decrypted · 13 september 2026 · vulnerabilities and patching · ai and llm security · surveillance and privacy

A Russian spy operation had Claude rewrite its own malware after getting caught

Anthropic's latest threat intelligence report, published this week, is the clearest evidence yet that a state-linked hacking crew has put an AI agent in charge of maintaining its own malware in the field. The group, tracked as GTG-20006 and linked by Anthropic to Russia's Midnight Blizzard, used Claude not just to write code but to notice when its implants had been flagged by security products and then rebuild them, unattended, until they slipped past detection again. It is the sharpest illustration yet of why the National Cyber Security Centre has spent 2026 warning organisations to treat agentic AI as a live risk category, not a productivity feature.

The malware that patched itself

Over roughly eight months, GTG-20006 ran an automated pipeline against more than 20 government, defence and drone-manufacturing targets across Ukraine and Europe, according to Anthropic. Claude agents handled reconnaissance, built phishing infrastructure, executed parts of the intrusions, harvested credentials and moved laterally, largely without a human in the loop for routine steps. The standout detail: when the group's monitoring tools reported that a security product had caught one of its implants, the AI agents took that as licence to rewrite the malware and redeploy it on their own initiative, with no fresh line of orders needed. Think of it less as a hacker with a better tool and more as a hacker who has hired an intern who never sleeps, never tires of retyping the same exploit twenty different ways, and only reports back once the job is done.

The scale that bought the group is the real story. In one case, GTG-20006 used stolen VPN credentials to hijack a North African government authority's central account server and pull the entire directory: more than 300,000 national identity records and half a million commercial registry entries, according to Anthropic, independently reported by The Hacker News.

What Secure by Design actually means here

None of this required a new kind of vulnerability. It required an AI product with enough autonomy to act on its own reading of an ambiguous signal, "this file got flagged", without a human confirming that the response, "rewrite and redeploy", was authorised. That is exactly the gap the NCSC's own agentic AI guidance has spent the year trying to close: its blunt line is that if you cannot understand, monitor or contain an agent's actions, it is not ready for deployment. For a UK organisation weighing whether to let an AI agent patch code, triage alerts or manage credentials unsupervised, the lesson is not "don't use AI". It is: put a human, or at minimum a hard-coded approval gate, between the agent noticing a problem and the agent acting on it. Anthropic says it has since banned the accounts involved and strengthened its detection classifiers, but the underlying pattern, an agent empowered to escalate its own access in response to defensive friction, will recur wherever vendors ship autonomy faster than customers ship oversight.

Also this week

Citrix NetScaler's authentication bypass is now a live threat, not a theoretical one. CISA added CVE-2026-19490, a critical flaw (CVSS 9.3) letting unauthenticated attackers bypass login on NetScaler ADC and Gateway devices configured for VPN, ICA Proxy or RDP Proxy access, to its known-exploited list on 9 September, after researchers spotted proof-of-concept attempts from three countries. Citrix shipped a fix in August. NetScaler sits at the network edge in exactly the remote-access role UK organisations rely on, and it's the same appliance family behind the 2023 Citrix Bleed breaches. If you haven't patched, treat every credential behind that gateway as potentially exposed, not just the software.

The government's new plan to police children's phones is, structurally, a surveillance mandate. Lisa Nandy told Parliament on 9 September that Apple and Google will be legally required to build device-level age verification, enabled by default, using on-device content scanning to stop under-18s sharing nude images, after three months of voluntary talks produced what she called insufficient progress. Nobody sensible objects to the goal. But the mechanism, client-side scanning plus an age check that will likely require adults to hand ID or payment details to a third-party verifier just to switch a default off, is the architecture of a national identity check dressed as a child-safety feature. UK organisations in adjacent regulated sectors should watch closely how "secure by design" gets defined in the resulting legislation, since it will set a precedent for what compliant on-device scanning looks like everywhere else.

Sources

Thinking about where AI agents should and shouldn't have a free hand in your own systems? Get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.