Threat reportAPTTL-2026-3117
Midnight Blizzard-Linked GTG-20006 Uses Claude Agents to Rebuild and Redeploy Detected Malware (CornFlake Go Backdoor, ChocoShell PowerShell Stager) via CaptiveCrunch and Device-Code Phishing
Midnight Blizzard-Linked GTG-20006 Uses Claude Agents to (TL-2026-3117), also tracked as CaptiveCrunch (related Microsoft-documented campaign), is a high-severity advanced persistent threat campaign, first published 2026-10-09. It is attributed to GTG-20006 (Russia) with medium confidence, affects Microsoft Microsoft 365 / Entra ID (OAuth device authorization grant), maps to 18 MITRE ATT&CK techniques (T1027, T1056.001, T1059.001), and is covered by 9 detection rules and 32 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 1GTG-20006
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 32Indicators of compromise
Key facts for TL-2026-3117
- Threat ID
- TL-2026-3117
- Also known as
- CaptiveCrunch (related Microsoft-documented campaign), Embassy Kit campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- GTG-20006
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, defense, diplomatic, intelligence, think tanks, drone-manufacturing, hospitality, maritime
- Target regions
- ukraine, Europe, North Africa, Middle East, Southeast Asia
- Detection rules
- 9
- Indicators of compromise
- 32
Malware and tooling in Midnight Blizzard-Linked GTG-20006 Uses Claude Agents to
Malware and tooling: ChocoShell, CornFlake, Embassy Kit
How Midnight Blizzard-Linked GTG-20006 Uses Claude Agents to works
Anthropic (Sept 2026) and ReversingLabs (Oct 2026) describe GTG-20006, a Russian-speaking espionage operator consistent with Midnight Blizzard, that used Claude-driven agents to detect when implants were flagged by security products, then modify, rebuild and redeploy them. ReversingLabs observed the Go backdoor on July 6 and the PowerShell stager on July 10, 2026, ahead of the public report.
GTG-20006 is a Russian-speaking, state-nexus espionage operator that Anthropic assesses as consistent with public reporting on Midnight Blizzard. Anthropic disrupted its Claude use between December 2025 and August 2026 and published details on September 10, 2026. The operator targeted 20+ organizations: Ukrainian and European government, military, diplomatic, defense and intelligence bodies, think tanks, drone manufacturers and supply-chain firms, and a North African government technology authority. Anthropic also names Southeast Asian maritime agencies and hospitality vendors used as a compromise vector.
The headline TTP is an AI-driven evasion loop: deploy artifact, monitor security-product detection, modify and rebuild the detected tool, test the new artifact, stage it on disposable infrastructure, redeploy. Anthropic states that when monitoring agents saw deployed malware detected by a security product, agents autonomously modified and rebuilt it and kept iterating until it went undetected. Human operators kept oversight. Claude was also used to fingerprint email and remote-access systems across 20+ Ukrainian government organizations, build phishing infrastructure, automate domain registration and hosting, run commands, organize stolen data, and automate registration of actor-controlled devices into victim tenants.
Initial access combined several methods. (1) Device-code phishing through the actor's 'Embassy Kit' framework, which abuses the OAuth 2.0 device authorization grant to steal Microsoft 365 tokens, with mailbox access and exfiltration from 8+ organizations, including a national prosecutor's office, a military education institute and an intergovernmental organization. (2) Compromise of at least three hospitality vendors operating hotel guest Wi-Fi, using stolen admin credentials to alter DNS records so guests were redirected to actor infrastructure and served ClickFix-style lures that delivered Windows, Android and iOS malware. Microsoft documented this method in July 2026 as CaptiveCrunch (Storm-2945 sub-cluster of Midnight Blizzard). (3) Fake update-themed lures delivering Windows credential stealers, with companion payloads that froze victim security updates. Other reported activity: WhatsApp account takeover via headless browsers registering the victim as a companion device using WPPConnect with read receipts suppressed, camera-streaming API authorization flaws, and a North African government intrusion (VPN credential theft, central account server takeover, 300,000+ national identity records and 500,000+ company registry records stolen).
Toolset named by Anthropic: Windows implants PowerChrome, WUEngine, Shadow C2, MiniPlasma and CloudSyncSvc; Android RAT GiftDrop (rebranded GiftsExpress); iOS exploit chain DarkSword; a browser password-store stealer; the Embassy Kit phishing platform; and an administrative console. Zscaler's CaptiveCrunch analysis describes CornFlake (Go RAT with service, Run key and scheduled-task persistence, SYSTEM token impersonation, VSS abuse and Defender signature lock) and ChocoShell (PowerShell stealer with AMSI bypass via .NET reflection, UAC bypass, and browser and M365/Azure AD token theft). The two SHA-256 hashes published by Anthropic match those Zscaler assigns to CornFlake and ChocoShell. ReversingLabs' independent description matches this pairing: a Go backdoor installed as a fake Windows service, injecting into processes and exfiltrating browser and Teams data (first seen July 6), and a PowerShell stager that hides its window, decodes and runs hidden code, collects browser history with Empire/PowerSploit modules and beacons to a staging server (first seen July 10). RL found 5 stager builds with different hashes between July 9 and August 3, 7 further malicious files through behavioral hunting, 8 URLs, 2 domain-to-server connections, and later classified 61 domains malicious; both samples were classified malicious on August 1. The RL hash and domain lists are not published in its article text.
