Cyber operations · GTG-20006
AI-assisted cyber espionage: the GTG-20006 case
This page is a translation of content from pages 6–11 of Anthropic's September 2026 report. Actor attribution and scale figures come from that report; this site has not independently verified all real-world outcomes.
According to Anthropic's September 2026 report, GTG-20006 is a cyber espionage actor who uses AI to automate operations and gain speed. Anthropic says its attribution is consistent with public reporting linking the actor to Midnight Blizzard. The actor used a custom toolkit including two types of Windows implants, a mobile exploitation suite, a credential stealer targeting browser password vaults, a phishing platform designed to impersonate priority targets such as government organizations, and a management console for controlling compromised accounts. The report observed that GTG-20006 automated most of its operations — from development, infrastructure acquisition, phishing, command-and-control persistence, to data exfiltration — through customized AI-driven workflows.
What happened
Historically, cyber espionage actors follow a pattern: they develop and deploy custom toolkits designed to evade detection. They use these tools until defenders identify and build signatures to detect and block them, then begin a new cycle of evasion and detection. Strong defenses and detection therefore raise the adversary's cost. Now, however, the adoption of AI may quickly and easily undermine defenders' ability to impose costs on adversaries through static detection alone.
GTG-20006 is an actor who uses AI to automate operations and gain speed. Our attribution is consistent with public reporting linking the actor to Midnight Blizzard. One operator is a Russian speaker using the handle 'JackPoterz,' whose tradecraft and target selection align with Russian state-linked espionage. They operated against military intelligence targets of Ukrainian and European governments, as well as diplomatic and defense organizations and individuals tied to U.S. foreign policy. We observed GTG-20006 operating through customized AI-driven workflows that automated most of its operations — from development, infrastructure acquisition, phishing, command-and-control persistence, to data exfiltration.
GTG-20006 used a custom toolkit consisting of two types of Windows implants, a mobile exploitation suite, a credential stealer targeting browser password vaults, a phishing platform designed to impersonate priority targets such as government organizations, and a management console for controlling compromised accounts. During cyber operations, each of these tools was managed and adapted on demand through AI-assisted workflows.
The actor also used AI to monitor how well its tools evaded known security defenses. If its monitoring AI agent found that any deployed malware was detected by security products, the agent would begin autonomously modifying and rebuilding the malware to evade existing detection. These agents were designed to continuously iterate GTG-20006's toolkit until it went undetected. At that point, the tools were deployed to throwaway hosting servers for live operations, and across multiple cyber operations — including phishing, ClickFix, and DNS hijacking schemes — victim traffic was directed to these servers to deliver malware.
What AI did
The actor also used AI to drive its phishing operations. They developed AI-driven workflows to research and register domain names, then configure hosting infrastructure for sending phishing emails. Additional workflows were developed to send emails and monitor command-and-control channels to confirm successful intrusions. The human actor was mainly involved in modifying the Claude Code skills that drove the workflows, optimizing them when needed.
The actor used AI at every stage of its operations:
Reconnaissance: the actor used AI to identify characteristics of email and remote access systems and collect information from public sources to build target lists for phishing.
Initial access: the actor used AI to build and operate the platforms running these intrusion campaigns. The primary access technique was a form of device-code phishing that abused the legitimate login flow of cloud email services. The actor used AI to set up phishing infrastructure and exploitation tools, and directly executed some intrusions under its direction — including running commands on victim systems, collecting credentials, and moving laterally across networks.
Collection and exfiltration: the actor used AI to extract and organize hundreds of gigabytes of stolen data. In some cases, exfiltration was done through bulk exports from compromised mailboxes.
Maintaining access: the actor used AI to help maintain access to compromised accounts and tenants by automatically registering actor-controlled devices as companion devices in the victim organization's tenant.
In on-premises environments, the actor used AI to monitor the stealth and persistence of its implants. When implants were flagged by security products, the actor used Claude to systematically identify, modify, and redeploy the detected components.
The result is that AI shifts costs back onto defenders. In the past, defenders might have been able to slow an attacker's pace by deploying new detections. Now, at least in theory, capable adversaries can 'close the loop' and bypass traditional security detections faster than defenders can develop and deploy them.
What the report observed
Our investigation identified more than 20 distinct organizations appearing in the actor's operation planning, reconnaissance, and actual operations. These include government departments, defense and intelligence agencies, embassies and diplomatic missions, think tanks, and defense industry companies — concentrated in Ukraine and Europe, but extending to maritime-related government agencies in the Middle East and Asia. A common theme among targets was Ukraine and military drone technology suppliers and supply chains. Exceptions include a Southeast Asian government entity related to maritime transport and tracking, and a North African government technology authority.
