Russian Hackers Used Claude AI to Launch Attacks Against Ukraine and Europe

Russian Hackers Used Claude AI to Launch Attacks Against Ukraine and Europe
Russian hacker. Source: Getty Images

The Russian hacking group Midnight Blizzard used Claude, an AI developed by Anthropic, to automate cyberespionage operations against Ukraine and European countries.

Anthropic reported this in its report titled “Detecting and Countering Misuse of AI: September 2026.”

According to the researchers, from December 2025 to August 2026, the hackers attacked more than 20 organizations. Targets included government, military, and intelligence agencies; diplomatic missions; think tanks; defense companies; and drone manufacturers.

Claude was used in nearly every stage of the attacks: to identify potential targets, gather information, register domains, set up phishing infrastructure, steal credentials, move laterally within compromised networks, and exfiltrate hundreds of gigabytes of data.

The AI also monitored whether security systems were detecting the group’s malicious programs. If an antivirus detected one of them, the system analyzed the reason for the detection, modified the code, and recompiled the program until it became invisible to security measures.

The attackers paid particular attention to drone technologies and related supply chains. They dumped the contents of email inboxes belonging to at least two drone component manufacturers, attacked a manufacturer of military UAVs, and stole a set of development tools for proprietary software used in a drone’s machine vision system.

Over the course of several days, the attackers reverse-engineered the stolen software. They reconstructed the system’s architecture, the list of hardware components, information about suppliers, and details about a product that had not yet been released.

To gain indirect access to priority targets, the group compromised at least three hotel Wi-Fi providers. By modifying DNS records, the hackers redirected guests’ devices to servers under their control and distributed malware for Windows, Android, and iOS.

The attackers also gained access to WhatsApp accounts. To do this, they used a browser-based platform without a graphical user interface, which connected devices controlled by the attackers to the victims’ accounts as linked devices.

Illustrative image on the topic of cyberattack

The setup, partially built on the open-source WhatsApp automation library WPPConnect, disabled read receipts. As a result, victims did not notice the mass download of their correspondence in Ukrainian and Russian. At least two former high-ranking Ukrainian officials were targeted in this manner.

The group also targeted video surveillance platforms. The attackers identified authorization vulnerabilities in the application programming interfaces (APIs) of video streaming services from cameras. By exploiting these vulnerabilities, they obtained user lists and stole tokens that granted access to live streams from the victims’ cameras.

The same group infiltrated the systems of a government technology agency in a North African country. The attackers stole the entire database of account records, which contained over 300,000 entries from the national citizen identification system, as well as data from the commercial registry on more than half a million companies operating in the country.

As a reminder, in July it was revealed that a group of Russian hackers had been conducting a cyberespionage campaign over the past year targeting American scientists in the nuclear sector, defense contractors, and government officials.

Share this post:

SUPPORT MILITARNYI

PrivatBank ( Bank card )
5169 3351 0164 7408
Bank Account in UAH (IBAN)
UA043052990000026007015028783
BTC
bc1qg0z99m95fte7kj8faa7h2kvnq92wvc53exe8gm
USDT
0x8676644fA7B6d328310283cAC1065Ae01d97CEe7
ETH
0xfD02863D3289416fcF50975c9DFda13623f97758
Popular
Button Text