Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection post, september 11, 2026september 15, 2026 Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where “GTG” stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight Blizzard (aka APT29 and Cozy Bear). Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection: Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection cybersecurity malware 2026Russia