An attacker built AI agents designed to rebuild malware whenever security tools flagged it. In a separate operation, a suspected ShinyHunters affiliate went from a stolen developer token to full administrative control of a victim's cloud environment in about three hours. Anthropic documented both operations in its September threat report.

For security teams, detection doesn't necessarily stop the attack: Malware can be rebuilt, and stolen AI credentials can be used to run further intrusions at the account owner's expense.

How the malware-rebuilding campaign worked

Anthropic tracked the attacker as GTG-20006 and assessed its tradecraft as consistent with Midnight Blizzard.

Anthropic says the attacker used AI agents to monitor whether security products detected its malware. When a product flagged an implant, the agents modified and rebuilt it. They were designed to repeat the process until the malware went undetected.

The attacker bulk-exported mailboxes from at least two drone component makers and stole a proprietary drone vision system's software development kit. They then reverse-engineered the system, recovering its product architecture, hardware bill of materials and supplier dependencies.

The attacker targeted more than 20 organizations across its planning, reconnaissance and live operations, including government ministries, defense and intelligence bodies, embassies, think tanks, and defense-industrial companies, concentrated in Ukraine and Europe. The attacker stole more than 300,000 national identity records and the commercial registry data of more than half a million companies from a North African government technology authority.

AI handled reconnaissance through exfiltration, but humans retained target selection and review of the stolen data. The same attacker compromised hotel guest Wi-Fi vendors and hijacked their DNS records, staging malware for targeted guests. Microsoft documented the campaign in its CaptiveCrunch report on July 31.

Anthropic found that companion payloads were designed to freeze the victim machine's security updates. Microsoft's analysis of the same tooling, linked by a shared C2 address and file hash across both reports' indicator tables, identified the specific mechanism. ChocoShell required administrative privileges to lock Defender signature updates and included UAC bypass techniques to obtain them.

The attacker designed its tools to close the loop at both ends, rebuilding the payload to beat what scanners had and blocking the victim from getting what scanners shipped next. Anthropic says capable adversaries could, "at least in theory," bypass detections faster than defenders can develop and deploy them.

From stolen token to cloud admin in about three hours

Suspected affiliates of the ShinyHunters collective used AI across the full kill chain. One of them escalated from a single stolen developer token to full administrative control of a victim's cloud environment in about three hours.

Anthropic describes the approach as resembling "vibe hacking": Operators give AI general goals and let it navigate each environment on its own.

In a separate compromise of a technology provider, the operators exfiltrated more than a terabyte of stolen data, including hundreds of thousands of national identifiers and millions of payment card records. At an airline, the operators reached systems holding tens of millions of passenger records. Anthropic says suspected ShinyHunters affiliates also stole victims' AI API keys and switched their attack workloads onto those keys.

Three checks for security teams

The attacks Anthropic documented exploited familiar weaknesses, including exposed credentials, while using AI to accelerate intrusions and adapt malware to detection. Security teams can start by checking whether the same gaps exist in their own environments.

Run TruffleHog or an equivalent scanner against your code repositories, container images and mobile app binaries. One suspected ShinyHunters affiliate mass-downloaded 1.8 million Android APKs and scanned every one for hardcoded secrets.

Inventory every AI agent credential in production and record which agents use it, what it can access and how to revoke it.

Test whether your EDR detects successive rebuilt variants of the same implant and flags attempts to block Defender signature updates. Microsoft publishes detection names for UAC bypass, AMSI tampering, and COM hijacking. Check whether your tooling detects those behaviors and whether your team can identify endpoints that have stopped receiving signature updates.