FR
live
AI

Anthropic attributes Claude misuse to Midnight Blizzard against 20 organizations and publishes IOCs

On September 11, 2026, Anthropic published an abuse report covering December 2025 through August 2026, attributing to Midnight Blizzard the use of Claude to reverse-engineer a drone maker’s vision SDK and evade detections. The published indicators of compromise belong in your threat feed, and the report raises the bar for AI lab transparency.

A disassembled camera lens examined under a jeweler’s loupe on an electronics workbench.

September 11, 2026. Anthropic published an abuse report covering December 2025 through August 2026, attributing an espionage campaign to Midnight Blizzard — also known as APT29, BlueBravo, and Cozy Bear, tied to Russia’s SVR. The group used Claude to reverse-engineer a drone maker’s vision SDK and to evade detections. Why it matters: this is the first time a frontier model lab has published such a detailed abuse analysis, indicators of compromise included.

An infrastructure that hijacks hotel Wi-Fi

The campaign attributed to Midnight Blizzard targeted more than 20 government, intelligence, diplomatic, and defense organizations. The initial access documented by Anthropic is striking: the attackers compromised hotel Wi-Fi providers and changed DNS records to redirect travelers to attacker-controlled infrastructure. Microsoft linked this activity to Storm-2945, a sub-cluster of Midnight Blizzard.

The repeated targets were members of the Ukrainian government, military, and diplomatic staff, alongside entities in the drone supply chain. After gaining access to the mailboxes of two drone-component manufacturers, the spies targeted a military drone maker and stole a complete proprietary software development kit for a drone vision system.

Claude as a reverse-engineering and detection-loop tool

The use of Claude documented in the report goes well beyond writing phishing emails. The group used the model to reverse-engineer the drone’s vision system, reconstructing its product architecture, hardware bill of materials, supplier dependencies, and details of an unannounced product.

The second use is more structural for defenders. When their implants were flagged by security products, the attackers used Claude to identify, modify, and redeploy the detected artifacts. Anthropic’s conclusion is blunt: AI has inverted the cost back onto defenders. Where a new detection once slowed an attacker’s operational tempo, a capable adversary can now “close the loop” and bypass detections faster than defenders can deploy them.

Concretely, this means the value of a static signature is falling. An implant flagged by an antivirus can be analyzed, modified, and redeployed within hours by a language model, forcing the defense team to produce a new detection in a loop. The countermeasure can no longer be an ever-growing rule catalog: it has to rest on behavioral signals, correlations, and automated response that keep the same pace.

This echoes the Five Eyes warning from June 2026, which estimated that frontier models will exceed industry expectations and transform both offensive and defensive capabilities, on a timeline of “months, not years.”

The report’s value lies as much in what it does as in what it says. Where competing abuse disclosures often stop at a global count — a number of suspended accounts, an estimate of malicious traffic share — Anthropic ships named campaign analyses, reusable indicators of compromise, and circumstantiated attributions. For a defense team, that is the difference between a press release and actionable intelligence.

Beyond the state: criminals, students, and a hacktivist

Anthropic’s report is not limited to state espionage. Suspected affiliates of the ShinyHunters cybercriminal group used AI to scan for credentials, map unfamiliar systems, and steal data for extortion. In one case, an operator moved from a stolen developer token to full administrative access to a victim’s cloud environment in about three hours.

A Chinese-speaking group — including two operators identified as undergraduates at a Chinese university in Hunan — ran an “autonomous vulnerability research program” whose centerpiece was sustained research against a major security product, yielding several zero-days.

A French-speaking hacktivist used Claude in attacks against European political parties, media outlets, and think tanks. For Anthropic, these cases show that AI narrows the gap between state-backed groups and smaller operators by lowering the labor and expertise needed to run complex campaigns — without replacing the classic methods of phishing, stolen credentials, and software flaws.

The common thread across all these cases fits in one sentence: AI compresses time. The most expensive phase of an intrusion — understanding an unfamiliar system, adapting an implant, evading a detection — was historically what separated competent actors from amateurs. By shrinking it to a few hours, frontier models level the field, and force defenders to rebalance their priorities toward behavioral detection and automated response.

This report also raises a governance question. By publishing IOCs and detailed attributions, Anthropic sets a transparency norm that neither regulation nor the market formally requires yet. The logic mirrors antivirus vendors publishing threat analyses: credibility is earned by showing you understand what is happening on your own infrastructure. Over time, the quality of abuse reports will become a model-selection criterion on par with its benchmarks.

Verdict

Anthropic’s report is a welcome anomaly in the ecosystem: where most labs publish abuse numbers without actionable detail, this one ships IOCs and per-campaign analysis. David Agranovich, a former Russia director at the National Security Council now at Google, notes that the press will summarize the report as “Claude was used to do bad things,” overlooking that the only reason we know is because Anthropic investigated and disrupted it. If companies are not incentivized to share, they will stop.

If you defend an organization, feed the report’s IOCs into your threat intelligence and prepare your teams for an attack tempo where detections are bypassed in a loop. The investment to make is not one more tool but detection diversity and response automation.

If you build or operate a frontier model, Anthropic’s disclosure sets a transparency bar your customers will eventually demand: document abuse, ship IOCs, and cooperate with authorities rather than publishing a count with no substance.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

OpenAI launches the Agents API and turns the Codex harness into a service

OpenAI opened an Agents API in public beta on September 10, 2026, selling Codex’s backend as a service to run agents unattended for days. The same day, the company paused sign-ups for its Pro plan under GPT-6 Astra demand: the bottleneck is shifting from models to infrastructure.

Cognition ships SWE-2, a coding model post-trained from the open Kimi K3 base

Cognition released SWE-2 on September 10, a coding-agent model post-trained from Kimi K3, Moonshot AI’s open 2.8-trillion-parameter base. It approaches Fable 5.1 on coding benchmarks at a claimed 64% lower cost, but collapses on Terminal-Bench 4 — the signal that its gains do not generalize to the hardest test.

← Back to the feed

Type at least two characters.

navigate open esc dismiss