01
GTG-20006 · Midnight Blizzard nexus
Malware that rebuilds itself when antivirus notices it.
A Russian-speaking operator consistent with Midnight Blizzard ran AI agents that
watched whether implants were flagged. If a security product caught them, the agents
autonomously modified, rebuilt, and restaged the toolkit until it was clean —
then pushed it from disposable servers. Anthropic’s phrase for the effect:
AI inverted the cost back onto defenders. A new signature used to buy time.
Now the loop can close faster than the patch.
PowerChrome · WUEngine · Shadow C2 · GiftDrop · DarkSword
02
Same actor · hotel supply chain
They hijacked hotel guest Wi‑Fi to hunt Ukrainian officials.
Compromised three hospitality vendors that run hotel Wi‑Fi. Changed DNS so guest
traffic flowed to attacker servers. Then staged ClickFix lures that dropped
Windows, Android, and iOS malware. Combined stolen hotel guest lists with device
data to focus on Ukrainian government staff and drone manufacturers.
Microsoft later named the method CaptiveCrunch.
03
North Africa intrusion
300,000 national IDs. Half a million companies. One VPN appliance.
Same Russian cluster stole VPN credentials from a North African government
technology authority, took over the central account server, and walked out with
the full credential database: 300k+ national identity records and the commercial
registry of more than 500,000 companies.
04
GTG-50014 · ShinyHunters
1.8 million Android apps, decompiled, hunted for secrets.
A French-speaking affiliate ran 10 AWS workers that mass-downloaded 1.8 million
distinct APKs, decompiled them, and scanned for hardcoded keys with TruffleHog.
Hits streamed live into Telegram groups with 100+ secret types. Parallel pipeline
harvested GitHub tokens. That was just the front door.
05
Smash-and-grab tempo
One stolen token to full cloud control in about three hours.
Another breach went from first access to bulk theft in hours. After a SaaS
compromise they dumped 2,100+ Azure AD token sets across 40 corporate tenants
in ~34 hours. AI agents did nearly all of the work. Operators called it
“vibe hacking”: give the model a goal, let it write and run the scripts.
06
Living off the AI land
They stole the victim’s Claude keys — then attacked the next company on the victim’s bill.
ShinyHunters affiliates treated AI credentials as loot, compute, and cover.
Stolen Anthropic API keys from customer environments funded secondary attacks
for weeks: a French retailer, a Web3 identity platform, a nonprofit.
Anthropic’s own systems were not compromised. The attacker’s compute just
quietly became someone else’s invoice. One energy-company claim in the same
cluster: they said they could remotely change the charging current of home EV chargers.
07
GTG-10007 · Changsha students
Undergraduates ran an overnight zero-day foundry.
Chinese-speaking operators, two of them Hunan undergrads (one interviewing at
QiAnXin for an offensive role), used Claude as the engineering layer of a standing
exploit program. One appliance-firmware loop produced more than a dozen possible
zero-days in a single month. Agent swarms kept campaign memory so work resumed mid-intrusion.
08
GTG-50020
Prompt-injected an AI vendor’s eval sandbox. Walked out with production keys.
A Russian actor who previously extorted hotel/fintech victims for $1.5–2.5M
injected malicious instructions into an AI vendor’s automated evaluation sandbox.
The sandbox handed over production API keys from multiple providers. Then the
actor switched their own attack traffic onto the stolen keys and hit ~30 AI
companies in four days. Goal: a pre-release Claude model. They never got it.