Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
AI Summary
Russian state-sponsored threat actor GTG-20006, linked to APT29 (Cozy Bear), has been using AI platform Claude to automate the rebuilding of malware upon detection, enabling evasion of static security defenses. The group targets Ukrainian and European government, diplomatic, defense, and U.S. foreign policy-related entities through a multi-platform toolkit including Windows, Android, and iOS malware delivered via phishing, DNS hijacking, and ClickFix lures. The actor abuses AI to dynamically modify malware, register domains, manage infrastructure, and monitor command-and-control channels, while also exploiting stolen data from compromised hotel Wi-Fi systems and surveillance platforms to identify and target high-value individuals.
AI-extracted · verify before operational use