Skip to content
The AI-First Web

Anthropic: one actor built AI agents to rebuild malware whenever it is flagged

Anthropic documents one actor that automated malware repair, and says others could 'at least in theory'.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Anthropic: one actor built AI agents to rebuild malware whenever it is flagged

AI-generated image for WebPulse. About our images

Key finding

Organizations in one actor's targeting: 20+ (Source: Anthropic Threat Intelligence report (September 2026))

Historically, catching an attacker's tool worked like a tax. Each detection forced the attacker to stop, rebuild and retest. That cost slowed them down. Anthropic's September threat report describes one actor who automated the payment.

What Anthropic found

Anthropic's Threat Intelligence team reviewed activity it disrupted between December 2025 and August 2026. One case, tracked as GTG-20006, stands out.

Public reporting has tied this actor to Midnight Blizzard. Anthropic says its own findings fit that account. It also says one operator's habits and targets look like Russian state espionage.

The actor built AI agents to watch whether security products flagged its malware. If one did, the agents changed and rebuilt the tool. Anthropic says they were built to repeat this until nothing detected it.

20+
Organizations in one actor's targeting
Source: Anthropic Threat Intelligence report (September 2026)

How the loop works

Most security tools spot known malware by a signature, a kind of fingerprint. Once a vendor publishes it, the tool gets blocked. Attackers have long answered by altering the tool. That takes skilled people and time.

Here, the agents did that work. A tool that passed was placed on disposable hosting servers. Victims were steered there by phishing, ClickFix lures (fake prompts that trick users) and DNS hijacking.

The actor also attacked the other end of the loop. Anthropic found companion payloads built to freeze a victim's security updates, so new signatures never arrived. VentureBeat reports that Microsoft's analysis of the same tooling explains how.

A component called ChocoShell needed administrator rights. It used UAC bypass techniques, which get around the Windows permission prompt, to obtain them. With those rights it could lock Defender's signature updates.

Anthropic concludes that AI has pushed the cost of this contest back onto defenders. It adds a limit: capable adversaries can do this "at least in theory." The report documents the loop for one actor. It does not show every attacker doing it, or how often the rebuilds succeeded.

Speed and stolen credentials

Anthropic's wider finding is that AI lets attackers work faster, across more ground, with fewer resources. The next cases involve different people from GTG-20006. Anthropic ties them to suspected affiliates of the ShinyHunters collective.

In one intrusion, a single stolen developer token was enough to take over a victim's cloud environment. It took about three hours.

~3 hours
Time from one stolen developer token to full cloud admin control
Source: Anthropic Threat Intelligence report (September 2026)

Another affiliate worked through a software vendor. In about 34 hours, the affiliate dumped a session store holding more than 2,100 Azure AD token sets from over 40 company tenants. Such tokens act like passes for signed-in users. Anthropic says AI agents did nearly all the work.

One French-speaking operator, known as frkoo, shows how stolen credentials get sourced. Anthropic says the affiliates appear disparate, with their own tooling. It still concludes they are part of the same overall operation.

Anthropic says frkoo ran 10 cloud servers that pulled 1.8 million Android apps from app stores. The apps were unpacked and searched for passwords and keys left in the code. The tool was TruffleHog, a free scanner. Verified finds went to a Telegram group. Anthropic does not describe AI as part of this step.

1.8 million
Android apps mass-downloaded and scanned for secrets by one operator (frkoo)
Source: Anthropic Threat Intelligence report (September 2026)

Anthropic says this pipeline, plus a second one that collected GitHub access tokens, supplied the entry credentials for most of frkoo's confirmed breaches. That covers frkoo's breaches only.

Another cost falls on victims. Anthropic says AI API keys were stolen from a target's software vendors. One stolen key was used for about three weeks to attack other organizations. VentureBeat notes the account owner pays for that use.

What this means for the people paying

The lesson here is that a detection no longer proves an attacker has been stopped. It may be one more step in their workflow. Anthropic also says investigators can no longer judge who is behind an attack by how skilled it looks. AI has lifted every stage, from scouting to data handling.

A small team can now run campaigns that once took many specialists, per Anthropic. VentureBeat notes that the weaknesses involved were familiar, including exposed credentials. That is the useful part. Automation speeds up the rebuild, but attackers still need a way in. Closing those doors is where spending can still add cost for them.

Questions to put to your security team

First: when a tool flags a file, do we stop at quarantine, or hunt for the same actor's next variant?

Second: could an intruder on a machine switch off its security updates? Who would notice?

Third: have we scanned code repositories, container images and mobile apps for embedded secrets? VentureBeat suggests running TruffleHog or an equivalent tool.

Fourth: if a developer token leaks, how fast can we revoke it? Anthropic's three-hour case is a useful yardstick.

Fifth: does anyone watch usage of our AI API keys? Who pays if a stolen one is used against others?

A detection used to be a price the attacker paid. Plan for the day it is only a step they repeat.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Anthropic.

Share this insight