Anthropic Links Hotel WiFi Hijacking to Midnight Blizzard
Security / news
Anthropic Links Hotel WiFi Hijacking to Midnight Blizzard
The Sept. 10 threat report ties a handle called "JackPoterz" to a campaign that stole more than 300,000 identity records, the same operation Microsoft named Storm-2945 in July.
A Russian-speaking operator using the handle "JackPoterz" ran a Claude-assisted espionage campaign against Ukrainian and European government targets between December 2025 and August 2026, Anthropic said in a threat intelligence report published Thursday. Anthropic tracks the group as GTG-20006 and said its tradecraft and targeting are consistent with Midnight Blizzard, the Russian state-linked group the United States and United Kingdom attribute to the SVR foreign intelligence service.
What the operators targeted
Anthropic's investigation identified more than 20 organizations in the group's operational planning, the company said, with Ukrainian government, military and diplomatic staff the most frequently recurring targets; other targets included European governments and individuals connected to US foreign policy. Email exfiltration affected at least eight organizations, and one intrusion alone stole more than 300,000 national identity records and the commercial registry data of more than half a million companies, according to the report.
How they used Claude
Anthropic said the actor "used AI at every point in their operations," including reconnaissance to fingerprint email and remote access systems, building the phishing infrastructure and exploitation tooling, running commands against victim systems, and organizing hundreds of gigabytes of stolen data. When Anthropic's own defenses flagged the group's malware, the report said, "the actor used Claude to systematically identify, modify and redeploy the detected artifacts," an automated evasion loop the report describes but does not put a number on.
How they got in
The operators used device code phishing, which abuses a sign-in flow built for devices without a browser to trick a target into authorizing an attacker's session on cloud email services, Anthropic said. They also hijacked DNS at compromised hospitality vendors to redirect hotel WiFi users, took over WhatsApp accounts using headless browsers, and exploited authorization flaws in the application interfaces of camera-streaming services. Anthropic named the malware involved: PowerChrome, WUEngine, Shadow C2, MiniPlasma and CloudSyncSvc on Windows, GiftDrop on Android and DarkSword on iOS.
What Microsoft's own report adds
Microsoft's security team described the same hotel WiFi campaign on July 31, under the name CaptiveCrunch, attributing it to Storm-2945, a sub-cluster of Midnight Blizzard. Microsoft named different malware, a remote access trojan called CornFlake and an infostealer called ChocoShell, and said Storm-2945 ran a command-and-control panel called FruitStone, disguised as what Microsoft's post calls a "CloudSync Console." Anthropic's own malware list from the same campaign includes one named CloudSyncSvc, a naming overlap neither company's report explains. Microsoft's post thanks "our partners at Anthropic and OpenAI for their collaboration and support during this investigation," confirming the two companies were working the same campaign months before Anthropic's Thursday report.
What neither report names
Anthropic's report does not say how many of the more than 20 targeted organizations were successfully breached as opposed to merely targeted, and it does not identify the compromised hospitality vendors whose DNS was hijacked. Microsoft's post does not use the GTG-20006 tracking number or reference Anthropic's malware names, leaving the correspondence between the two companies' tool names, PowerChrome to CornFlake, CloudSyncSvc to FruitStone, unconfirmed by either side.
The campaign sits alongside other recent state-linked intrusions this beat has tracked, including Adobe's actively exploited Commerce zero-day and September's Patch Tuesday, where attackers again reached production systems before a fix shipped.
Sources
More in Security
- 01Cisco and Acronis Share a CISA Deadline, Not a Severity ScoreOne flaw needs no password and no user interaction, the other needs an attacker already logged in, and CISA gave federal agencies the same three days to fix both.
- 02Bransys ELD App Shipped With Hardcoded Login CredentialsCISA disclosed three flaws Sept. 17 in the trucking compliance app, including a hardcoded password a researcher says exposed live location and engine data from every connected truck on a subset of fleets.
- 03MikroTik Patches RouterOS Flaws Attackers Exploited FirstPoland's national CERT says attackers began exploiting the chained flaws on Sept. 2, a day before MikroTik shipped a fix, and more than 122,500 routers were still reachable a week later.
- 04Attackers Exploit a JFrog Artifactory Bug in Four DayswatchTowr says attackers began minting administrator tokens by abusing a default empty join key, CVE-2026-82329, within days of JFrog's own patch shipping.