A ransomware affiliate weaponized Claude Code to autonomously steal LDAP credentials, backdoor VPNs, and exfiltrate SQL ...
The implant ensures defenders only see legit Microsoft services rather than unknown external domains, making it more ...