Detect Deepfakesby Resemble AI
Agentic AI attack

Midnight Blizzard agentic AI attack — Sep 2026

Anthropic reports that a Russian state-nexus group used AI agents to autonomously modify and rebuild malware to bypass security detection controls

Reported date
Sep 14, 2026
Target
Midnight Blizzard (Russian state-nexus group)
Agent type
Other AI agent
Agent role
Used by the attacker

The exact incident date was not established. This entry is dated by its source report.

Updated Sep 24, 2026 · 1 min read

What happened

Anthropic has reported that a cyber espionage operation, linked to the Russian state-nexus group Midnight Blizzard, utilized AI agents to enhance the effectiveness of their malware. According to the report, the threat actors employed Claude to monitor their malware for detection by security products. When a security tool flagged the malware, the AI agents were used to autonomously modify and rebuild the code. This process was repeated until the malware successfully evaded detection.

Anthropic stated that this methodology allows adversaries to "close the loop" on their operations, enabling them to bypass traditional security controls at a speed that outpaces the ability of defenders to develop and deploy countermeasures. The incident highlights a broader trend where threat actors are integrating AI capabilities into multiple stages of the attack lifecycle to automate and scale their operations.

Beyond the use of AI for malware refinement, the same actor was involved in other malicious activities. Anthropic reported that the group compromised at least three hospitality vendors that operate hotel guest Wi-Fi. Using stolen administrative credentials, the attackers performed DNS hijacking to redirect guest traffic in a campaign identified as CaptiveCrunch. Additionally, the group was observed bulk-exporting mailboxes at drone component manufacturers and stealing a complete software development kit for a drone vision system.

These findings underscore a shift in the threat landscape where the skill gap between state-sponsored actors and less sophisticated operators is narrowing. Anthropic noted that the use of AI makes diverse target environments easier to understand and adjust to, rendering the concept of "security through obscurity" increasingly ineffective. The report emphasizes that everything connected to the internet is now a potential target for AI-assisted exploitation.

Evidence in the reporting

Incident evidence
disrupted a cyber espionage operation whose tradecraft and targeting match
Agent involvement
AI agents automatically modified and rebuilt it, then redeployed it

Sources