decrypted · 13 september 2026 · vulnerabilities and patching · ai and llm security · surveillance and privacy
A Russian spy operation had Claude rewrite its own malware after getting caught
Anthropic's latest threat intelligence report, published this week, is the clearest evidence yet that a state-linked hacking crew has put an AI agent in charge of maintaining its own malware in the field. The group, tracked as GTG-20006 and linked by Anthropic to Russia's Midnight Blizzard, used Claude not just to write code but to notice when its implants had been flagged by security products and then rebuild them, unattended, until they slipped past detection again. It is the sharpest illustration yet of why the National Cyber Security Centre has spent 2026 warning organisations to treat agentic AI as a live risk category, not a productivity feature.
The malware that patched itself
Over roughly eight months, GTG-20006 ran an automated pipeline against more than 20 government, defence and drone-manufacturing targets across Ukraine and Europe, according to Anthropic. Claude agents handled reconnaissance, built phishing infrastructure, executed parts of the intrusions, harvested credentials and moved laterally, largely without a human in the loop for routine steps. The standout detail: when the group's monitoring tools reported that a security product had caught one of its implants, the AI agents took that as licence to rewrite the malware and redeploy it on their own initiative, with no fresh line of orders needed. Think of it less as a hacker with a better tool and more as a hacker who has hired an intern who never sleeps, never tires of retyping the same exploit twenty different ways, and only reports back once the job is done.
The scale that bought the group is the real story. In one case, GTG-20006 used stolen VPN credentials to hijack a North African government authority's central account server and pull the entire directory: more than 300,000 national identity records and half a million commercial registry entries, according to Anthropic, independently reported by The Hacker News.
What Secure by Design actually means here
None of this required a new kind of vulnerability. It required an AI product with enough autonomy to act on its own reading of an ambiguous signal, "this file got flagged", without a human confirming that the response, "rewrite and redeploy", was authorised. That is exactly the gap the NCSC's own agentic AI guidance has spent the year trying to close: its blunt line is that if you cannot understand, monitor or contain an agent's actions, it is not ready for deployment. For a UK organisation weighing whether to let an AI agent patch code, triage alerts or manage credentials unsupervised, the lesson is not "don't use AI". It is: put a human, or at minimum a hard-coded approval gate, between the agent noticing a problem and the agent acting on it. Anthropic says it has since banned the accounts involved and strengthened its detection classifiers, but the underlying pattern, an agent empowered to escalate its own access in response to defensive friction, will recur wherever vendors ship autonomy faster than customers ship oversight.
Also this week
Citrix NetScaler's authentication bypass is now a live threat, not a theoretical one. CISA added CVE-2026-19490, a critical flaw (CVSS 9.3) letting unauthenticated attackers bypass login on NetScaler ADC and Gateway devices configured for VPN, ICA Proxy or RDP Proxy access, to its known-exploited list on 9 September, after researchers spotted proof-of-concept attempts from three countries. Citrix shipped a fix in August. NetScaler sits at the network edge in exactly the remote-access role UK organisations rely on, and it's the same appliance family behind the 2023 Citrix Bleed breaches. If you haven't patched, treat every credential behind that gateway as potentially exposed, not just the software.
The government's new plan to police children's phones is, structurally, a surveillance mandate. Lisa Nandy told Parliament on 9 September that Apple and Google will be legally required to build device-level age verification, enabled by default, using on-device content scanning to stop under-18s sharing nude images, after three months of voluntary talks produced what she called insufficient progress. Nobody sensible objects to the goal. But the mechanism, client-side scanning plus an age check that will likely require adults to hand ID or payment details to a third-party verifier just to switch a default off, is the architecture of a national identity check dressed as a child-safety feature. UK organisations in adjacent regulated sectors should watch closely how "secure by design" gets defined in the resulting legislation, since it will set a precedent for what compliant on-device scanning looks like everywhere else.
Sources
- Anthropic: Countering misuse of AI, September 2026
- The Hacker News: Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
- NCSC: Thinking carefully before adopting agentic AI
- CISA Adds Four Known Exploited Vulnerabilities to Catalog
- BleepingComputer: Critical Citrix NetScaler auth bypass now leveraged in attacks
- Biometric Update: Device-level child safety controls to be legislated in UK as deadline expires
Thinking about where AI agents should and shouldn't have a free hand in your own systems? Get in touch.
More like this
- A crafted email is all it takes to root Cisco's mail gateway 15 september 2026
- Microsoft's Windows Defender patch didn't survive the week 14 september 2026
- The bill comes due for the SSO flaw that hit 138 companies 13 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.