GTG-20006 is a Russian state-sponsored cyber-espionage cluster whose attribution and tradecraft align with Midnight Blizzard, also known as APT29 and Cozy Bear. Its operations principally target Ukrainian and European government, military-intelligence, diplomatic, and defense-industrial organizations, including drone manufacturers and their supply chains. Additional targets include think tanks, individuals associated with U.S. foreign policy, Asian government agencies, and a North African government technology authority. The cluster designation does not establish that its scope is identical to the broader Midnight Blizzard grouping. The actor uses phishing, device-code phishing, ClickFix lures, compromised credentials, and DNS hijacking for initial access. It has compromised hospitality vendors operating hotel guest Wi-Fi services and altered DNS records to redirect guests to infrastructure delivering Windows, Android, and iOS malware. Information collected from hotel-management systems and guest devices supports identification of additional targets. Its cloud-email espionage operations use Embassy Kit to obtain Microsoft 365 tokens and access and exfiltrate government and diplomatic email. GTG-20006 deploys credential stealers, PowerShell stagers, Windows backdoors, and mobile surveillance tools. Observed malware behaviors include concealed script execution, browser-history collection, persistence through Windows services, process injection, and access to browser and Microsoft Teams data. The actor also links unauthorized companion devices to WhatsApp accounts to export conversations, exploits surveillance-platform authorization flaws to obtain live-camera access tokens, and steals government identity and commercial-registry data. The cluster uses Claude-assisted workflows for reconnaissance, phishing infrastructure, malware development, and command-and-control management. Its operations include modifying and rebuilding detected implants to evade existing security controls. Repeated malware variants retain consistent malicious behaviors despite changes to their static characteristics.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
60 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Russia-linked espionage operator reportedly used Claude to identify, modify and redeploy implants flagged by security products. ReversingLabs observed multiple stager builds with different hashes but consistent malicious behaviors. Its telemetry supported the rebuild pattern but could not independently establish that AI generated the files. Attribution to Midnight Blizzard is presented as consistent with public reporting, not confirmed identity.
Russian state-sponsored cyber-espionage activity using Claude-enabled AI workflows to monitor detections and autonomously modify, rebuild, and redeploy malware. The group targeted government, military intelligence, diplomatic, defense, and Ukraine-connected individuals and organizations; it also compromised hotel Wi-Fi vendors for DNS hijacking and delivered device-specific malware, conducted cloud-email and WhatsApp espionage, and accessed surveillance-camera streams.
Russian state-linked espionage activity that used AI agents to automate phishing infrastructure, malware development and iterative evasion, command-and-control, DNS hijacking, WhatsApp account compromise, and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.