Find notable cyber news and cases, enriched with sources, timelines, and signals.

Midnight Blizzard Claude-assisted cyberespionage campaign

Campaign
First reported
Last updated
Happening score
H score 19
1 unique sources, 1 articles

Summary

Hide ▲

Midnight Blizzard ran a Claude-assisted cyberespionage campaign that automated malware evasion and kept the operation active across more than 20 organizations. The activity reached government ministries, defense and intelligence bodies, embassies, and think tanks across Europe, the Middle East, and Asia. Anthropic said it disrupted the campaign after tracking it from December 2025 to August 2026 and used the findings to strengthen its safeguards.

Related Happenings

Aurora ransomware Cursor Agent exploitation campaign

Campaign
H score24 First: 28.08.2026 11:00 Last: 28.08.2026 11:00 Sources 1

About this happening: Aurora ransomware operators used Cursor Agent and Claude Sonnet to support post-compromise exploitation against 10 victims between April 8 and May 26, 2026...

Earth Lusca Operation FishMedley espionage campaign

Campaign
H score38 First: 16.06.2026 12:44 Last: 16.06.2026 12:44 Sources 1

About this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...

Webworm multi-country targeting campaign against government and enterprise victims

Campaign
H score38 First: 20.05.2026 15:51 Last: 20.05.2026 15:51 Sources 1

About this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...

Shadow-Aether-040 AI-augmented campaign against Mexican government entities

Campaign
H score41 First: 13.05.2026 16:00 Last: 13.05.2026 16:00 Sources 1

About this happening: The Shadow-Aether-040 campaign used AI agents and custom tooling to compromise six government entities in Mexico, increasing the risk of follow-on intrusion and data...

Silk Typhoon / Hafnium coordinated intelligence-gathering campaign

Campaign
H score59 First: 27.04.2026 22:56 Last: 27.04.2026 22:56 Sources 1

About this happening: The Silk Typhoon / Hafnium operation is tied to a coordinated intelligence-gathering campaign spanning February 2020 to June 2021, underscoring a sustained espionage e...

Latest development: 28.04.2026 15:30

US officials described Silk Typhoon/Hafnium activity from February 2020 to June 2021 as a coordinated intelligence-gathering campaign that targeted US universities and COVID-19 researchers, including a Texas university network, and later expanded into Microsoft Exchange Server vulnerability exploitation. The operation reportedly used stolen mailbox access to search for vaccines, treatments, and testing research, and the FBI said the campaign affected more than 12,700 US organizations.

Timeline

  1. 11.09.2026 11:47 1 articles · 1h ago

    Anthropic disrupts Midnight Blizzard Claude-assisted cyberespionage campaign

    Initial Disclosure

    Anthropic said it disrupted a Russian state-nexus cyberespionage operation tracked as Midnight Blizzard after identifying and shutting down activity between December 2025 and August 2026. The group used Claude to monitor whether malware evaded security products, then had AI agents automatically modify, rebuild, and redeploy tools until they went undetected again, with the campaign reaching more than 20 organizations including government ministries, defense and intelligence bodies, embassies, and think tanks across Europe, the Middle East, and Asia. Anthropic also said the same actor exfiltrated mailboxes from two drone component manufacturers, stole a complete proprietary software development kit for a drone vision system, compromised at least three hospitality vendors that operate hotel guest Wi-Fi through DNS hijacking, and took over WhatsApp accounts by linking them as companion devices through headless browsers.

    Show sources