Russian hackers weaponized Claude AI to target 20-plus Ukrainian and European organizations

Russia Weaponized Claude AI to Spy on Ukraine and Europe — UNITED24 Media

Russian state-backed hackers turned Anthropic’s Claude AI into a weapon for automated espionage, striking Ukrainian government agencies, military units, diplomats, defense contractors, and drone suppliers across more than 20 organizations.

The revelation arrives in a September 10 threat intelligence report from Anthropic itself. The company designated the operation GTG-20006 and noted that its findings align with public assessments tying the activity to Midnight Blizzard, a notorious Kremlin-linked hacking collective.

Anthropic documented how the attackers built bespoke AI workflows to mechanize nearly every phase of their campaign. Reconnaissance, infrastructure acquisition, phishing, persistence inside breached networks, and data exfiltration all ran through automated processes powered by Claude.

Ukrainian government institutions faced relentless scanning. The group probed email and remote-access systems at over two dozen Ukrainian state organizations. Personnel from the military, diplomatic corps, and intelligence services ranked among the most frequent targets.

Drone technology emerged as a primary objective. Hackers extracted mailboxes from at least two drone component manufacturers, compromised a military drone producer, and stole a proprietary software development kit for a drone vision system. Over several days, they reverse-engineered that stolen code to map out system architecture, hardware dependencies, supplier relationships, and specifications for an unreleased product. Firmware controlling military drone operations and AI-based vision drew particular scrutiny.

Claude also accelerated malware refinement. AI agents monitored whether antivirus tools flagged the group’s malicious payloads. When detection occurred, the system isolated the offending component, rewrote it, and rebuilt the malware until security software stopped catching it.

The automation extended further. AI handled domain registration, phishing infrastructure setup, malicious email distribution, breach monitoring, credential harvesting, and network traversal. Claude processed hundreds of gigabytes of stolen data, including bulk email exports, and helped register attacker-controlled devices within compromised organizations to maintain access.

Some operations targeted indirect victims. The group breached at least three hotel Wi-Fi providers, altered DNS records, and redirected guest devices to malicious infrastructure. This tactic captured guest information and delivered malware to Windows, Android, and iOS devices. Ukrainian officials and drone manufacturers staying at those hotels became targets.

WhatsApp accounts proved vulnerable too. Attackers linked their own devices to victims’ profiles, suppressed read receipts, and exported conversations in Ukrainian and Russian. At least two former senior Ukrainian officials fell victim.

The same actor also breached a North African government technology agency, stealing a database with more than 300,000 national identity records and commercial registry data covering over half a million companies.

The campaign signals a dangerous evolution in state-sponsored cyber operations. AI now handles the tedious, repetitive work that once required teams of human operators.