Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-09-10

CriticalVendor post

Anthropic Reports GTG-20006 Used Claude Code Workflows Across Live Russian Espionage Operations

Analysis of Anthropic's September 2026 disclosure that GTG-20006 used Claude Code skills and AI workflows for malware rebuilding and live intrusions.

Claude CodeCredential exposureAttacker-operated AI-augmented espionage campaignVictim government, defense, hospitality, cloud-email, identity, and surveillance systems

What happened

AI workflows fingerprinted services, built and operated phishing infrastructure, ran commands against victim systems, harvested credentials, moved laterally, organized stolen data, registered actor-controlled devices, and rebuilt detected malware.

Why it matters

Anthropic identified more than 20 organizations in planning or live operations; reported impacts included compromised hospitality vendors, mailbox theft from at least eight organizations, hundreds of gigabytes of stolen data, more than 300,000 national identity records, and registry data for over half a million companies.

Missing authorization check

No independent, victim-side authorization gate constrained stolen credential use, new device registration, mailbox export, DNS changes, or other consequential state changes.

Would PP block it?

At integrated enterprise boundaries, PP could require separate approval for device registration, privileged identity changes, mailbox bulk export, DNS mutation, or other protected actions. It would not stop the initial intrusion, malware rebuilding, reconnaissance, or data reads outside those boundaries.

Incident analysis

Timeline and technical read

Timeline

  1. 2025-12 to 2026-08

    Anthropic observes and disrupts misuse campaigns covered by its September report, including GTG-20006 activity.

  2. 2026-07-31

    Microsoft publishes related reporting on CaptiveCrunch, a hotel-network technique Anthropic associates with the actor's operations.

  3. 2026-09-10

    Anthropic publishes its September 2026 misuse report detailing GTG-20006.

Technical breakdown

  • Monitoring agents detected security-product alerts and autonomously modified and rebuilt malware until it was undetected.
  • Claude Code skills drove workflows for domain research and registration, hosting configuration, phishing delivery, and command-and-control monitoring.
  • During live intrusions, AI ran commands, harvested credentials, moved laterally, processed exfiltrated data, and automated actor-controlled device registration.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Credential exposure. The relevant Permission Protocol gate is Credential Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Identity-provider mutations, privileged credential use, mailbox export, DNS changes, and protected administrative APIs
Still needs
Phishing, malware engineering, endpoint compromise, reconnaissance, unprotected data reads, and attacker-controlled infrastructure remain outside coverage.
Receipt required for
Registering devices, changing privileged identity state, exporting mailboxes, changing DNS, or mutating protected enterprise systems

PP cannot prevent attacker-operated phishing, malware delivery, credential theft, or activity on systems that do not enforce PP receipts.

Start small

Put the relevant gate at this action boundary.

This incident maps to Credential Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop