{ "actor": "Russia-nexus espionage actor (tracked by Anthropic as GTG-20006; attribution described as consistent with public reporting on Midnight Blizzard)", "actor_type": "nation-state", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "significant", "autonomy_level": "supervised-autonomous", "autonomy_pct": null, "category": "ai-orchestrated-campaign", "confidence": "primary", "date_disclosed": "2026-09-10", "guardrail_bypass": [ "legitimate-tool-abuse" ], "id": "gtg-20006-agentic-espionage", "impact": "Per Anthropic: at least three hospitality vendors compromised; mail records exfiltrated from at least eight organizations; hundreds of gigabytes of stolen data extracted and organized with AI, including more than 300,000 national identity records and commercial registry data on more than half a million companies from a North African government technology authority.", "last_updated": "2026-10-10", "lifecycle_phases": [ "initial-access", "credential-access", "persistence", "exfiltration" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Anthropic states it disrupted the activity, strengthened its safeguards and shared intelligence with authorities and industry partners where appropriate." ], "model_families": [ "claude" ], "models": [ "Claude Code" ], "name": "GTG-20006 agentic espionage against government, defense and diplomatic targets (Russia-nexus)", "related": [ "gtg-1002-ai-espionage", "gtg-2002-vibe-hacking-extortion", "gtg-50014-agentic-mass-exfiltration", "gtg-10007-agent-swarm-intrusions", "gtg-50029-hacktivist-agentic-recon", "gtg-50020-ai-vendor-api-key-theft" ], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20261009173227/https://www.anthropic.com/threat-intelligence-report-september-2026", "date": "2026-09-10", "publisher": "Anthropic", "title": "Countering misuse of AI: September 2026", "type": "first-party-disclosure", "url": "https://www.anthropic.com/threat-intelligence-report-september-2026" } ], "status": "confirmed", "summary": "In its September 2026 report \"Countering misuse of AI\", Anthropic disclosed a cluster it tracks as GTG-20006 that ran from December 2025 through August 2026. Anthropic describes the attribution as \"consistent with public reporting linking the actor to Midnight Blizzard\" and one operator's tradecraft and targeting as \"consistent with Russian state-nexus espionage\". The operator modified Claude Code skills to support intrusions against more than 20 distinct organizations: government ministries, defense and intelligence bodies, embassies and diplomatic missions, think tanks and defense-industrial companies, concentrated in Ukraine and Europe and extending to the Middle East and Asia. At least three hospitality vendors were compromised and mail records were exfiltrated from at least eight organizations. Humans set targets and reviewed exfiltration, while scheduled jobs renewed stolen access tokens and harvested victim cloud storage with no human involvement. Anthropic states it used AI to extract and organize hundreds of gigabytes of stolen data, including more than 300,000 national identity records and registry data on more than half a million companies taken from a North African government technology authority.", "targets": { "countries": [ "UA" ], "orgs_affected": 20, "records_exfiltrated": 300000, "sectors": [ "government", "defense", "hospitality" ] } }