# Midnight Blizzard-Linked GTG-20006 Uses Claude Agents to Rebuild and Redeploy Detected Malware (CornFlake Go Backdoor, ChocoShell PowerShell Stager) via CaptiveCrunch and Device-Code Phishing

> Anthropic (Sept 2026) and ReversingLabs (Oct 2026) describe GTG-20006, a Russian-speaking espionage operator consistent with Midnight Blizzard, that used Claude-driven agents to detect when implants were flagged by security products, then modify, rebuild and redeploy them. ReversingLabs observed the Go backdoor on July 6 and the PowerShell stager on July 10, 2026, ahead of the public report.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3117
- **ID:** TL-2026-3117
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** GTG-20006 (Russia)
- **Detections:** 9 · **IOCs:** 32 (full data via the Threadlinqs MCP server — Purple tier)

## Description

GTG-20006 is a Russian-speaking, state-nexus espionage operator that Anthropic assesses as consistent with public reporting on Midnight Blizzard. Anthropic disrupted its Claude use between December 2025 and August 2026 and published details on September 10, 2026. The operator targeted 20+ organizations: Ukrainian and European government, military, diplomatic, defense and intelligence bodies, think tanks, drone manufacturers and supply-chain firms, and a North African government technology authority. Anthropic also names Southeast Asian maritime agencies and hospitality vendors used as a compromise vector.

The headline TTP is an AI-driven evasion loop: deploy artifact, monitor security-product detection, modify and rebuild the detected tool, test the new artifact, stage it on disposable infrastructure, redeploy. Anthropic states that when monitoring agents saw deployed malware detected by a security product, agents autonomously modified and rebuilt it and kept iterating until it went undetected. Human operators kept oversight. Claude was also used to fingerprint email and remote-access systems across 20+ Ukrainian government organizations, build phishing infrastructure, automate domain registration and hosting, run commands, organize stolen data, and automate registration of actor-controlled devices into victim tenants.

Initial access combined several methods. (1) Device-code phishing through the actor's 'Embassy Kit' framework, which abuses the OAuth 2.0 device authorization grant to steal Microsoft 365 tokens, with mailbox access and exfiltration from 8+ organizations, including a national prosecutor's office, a military education institute and an intergovernmental organization. (2) Compromise of at least three hospitality vendors operating hotel guest Wi-Fi, using stolen admin credentials to alter DNS records so guests were redirected to actor infrastructure and served ClickFix-style lures that delivered Windows, Android and iOS malware. Microsoft documented this method in July 2026 as CaptiveCrunch (Storm-2945 sub-cluster of Midnight Blizzard). (3) Fake update-themed lures delivering Windows credential stealers, with companion payloads that froze victim security updates. Other reported activity: WhatsApp account takeover via headless browsers registering the victim as a companion device using WPPConnect with read receipts suppressed, camera-streaming API authorization flaws, and a North African government intrusion (VPN credential theft, central account server takeover, 300,000+ national identity records and 500,000+ company registry records stolen).

Toolset named by Anthropic: Windows implants PowerChrome, WUEngine, Shadow C2, MiniPlasma and CloudSyncSvc; Android RAT GiftDrop (rebranded GiftsExpress); iOS exploit chain DarkSword; a browser password-store stealer; the Embassy Kit phishing platform; and an administrative console. Zscaler's CaptiveCrunch analysis describes CornFlake (Go RAT with service, Run key and scheduled-task persistence, SYSTEM token impersonation, VSS abuse and Defender signature lock) and ChocoShell (PowerShell stealer with AMSI bypass via .NET reflection, UAC bypass, and browser and M365/Azure AD token theft). The two SHA-256 hashes published by Anthropic match those Zscaler assigns to CornFlake and ChocoShell. ReversingLabs' independent description matches this pairing: a Go backdoor installed as a fake Windows service, injecting into processes and exfiltrating browser and Teams data (first seen July 6), and a PowerShell stager that hides its window, decodes and runs hidden code, collects browser history with Empire/PowerSploit modules and beacons to a staging server (first seen July 10). RL found 5 stager builds with different hashes between July 9 and August 3, 7 further malicious files through behavioral hunting, 8 URLs, 2 domain-to-server connections, and later classified 61 domains malicious; both samples were classified malicious on August 1. The RL hash and domain lists are not published in its article text.

Defensive implication: hash and signature blocking is quickly invalidated by the rebuild loop, so detection should be behavioral and capability-based. That means identity telemetry (device-code sign-ins, new device registrations, unfamiliar app IDs, refresh-token use from new infrastructure), endpoint chains (browser-to-shell execution, new services, credential-store access, repeated similar executions after quarantine), network signals (first-seen domains, encrypted egress from unusual processes, DNS changes on hospitality or captive-portal infrastructure) and data-access signals (mailbox export, bulk Graph API requests). Retro-hunt vendor reports against historical telemetry as soon as they are released.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1583.001 Domains
- T1584.002 DNS Server
- T1566.002 Spearphishing Link
- T1078.004 Cloud Accounts
- T1204.004 Malicious Copy and Paste
- T1059.001 PowerShell
- T1543.003 Windows Service
- T1098.005 Device Registration
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1550.001 Application Access Token
- T1528 Steal Application Access Token
- T1555.003 Credentials from Web Browsers
- T1056.001 Keylogging
- T1114.002 Remote Email Collection
- T1113 Screen Capture
- T1071.001 Web Protocols

## Sources

- [What ReversingLabs Found Before Anthropic's Midnight Blizzard Report](https://www.reversinglabs.com/blog/anthropic-midnight-blizzard-what-reversinglabs-found-first)
- [Anthropic: Countering misuse of AI: September 2026](https://www.anthropic.com/threat-intelligence-report-september-2026)
- [Zscaler: CaptiveCrunch - Midnight Blizzard weaponizes hotel Wi-Fi captive portals](https://www.zscaler.com/blogs/security-research/captivecrunch-midnight-blizzard-weaponizes-hotel-wi-fi-captive-portals)
- [The Hacker News: Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection](https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html)
- [Hive Security: When Malware Rebuilds Itself - Defending Against GTG-20006's AI Evasion Loop](https://hivesecurity.gitlab.io/blog/gtg-20006-ai-malware-rebuild-detection/)
- [Aegis AI: Midnight Blizzard-Linked Actor GTG-20006 Automated Device Code Phishing With AI](https://www.aegisai.com/blog/anthropic-midnight-blizzard-ai-device-code-phishing)
- [Mallory: Midnight Blizzard Used Claude Agents to Automate Malware Evasion](https://mallory.ai/stories/01a08eaa-270f-7b86-9697-3d226718b49f)
- [DEV Community: Anthropic Report - AI Automates Malware Reconstruction, Large-Scale Secret Discovery, and Compromise](https://dev.to/anoymask/anthropic-report-ai-automates-malware-reconstruction-large-scale-secret-discovery-and-compromise-370a)
- [Publish TI-20260914-001: Midnight Blizzard AI-automated malware evasion cycle (PR #37)](https://github.com/dcollette4456/dcollette4456.github.io/pull/37)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3117
