Anthropic said it disrupted a Russia-linked espionage campaign by Midnight Blizzard that used Claude to automate malware evasion across more than 20 organizations, in a report covering activity from December 2025 through August 2026. The targets included government, defense, diplomatic, intelligence, and drone-supply-chain organizations in Europe, the Middle East, and Asia.
When security products flagged an implant, the group used Claude to test, modify, rebuild, and redeploy it until it slipped past detection again. That turns what was once a slower, manual rewrite cycle into a rapid loop, so signatures and other pattern-based defenses can force a quick retooling instead of a clean stop.
For teams that lean on signature or behavior-based detection, the exposure is the attacker’s ability to keep regenerating variants faster than a fixed rule set ages out. That matters most where the target set includes government, defense, diplomatic, or drone/dual-use environments, because the same detection event can now trigger the next version of the malware.