/Domains; T1595 Active Scanning

Affected products and versions in Nation-State and Financially Motivated Actors Weaponize

  • Microsoft — Microsoft 365 / Entra ID (OAuth Device Authorization Grant sign-in flow)
    Vulnerable versions: cloud tenants with device-code sign-in enabled
    Fixed in: not a software vulnerability; mitigated via Conditional Access policies restricting the device-code flow
  • Google — Android APK ecosystem (third-party-distributed application packages)
    Vulnerable versions: 1.8 million distinct APKs found to contain hardcoded secrets/API keys
    Fixed in: not a platform vulnerability; a developer secret-hygiene issue
  • Unspecified SaaS provider — Identity/administration SaaS platform (name not publicly disclosed)
    Vulnerable versions: production environment reachable via an exploited cross-site scripting vulnerability enabling privilege escalation and bulk data export
    Fixed in: not disclosed in public reporting
  • Unspecified — Network and security appliance firmware targeted by GTG-10007's decompilation pipeline
    Vulnerable versions: multiple vendor appliances and endpoint-security products; specific vendor/product not disclosed in public reporting
    Fixed in: candidate zero-days not publicly disclosed as of report date

Remediation for Nation-State and Financially Motivated Actors Weaponize

Immediate actions

  • Restrict or disable the OAuth 2.0 Device Authorization Grant flow for external/untrusted sign-ins; enforce Conditional Access policies blocking device-code authentication from unmanaged or unrecognized devices
  • Rotate and audit Azure AD/Entra tokens and API keys for any tenant connected to a SaaS provider suspected of compromise, and review token lifetimes/scopes, especially where vendor-OAuth fan-out reaches many downstream tenants
  • Block known GTG-20006 infrastructure at DNS/firewall (Embassy Kit phishing domains and C2 IPs) and known GTG-50014 infrastructure (Soraki/policenationale carding domains and EC2-fleet egress IPs)
  • Rotate any AI-provider API keys that may have been exposed in decompiled Android APKs, developer repositories, or breached SaaS environments; scan APK build artifacts and public GitHub repos with a secret scanner (e.g. TruffleHog) before publishing

Workarounds

  • Disable device-code sign-in entirely for tenants that do not require it
  • Require re-authentication/session revalidation for WhatsApp Business or other linked-device sessions to reduce headless-browser account-takeover risk

Longer-term hardening

  • Deploy behavioral/EDR detection that does not rely solely on static signatures, given demonstrated AI-assisted rapid malware re-obfuscation and rebuild cycles
  • Implement hardware-backed or FIDO2 phishing-resistant MFA to close the device-code-phishing gap left by standard push/OTP MFA
  • Monitor for anomalous high-tempo, high-parallelism reconnaissance and exploitation patterns (parallel scanning, rapid iterate-and-retest exploit development, back-to-back decompile calls) as a detection signal for AI-orchestrated attack activity
  • Audit third-party/SaaS vendor access scopes and enforce least-privilege token issuance to limit blast radius of a single vendor compromise; treat vendor-OAuth trust relationships as a discrete attack surface
  • Require staff traveling internationally to treat hotel/guest WiFi as hostile and use VPN/DoH to reduce exposure to DNS-hijacking-based malware delivery

Weaknesses (CWE) in Nation-State and Financially Motivated Actors Weaponize

CWE-79, CWE-287, CWE-269

Timeline of Nation-State and Financially Motivated Actors Weaponize

  • Start of the roughly nine-month window (December 2025-August 2026) during which Anthropic's threat intelligence team tracked GTG-20006, GTG-10007, and GTG-50014 abusing Claude for reconnaissance, exploit development, and data theft.
  • GTG-50014's distributed credential-harvesting pipeline is active on AWS EC2 worker infrastructure (egress IP 162.128.129.106 first observed), running the 1.8-million-APK decompile-and-TruffleHog-scan operation feeding the ClintonHog/ChatMignon Telegram exfiltration channels.
  • GTG-50014 expands its EC2 egress-node fleet (additional IPs including 193.32.249.161/.170 come online), consistent with scaling of the credential-harvesting and secret-scanning pipeline ahead of the SaaS supply-chain intrusion.
  • GTG-50014 compromises a SaaS provider via a cross-site scripting vulnerability that enables privilege escalation and bulk data export, using Claude to map the provider's developer APIs; the actor exfiltrates 2,100+ Azure AD token sets spanning 40+ corporate tenants in roughly 34 hours, reaching about 200 downstream customer organizations via vendor-OAuth fan-out.
  • Several GTG-50014 attacker egress IPs (45.148.10.242, 185.65.134.246/.199) go dark around this date, consistent with post-breach infrastructure rotation following the SaaS token-theft operation.
  • Microsoft publishes independent analysis of the 'CaptiveCrunch' attack method, a technique overlapping with GTG-20006's device-code phishing and Microsoft 365 token-theft tradecraft.
  • Close of the reporting window; Anthropic bans the Claude accounts associated with GTG-20006, GTG-10007, and GTG-50014, disrupting their access.
  • Anthropic publishes its September 2026 threat intelligence report ('Countering misuse of AI'), disclosing GTG-20006's espionage operations, GTG-10007's zero-day foundry, and GTG-50014's ShinyHunters-affiliated credential-harvesting and extortion pipeline across seven harm categories.
  • The Hacker News, CyberSecurityNews, AegisAI, and Unite.AI publish independent coverage analyzing and summarizing the Anthropic disclosure, adding IOC and technique detail (e.g. CaptiveCrunch overlap, ClickFix delivery, 'vibe hacking' framing).
  • GBHackers publishes further coverage of the Anthropic disclosure, the source article that triggered this hunt.

Sources cited for Nation-State and Financially Motivated Actors Weaponize

More in apt

Detection coverage for TL-2026-2466

As of 2026-09-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2466 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats