The Russian hacking group Midnight Blizzard used Claude, an AI developed by Anthropic, to automate cyberespionage operations against Ukraine and European countries.
Anthropic reported this in its report titled “Detecting and Countering Misuse of AI: September 2026.”
According to the researchers, from December 2025 to August 2026, the hackers attacked more than 20 organizations. Targets included government, military, and intelligence agencies; diplomatic missions; think tanks; defense companies; and drone manufacturers.
Claude was used in nearly every stage of the attacks: to identify potential targets, gather information, register domains, set up phishing infrastructure, steal credentials, move laterally within compromised networks, and exfiltrate hundreds of gigabytes of data.
Російські хакери використали ШІ Claude для атак на Україну та Європу pic.twitter.com/4CBP6Ugcxr
— dimdim (@dimdim518484) September 11, 2026
The AI also monitored whether security systems were detecting the group’s malicious programs. If an antivirus detected one of them, the system analyzed the reason for the detection, modified the code, and recompiled the program until it became invisible to security measures.
The attackers paid particular attention to drone technologies and related supply chains. They dumped the contents of email inboxes belonging to at least two drone component manufacturers, attacked a manufacturer of military UAVs, and stole a set of development tools for proprietary software used in a drone’s machine vision system.
Over the course of several days, the attackers reverse-engineered the stolen software. They reconstructed the system’s architecture, the list of hardware components, information about suppliers, and details about a product that had not yet been released.
To gain indirect access to priority targets, the group compromised at least three hotel Wi-Fi providers. By modifying DNS records, the hackers redirected guests’ devices to servers under their control and distributed malware for Windows, Android, and iOS.
The attackers also gained access to WhatsApp accounts. To do this, they used a browser-based platform without a graphical user interface, which connected devices controlled by the attackers to the victims’ accounts as linked devices.
The setup, partially built on the open-source WhatsApp automation library WPPConnect, disabled read receipts. As a result, victims did not notice the mass download of their correspondence in Ukrainian and Russian. At least two former high-ranking Ukrainian officials were targeted in this manner.
The group also targeted video surveillance platforms. The attackers identified authorization vulnerabilities in the application programming interfaces (APIs) of video streaming services from cameras. By exploiting these vulnerabilities, they obtained user lists and stole tokens that granted access to live streams from the victims’ cameras.
The same group infiltrated the systems of a government technology agency in a North African country. The attackers stole the entire database of account records, which contained over 300,000 entries from the national citizen identification system, as well as data from the commercial registry on more than half a million companies operating in the country.
As a reminder, in July it was revealed that a group of Russian hackers had been conducting a cyberespionage campaign over the past year targeting American scientists in the nuclear sector, defense contractors, and government officials.
Підтримати нас можна через:
Приват: 5169 3351 0164 7408 PayPal - [email protected] Стати нашим патроном за лінком ⬇
Subscribe to our newsletter
or on ours Telegram
Thank you!!
You are subscribed to our newsletter