Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

Summary

Anthropic has disrupted a campaign by a Russian state-sponsored threat actor that utilized Claude, an AI model, to create an AI-assisted workflow. This workflow was designed to help the group rebuild malware after it was detected, aiming to stay ahead of security measures.

IFF Assessment

FOE

This is bad news for defenders as it demonstrates a state-sponsored actor leveraging AI for offensive purposes, specifically to circumvent detection and rebuild malicious tools.

Defender Context

This highlights a growing trend of threat actors incorporating AI into their operations to enhance efficiency and evade detection. Defenders should be aware of how AI tools, even seemingly benign ones like LLMs, can be weaponized and prepare for more sophisticated, AI-assisted attacks.

Read Full Story →