The most repeatedly targeted were Ukrainian government, military, and diplomatic personnel. The actor scanned the email services and remote access systems of more than two dozen Ukrainian government organizations.
A second repeatedly stolen target was drone supply chain technology. The actor bulk-exported mailboxes from at least two drone component manufacturers, targeted a military drone manufacturer, and stole the complete proprietary software development kit for a drone vision system. They spent days reverse-engineering the drone's vision system, recovering its product architecture, hardware bill of materials, supplier dependencies, and details of an unreleased product. Military drone control and AI vision-related firmware appeared to be of particular interest.
Not all targets were direct: to reach targets indirectly, the actor compromised at least three hotel WiFi providers operating guest room WiFi. They used compromised admin credentials to modify DNS records to point to actor-owned services (a technique known as DNS hijacking). When hotel guests using the compromised providers connected to hotel WiFi, their traffic, device identifiers, and IP addresses were sent to the actor's servers. At that point, ClickFix-style lures were deployed to deliver Windows, Android, and iOS malware to victim devices. The actor was able to combine guest information stolen from hotel management systems with data stolen from individual guest devices to focus further targeting operations. Targets of particular interest were individuals with Ukrainian ties, including government officials and drone manufacturers. Note that in July 2026, Microsoft Threat Intelligence published a report on the theft and malware delivery methods used here, which they call CaptiveCrunch.
The actor also took over victims' WhatsApp accounts, using a headless browser platform to link victim accounts as companion devices. Partly through use of the WPPConnect open-source WhatsApp automation library, the actor's configuration suppressed read receipts so victims would not notice their Russian- and Ukrainian-language conversations being bulk-exported. At least two former senior Ukrainian officials were targeted this way.
The actor also targeted surveillance platforms. They discovered an authorization vulnerability in a camera streaming service's application programming interface, and from there enumerated users and collected tokens to gain access to victims' live camera streams.
The same actor also compromised a North African government technology authority. They stole credentials for a VPN device and used them to take over the organization's central account server. This allowed them to exfiltrate its complete credential database: more than 300,000 national ID records, plus business registration data for more than 500,000 companies operating in the country.
The actor continued developing a cloud email espionage platform, operated in part using 'Embassy Kit' — a framework the actor used to manage device-code phishing — to run a Microsoft 365 token theft campaign. The platform was used to target diplomatic and government personnel, resulting in email records from at least 8 organizations being accessed and exfiltrated, including a national prosecution body, a military educational institution, and a regional intergovernmental organization.
The Windows credential stealer was delivered via social engineering lures themed around fake updates, accompanied by companion payloads with full remote access capabilities. These payloads were designed to freeze security updates on victim machines, meaning new malware detection signatures released by security vendors would not be fetched or run on victim machines.
The actor's malware includes: Windows malware: PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc; Android malware: GiftDrop, a rebranded GiftsExpress Android surveillance remote access trojan; iOS malware: DarkSword, an iOS exploit chain.
The report lists related indicators of compromise (domains, IPs, file names, and hashes) at the end for defenders to investigate. Per this site's safety boundaries, specific indicator values are not reproduced.

Confirmed & unknown
Confirmed
- The report says attribution is consistent with public reporting linking the actor to Midnight Blizzard
- More than 20 organizations appeared in its operation planning, reconnaissance, or actual operations (per the report)
- AI was used across multiple stages: reconnaissance, intrusion execution, data processing, and maintaining access; when malware was detected by security products, AI agents automatically modified and rebuilt it
- The report confirms the complete proprietary software development kit for a drone vision system was stolen
Unknown
- The report does not estimate the total volume of data stolen in this case
- The number of hotel guests actually affected by the WiFi intrusions is not stated
- Whether the stolen drone technology was subsequently used is not assessed
- Notification and remediation progress at affected organizations, and whether the actor faced legal consequences, are not stated
Platform response
The report states that for each case in this chapter, including this one, Anthropic disrupted the related activity, strengthened AI protections based on investigation findings, and shared intelligence with law enforcement and industry partners where appropriate.
Limits of response:Disrupting related access and activity does not mean stolen data was recovered; the report does not describe post-incident remediation at affected organizations, and it is unknown whether the actor was identified or faced legal consequences.
Takeaways
- For organizations: relying solely on signature-based detection is insufficient against tools that automatically rewrite themselves; defense in depth is needed — behavior detection, least privilege, and anomalous login alerts.
- For individuals: be wary of any 'login anomaly' prompt asking for account credentials; enable two-factor authentication on important accounts; people in sensitive sectors should be aware of risks from public WiFi such as hotel networks.