Defensive implication: hash and signature blocking is quickly invalidated by the rebuild loop, so detection should be behavioral and capability-based. That means identity telemetry (device-code sign-ins, new device registrations, unfamiliar app IDs, refresh-token use from new infrastructure), endpoint chains (browser-to-shell execution, new services, credential-store access, repeated similar executions after quarantine), network signals (first-seen domains, encrypted egress from unusual processes, DNS changes on hospitality or captive-portal infrastructure) and data-access signals (mailbox export, bulk Graph API requests). Retro-hunt vendor reports against historical telemetry as soon as they are released.
MITRE ATT&CK techniques used in TL-2026-3117
Defense Evasion
T1027 Obfuscated Files or Information
Credential Access
T1056.001 Keylogging; T1528 Steal Application Access Token; T1555.003 Credentials from Web Browsers
Execution
T1059.001 PowerShell; T1204.004 Malicious Copy and Paste
Command and Control
Initial Access
T1078.004 Cloud Accounts; T1566.002 Spearphishing Link
Persistence
T1098.005 Device Registration; T1543.003 Windows Service
Collection
T1113 Screen Capture; T1114.002 Remote Email Collection
lateral-movement
T1550.001 Application Access Token
Resource Development
T1583.001 Domains; T1584.002 DNS Server
Reconnaissance
T1595.002 Vulnerability Scanning
defense-impairment
Affected products and versions in Midnight Blizzard-Linked GTG-20006 Uses Claude Agents to
- Microsoft — Microsoft 365 / Entra ID (OAuth device authorization grant)
Vulnerable versions: Tenants permitting device-code flow - Microsoft — Windows (CornFlake/ChocoShell targets)
Vulnerable versions: Not specified in sources - Google — Android (GiftDrop / GiftsExpress)
Vulnerable versions: Not specified in sources - Apple — iOS (DarkSword exploit chain)
Vulnerable versions: Not specified in sources - Various — Hotel guest Wi-Fi / captive portal vendors (DNS records altered)
Vulnerable versions: Three hospitality vendors compromised
Remediation for Midnight Blizzard-Linked GTG-20006 Uses Claude Agents to
Immediate actions
- Retro-hunt the published domains, IPs, hashes and filenames against historical DNS, proxy, EDR and email telemetry
- Review Entra ID sign-in logs for device-code flow authentications and revoke refresh tokens and unfamiliar device registrations
- Audit Microsoft Graph and Exchange logs for bulk mailbox access and mailbox exports
- Hunt for services or scheduled tasks created by unsigned binaries such as WUEngine.exe, DiagHost.exe or msedgeupdate*.exe outside normal Edge update paths
Workarounds
- Avoid hotel and captive-portal Wi-Fi for sensitive work without a trusted VPN
- Restrict PowerShell execution via Constrained Language Mode and AMSI logging
- Disable WhatsApp companion-device linking prompts for high-risk users and review linked devices regularly
Longer-term hardening
- Build behavioral, capability-based detections instead of relying on hash blocks, since artifacts are rebuilt after detection
- Block or conditionally restrict the OAuth device-code flow with Conditional Access for users who do not need it
- Alert on repeated similar executions after a quarantine event as a sign of rebuild and redeploy
- Force managed endpoints to establish VPN before reaching sensitive services when travelling; train staff on ClickFix paste-and-run lures
- Treat infrastructure reputation as supplementary and enrich it with file-to-domain relationships
Timeline of Midnight Blizzard-Linked GTG-20006 Uses Claude Agents to
- Start of the GTG-20006 activity window that Anthropic later disrupted (December 2025 through August 2026).
- ReversingLabs first observes the Go backdoor (fake Windows service, process injection, browser and Teams data exfiltration).
- ReversingLabs first observes the PowerShell stager; 5 builds with different hashes appear between July 9 and August 3, consistent with the rebuild loop.
- Microsoft discloses the CaptiveCrunch hotel Wi-Fi campaign (Storm-2945, Midnight Blizzard sub-cluster); Zscaler publishes analysis of CornFlake and ChocoShell.
- ReversingLabs classifies both the Go backdoor and PowerShell stager as malicious.
- End of the August 2026 activity window; operations disrupted by Anthropic.
- Anthropic publishes its September 2026 threat intelligence report attributing GTG-20006 as consistent with Midnight Blizzard and describing the AI malware rebuild loop.
- ReversingLabs publishes its retrospective showing it detected the activity about two months before Anthropic's report, and that 61 domains were later classified malicious.
Sources cited for Midnight Blizzard-Linked GTG-20006 Uses Claude Agents to
- What ReversingLabs Found Before Anthropic's Midnight Blizzard Report
- Anthropic: Countering misuse of AI: September 2026
- Zscaler: CaptiveCrunch - Midnight Blizzard weaponizes hotel Wi-Fi captive portals
- The Hacker News: Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
- Hive Security: When Malware Rebuilds Itself - Defending Against GTG-20006's AI Evasion Loop
- Aegis AI: Midnight Blizzard-Linked Actor GTG-20006 Automated Device Code Phishing With AI
- Mallory: Midnight Blizzard Used Claude Agents to Automate Malware Evasion
- DEV Community: Anthropic Report - AI Automates Malware Reconstruction, Large-Scale Secret Discovery, and Compromise
- Publish TI-20260914-001: Midnight Blizzard AI-automated malware evasion cycle (PR #37)
Detection coverage for TL-2026-3117
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3117 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.