Skip to content
AI SecurityLLMDual Use

Midnight Blizzard's malware evasion loop: how Anthropic's report describes the new AI-assisted EDR bypass cycle

2 min read
Share

What Anthropic's report covers

Anthropic published a threat intelligence report in September 2026 documenting Midnight Blizzard's use of Claude from December 2025 through August 2026. The group, assessed by the US and UK governments as Russia's SVR foreign intelligence service, has a long history of targeting government, diplomatic, and defense organizations. This operation is the first publicly documented case of a nation-state actor using an AI API to close the malware detection and evasion cycle automatically.

The detection-evasion loop

When one of the group's tools was flagged by a security product, AI agents automatically modified and rebuilt it, then redeployed it against the detection environment. The cycle repeated until the malware passed. This is a fundamental shift in the economics of malware development. Previously, new detection signatures forced attackers into a slower manual rewrite cycle, which gave defenders a meaningful window. AI has compressed that window significantly.

Who was targeted

Anthropic's report identifies more than 20 targeted organizations, including Ukrainian and European government ministries, defense and intelligence bodies, embassies, and think tanks. Targeting also extended into the Middle East and Asia. The profile matches Midnight Blizzard's established collection priorities: diplomatic and military intelligence, active conflict-zone states, and Western alliance partners.

What this means for defenders

The traditional defender advantage in the signature-writing cycle depended on the assumption that attackers needed manual effort to adapt tools after detection. AI has eroded that assumption. Anthropic frames this explicitly: the cost of the detection-evasion cycle has shifted back onto defenders. Security teams that rely on EDR signatures as a primary control are now facing an adversary that can iterate faster than signature cycles update. Behavioral detection, anomaly-based controls, and network-level segmentation become more important relative to signature-based approaches.

Practical steps

  • Prioritize behavioral and anomaly-based EDR controls over signature-only coverage.
  • Review how quickly your EDR vendor pushes new signatures and whether that cadence is adequate when attackers can iterate using AI.
  • If your organization is in government, defense, or diplomacy in Europe or Central Asia, review your email gateway and endpoint telemetry for the campaign dates: December 2025 through August 2026.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you want to discuss AI-assisted threat actor operations or attribution analysis.