Published · Updated

Anthropic report: Russian-linked hackers used Claude AI to automate cyberattacks on Ukraine and Europe

Anthropic has published a report documenting that a cyber actor tracked as GTG-20006, linked by researchers to the Russian hacker group Midnight Blizzard, used its Claude AI tool to automate cyberattacks against Ukrainian, European, and other targets. The campaign targeted military intelligence assets, diplomatic and defense organizations, and developers of military drone technology and their supply chains.

Key points

  • Anthropic reported that cyber actor GTG-20006, linked to the Russian group Midnight Blizzard, used its Claude AI tool to automate attacks against Ukraine and European countries.
  • Targets included military intelligence assets in Ukraine and European governments, as well as diplomatic and defense organizations and individuals connected to US foreign policy.
  • The AI tool was used for target research, phishing infrastructure, credential theft, data exfiltration, and autonomous modification of malware code to bypass antivirus detection.
  • More than 20 organizations were targeted, including ministries, defense and intelligence agencies, embassies, think tanks, and defense-industrial enterprises, primarily in Ukraine and Europe.
  • Hackers stole data from mailboxes of at least two drone-component manufacturers and analyzed a drone's machine-vision software to reconstruct its architecture and supplier list.
  • Attackers compromised at least three hotel Wi-Fi providers and altered DNS records to redirect guests' devices to attacker-controlled servers spreading malware for Windows, Android, and iOS.
  • WhatsApp accounts of at least two former senior Ukrainian officials were accessed, with correspondence in Ukrainian and Russian mass-exported.

Why it matters

The Anthropic report documents what appears to be the first major publicly disclosed case of a state-linked actor using a commercial frontier AI to automate significant portions of a cyber-espionage operation. Ukraine and European government, defense, and diplomatic institutions were among the primary targets, extending the documented cyber dimension of the conflict beyond purely military systems. The reported theft of data from drone-component manufacturers and analysis of a drone's machine-vision software point at attempts to compromise Ukraine's unmanned aerial capabilities and their supply chains. The AI tool allegedly enabled bypassing traditional cyber defenses and autonomous modification of malware code, lowering the technical threshold and scaling speed of such operations. The targeting of WhatsApp accounts of former senior Ukrainian officials indicates an effort to harvest political and policy intelligence.

What happened

Anthropic published a report describing how a Russian-linked cyber actor, tracked as GTG-20006 and attributed by researchers to the group Midnight Blizzard, used its Claude AI tool — specifically Claude Code — to automate cyberattacks against Ukraine and European countries. One identified operator was a Russian-speaking hacker using the nickname JackPoterz, whose methods researchers said are consistent with Russian special services. The hackers targeted military intelligence assets in Ukrainian and European governments, diplomatic and defense organizations, and individuals connected to US foreign policy. AI workflows automated target research, phishing infrastructure setup, credential theft, and data exfiltration via command-and-control channels; the AI also analyzed why antivirus software detected their malware, modified the code, and rebuilt it until detection ceased. A human operator stepped in mainly to fine-tune Claude Code workflows. The investigation identified more than 20 targeted organizations, including ministries, defense and intelligence agencies, embassies, diplomatic missions, think tanks, and defense-industrial enterprises concentrated in Ukraine and Europe, with additional hits in the Middle East and Asian maritime state agencies. Key themes included Ukraine and developers of military drone technologies. Hackers stole data from at least two drone-component manufacturers and analyzed a drone's machine-vision software for several days to reconstruct its architecture and supplier list. They compromised at least three hotel Wi-Fi providers, altered DNS records, and redirected guests' devices to servers spreading malware for Windows, Android, and iOS. They also accessed WhatsApp accounts, mass-exporting correspondence in Ukrainian and Russian, including from at least two former senior Ukrainian officials.

Background

Anthropic, the developer of the Claude AI model, itself published the report describing the abuse of its tool. The cyber actor is tracked as GTG-20006 and has been linked by researchers to the Russian hacker group Midnight Blizzard. The campaign combined AI-automated development, infrastructure acquisition, phishing, data exfiltration, and data leak workflows, with a human operator primarily stepping in to fine-tune Claude Code. More than 20 organizations were identified as targeted at various stages, including ministries, defense and intelligence agencies, embassies, diplomatic missions, think tanks, and defense-industrial enterprises concentrated in Ukraine and Europe, with additional hits in the Middle East and Asian maritime state agencies, and outliers in a Southeast Asian maritime body and a North African state technology authority. Hackers compromised at least three hotel Wi-Fi providers and altered DNS records to redirect guests' devices to attacker-controlled servers to spread malware for Windows, Android, and iOS.