On Thursday, Anthropic announced that it had disrupted a campaign orchestrated by a Russian state-sponsored threat actor using Claude. The group developed an AI-driven approach to swiftly rebuild and re-deploy their toolkit, effectively evading security products and hindering defenders' ability to intercept and block the toolkit through static detection methods. foreign policy.
The toolkit includes a variety of programs: two Windows-based implants, a mobile exploitation kit, a credential-stealing tool that targets browser password stores, a phishing platform designed to mimic high-profile targets such as government organizations, and an administrative console used to manage compromised accounts.
This is complemented by attempts to take over victims' WhatsApp accounts using headless browsers to link victim accounts as companion devices and bulk-export Russian and Ukrainian language conversations from them while suppressing read receipts. The threat actor leveraged credentials from a VPN appliance to hijack the central account server and steal the entire credential database, including over 300,000 national identity records and the commercial registry data of more than half a million companies. Additionally, the actor developed a cloud email espionage platform that used a device code phishing framework called Embassy Kit to orchestrate a Microsoft 365 token theft campaign, compromising the mail records of at least eight organizations, including a national prosecutor's office, a military education institute, and a regional intergovernmental organization.












