Anthropic’s threat intelligence team disclosed that a Russian state-nexus group it tracks as GTG-20006 (assessed to overlap with Midnight Blizzard) used Claude models in AI-orchestrated intrusion campaigns against more than 20 organizations between December 2025 and August 2026, including Ukrainian government bodies, defense contractors, diplomatic missions, and drone manufacturers. The operators used Claude for reconnaissance, phishing, persistence, and to automatically rewrite their own malware whenever security products flagged it, repeating the loop until detection stopped. The campaign compromised military intelligence targets and exfiltrated proprietary drone software designs along with more than 300,000 national ID records and 500,000 company registry entries.