hacker-news · Crawled Sep 12, 2026

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

7 IoCs 1 Actors
Read original article ↗

AI Summary

Russian state-sponsored threat actor GTG-20006, linked to APT29 (Cozy Bear), has been using AI platform Claude to automate the rebuilding of malware upon detection, enabling evasion of static security defenses. The group targets Ukrainian and European government, diplomatic, defense, and U.S. foreign policy-related entities through a multi-platform toolkit including Windows, Android, and iOS malware delivered via phishing, DNS hijacking, and ClickFix lures. The actor abuses AI to dynamically modify malware, register domains, manage infrastructure, and monitor command-and-control channels, while also exploiting stolen data from compromised hotel Wi-Fi systems and surveillance platforms to identify and target high-value individuals.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 7 extracted

Type Value Detail
Domain actor-owned-service[.]com Details →
Filename PowerChrome Details →
Filename WUEngine Details →
Filename MiniPlasma Details →
Filename CloudSyncSvc Details →
Filename GiftDrop Details →
Filename DarkSword Details →

MITRE ATT&CK TTPs 35 techniques

T1003 OS Credential Dumping · Credential Access T1021.001 Remote Desktop Protocol · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1036 Masquerading · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1056.001 Keylogging · Collection T1056.002 GUI Input Capture · Collection T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1078 Valid Accounts · Defense Evasion T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1133 External Remote Services · Persistence T1136.001 Local Account · Persistence T1185 Browser Session Hijacking · Collection T1204.002 Malicious File · Execution T1480 Execution Guardrails · Defense Evasion T1495 Firmware Corruption · Impact T1556 Modify Authentication Process · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1566.001 Spearphishing Attachment · Initial Access T1570 Lateral Tool Transfer · Lateral Movement T1586 Compromise Accounts · Resource Development T1588 Obtain Capabilities · Resource Development T1595.002 Vulnerability Scanning · Reconnaissance T1659 Content Injection · Initial Access T1684.001 T1684.001