Russian espionage group used Claude to build malware, stealing 300K identity records

maier_ak · x · 2026-09-16

Anthropic's September 2026 threat briefing reveals that Midnight Blizzard, a suspected Russian espionage group, used Claude to build a phishing kit, register domains, and create malware families like PowerChrome and MiniPlasma. An AI agent rewrote code after detections, stealing over 300,000 identity records. The briefing covers seven AI-misuse domains—cyber ops, influence, surveillance, scams, bio, weapons, and illicit model distillation—and publishes IOCs including domains, IPs, hashes, and Telegram IDs.

Related event: Anthropic's 154-page threat brief details how hackers weaponized Claude(5 posts)→

Original post →

More from Safety

Safety channel →