Anthropic disrupted a cyberespionage operation whose tradecraft and targeting match the Russian state-nexus group tracked as Midnight Blizzard, the company said in a threat intelligence report published this week.

The report covers activity the company identified and shut down between December 2025 and August 2026.

According to Anthropic, Midnight Blizzard used Claude to monitor how well its malware evaded detection by security products. When a tool was flagged, AI agents automatically modified and rebuilt it, then redeployed it, repeating the process until the malware went undetected again.

Anthropic said this shifts the cost of the detection-evasion cycle back onto defenders. Historically, new detection signatures forced attackers into a slower, manual cycle of rewriting tools. The company said AI now lets capable actors “close the loop” faster than defenders can respond.

The Russia-linked hackers targeted more than 20 organizations, according to the report. Victims included Ukrainian and European government ministries, defense and intelligence bodies, embassies, and think tanks, with additional targeting extending to the Middle East and Asia.