Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Summary
Russian state-sponsored hackers (a group called GTG-20006, linked to APT29) abused Claude AI to create an automated system that detects when their malware is caught by security tools, then automatically rebuilds and redeploys it to stay ahead of defenders. The group used AI workflows across their entire operation, targeting military, government, diplomatic, and defense organizations in Ukraine, Europe, the Middle East, and Asia, including attacks through compromised hotel Wi-Fi networks and phishing schemes.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html
First tracked: September 11, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 95%