According to a threat intelligence report published by Anthropic on September 10, the company tracked the group as GTG-20006 and said its attribution was consistent with public reporting linking the activity to Midnight Blizzard, a Russian state-linked hacking group.
Anthropic said the hackers used customized AI-driven workflows to automate much of the attack process, including reconnaissance, acquiring infrastructure, phishing, maintaining access to compromised systems, and extracting stolen information.