Skip to main content
Cozy Bear

Cozy Bear

Search complete. 18 mentions across 11 episodes found for "Cozy Bear".

Sep 18, 2026

Neil BissonHOST
17:36
Anthropic tracks the actor behind this operation as GTG-20006.
Neil BissonHOST
17:42
According to Anthropic, its attribution is consistent with public reporting connected to the actor named Midnight Blizzard, the Russian-linked cyber espionage group also known as APT-29 or Cozy Bear.
Neil BissonHOST
17:56
Midnight Blizzard has previously been attributed by Western governments to Russia's Foreign Intelligence Service, the
speaker_0NARRATOR
18:01
SPR.
Steve PrenticeHOST
1:25
In a somewhat blockbuster threat report covering activity between December 2025 and August of this year, Anthropic says it, quote, "detected and disrupted a Russia-linked cyber espionage group that used its AI tool, Claude, in a hacking campaign targeting more than 20 government, intelligence, diplomatic, and defense organizations," end quote.
Steve PrenticeHOST
1:47
Anthropic said the activity aligned with Midnight Blizzard, which used to be known as Cozy Bear, a group attributed to Russia's foreign intelligence service.
Steve PrenticeHOST
1:56
In one instance, the group, quote, "targeted members of the Ukrainian government, military, and diplomatic staff, alongside entities involved in the drone supply chain.
Steve PrenticeHOST
2:05
They were able to steal a complete proprietary software development kit for a drone vision system and then used Claude to reverse engineer that vision system, recovering its product architecture, its hardware bill of materials, its supplier dependencies, and details of an unannounced product." Shiny Hunters also abused Claude to extract secrets from Android apps.
speaker_0HOST
14:54
Who are they?
speaker_1HOST
14:55
Anthropix Telemetry shows they have distinct ties to the Russian state-sponsored group Midnight Blizzard, also known as APT29.
speaker_0HOST
15:03
Wow.
speaker_0HOST
15:04
So nation states are leaning in.
Steve PrenticeSOUNDBITE_SPEAKER
20:16
tropic caught russia linked spies using claude in hacking operations In a somewhat blockbuster threat report covering activity between December 2025 and August of this year, Anthropic says it, quote, detected and disrupted a Russia-linked cyber espionage group that used its AI tool Clawed in a hacking campaign targeting more than 20 government, intelligence, diplomatic, and defense organizations, end quote.
Steve PrenticeSOUNDBITE_SPEAKER
20:44
Anthropic said the activity aligned with Midnight Blizzard, which used to be known as Cozy Bear, a group attributed to Russia's Foreign Intelligence Service.
Steve PrenticeSOUNDBITE_SPEAKER
20:54
In one instance, the group, quote, targeted members of the Ukrainian government, military and diplomatic staff, alongside entities involved in the drone supply chain.
Steve PrenticeSOUNDBITE_SPEAKER
21:03
They were able to steal a complete proprietary software development kit for a drone vision system and then used Claude to reverse engineer that vision system, recovering its product architecture, its hardware bill of materials, its supplier dependencies, and details of an unannounced product.
speaker_1HOST
14:55
And this cluster aligns with broader reporting linking them to the group known as Midnight Blizzard.
speaker_0HOST
14:59
Also tracked as APT29 or Cozy Bear.
speaker_0HOST
15:01
Right.
speaker_1HOST
15:02
This is a highly resourced, highly capable, advanced, persistent threat.
Dave BittnerHOST
6:58
Anthropic says it disrupted a Russia-linked cyber espionage group using Claude in attacks against more than twenty government intelligence, diplomatic, and defense organizations.
Dave BittnerHOST
7:09
The activity aligned with Midnight Blizzard, also known as APT29 or Cozy Bear, which Western intelligence agencies attribute to Russia's SVR.
Dave BittnerHOST
7:20
According to Anthropic, the hackers compromised hotel Wi-Fi providers, targeted Ukrainian officials and organizations in the drone supply chain, and stole a drone vision system's software development kit.
Dave BittnerHOST
7:34
They then used Claude to reverse engineer the technology and modify hacking tools after security products detected them.
Costin RaiuHOST
19:42
There were some surprises that I was, um, thinking about.
Costin RaiuHOST
19:46
So for instance, they talk about this, uh, APT29 captive portal, uh, attacks that we discussed before, and they had some, some new details.
Ryan NaraineHOST
19:55
Captive portal, right.
Ryan NaraineHOST
19:55
This is the-
Ryan NaraineHOST
20:01
... by the MSPs, the whole supply chain piece of it, right?
Costin RaiuHOST
20:03
Mm-hmm.
Costin RaiuHOST
20:04
The new dark hotel from, uh, APT29 and-
Ryan NaraineHOST
20:06
Anthropic had something new there
Donna GrindleHOST
17:12
And I like the fact that they've taken this approach where it's people.
Donna GrindleHOST
17:19
Well, except for cozy bear, but that would have been complicated if they made.
David SimsHOST
17:24
Again, I'll run the bear.
Donna GrindleHOST
17:25
Yeah.

10 MINS LATER

Donna GrindleHOST
27:08
And then I'll go and check your passwords.
Donna GrindleHOST
27:09
Right.
Donna GrindleHOST
27:13
And then the next one is cozy bear.
Donna GrindleHOST
27:16
And it's literally a bear wearing glasses and headphones at a computer.
speaker_1HOST
5:03
Yeah, they're hitting NATO and European Union government websites, financial hubs, transport sites.
speaker_0HOST
5:08
But there's also a much more sophisticated Russian intelligence cluster operating in parallel, right? APT29.
speaker_1HOST
5:14
Also tracked as ICE-like, yes.
speaker_1HOST
5:17
They're actively mapping the transatlantic policy response.
Artificial IntelligenceNARRATOR
4:47
SolarWinds is the second structurally different pattern.
Artificial IntelligenceNARRATOR
4:50
Between roughly September twenty nineteen and March twenty twenty, attackers, later attributed to Russia's SVR, APT29, compromised SolarWinds' build environment itself using malware tracked as SunSpot that watched for the Orion product's build process and injected the SunBurst backdoor directly into the compiled output before it was signed.
Artificial IntelligenceNARRATOR
5:11
SolarWinds has stated the attackers did not modify the source repository.
Artificial IntelligenceNARRATOR
5:15
The tampering happened inside the automated build pipeline.

1 more episode mentions Cozy Bear.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.