Global Situation Board
Actor · non-state · Transnational & Hybrid

Russian state hackers (GRU / Sandworm / APT28)

4High
Assessed 15 September 2026

Assessment

Anthropic reported on Sept 11 that GTG-20006, whose attribution is consistent with Midnight Blizzard, ran AI-driven phishing, malware-development and evasion workflows against more than 20 organisations, mostly Ukrainian government, military and diplomatic entities, rebuilding its toolkit automatically whenever security products flagged it, and hijacked DNS records at three hotel Wi-Fi providers to stage malware on guests' devices. No further publicly attributed Russian state cyber operation surfaced through Sept 15.

Recent, assessed

  • 2026-09-11Anthropic threat intelligence report details GTG-20006 (attribution consistent with Midnight Blizzard) automating malware mutation against detection telemetry and targeting 20-plus Ukrainian government, military and diplomatic organisations. anthropic.com

Level history

Threat level after each research review12 September 2026 baseline: level 4; 12 September 2026 weekly review: level 4; 14 September 2026 weekly review: level 4; 15 September 2026 weekly review: level 41234512 September 2026, baseline: level 412 September 2026, weekly review: level 414 September 2026, weekly review: level 415 September 2026, weekly review: level 412 Sep14 Sep15 Septoday

Levels set by research reviews. A level set by hand is shown at the top of the page while it is in force and is not part of this history.

DateLevelReview
2026-09-154Weekly review
2026-09-144Weekly review
2026-09-124Weekly review
2026-09-124Baseline

Latest headlines 0

Matched to this entry by keyword from the pull of 19 Sep, 11:09 UTC. Not reviewed; some may be off-topic.

  • No headlines matched in this pull.