A Russian-linked hacking operation used Anthropic’s Claude artificial intelligence models to automate cyberespionage targeting Ukrainian government officials, military personnel, diplomats, defense companies, and drone technology suppliers, with more than 20 organizations identified as targets.
We bring you stories from the ground. Your support keeps our team in the field.
According to a threat intelligence report published by Anthropic on September 10, the company tracked the group as GTG-20006 and said its attribution was consistent with public reporting linking the activity to Midnight Blizzard, a Russian state-linked hacking group.
Anthropic said the hackers used customized AI-driven workflows to automate much of the attack process, including reconnaissance, acquiring infrastructure, phishing, maintaining access to compromised systems, and extracting stolen information.
The company identified more than 20 organizations targeted during planning, reconnaissance, or active operations. They included government ministries, intelligence and defense agencies, diplomatic missions, think tanks, and defense companies, primarily in Ukraine and Europe.
Ukrainian government, military, and diplomatic personnel were among the most frequent targets. The group scanned email and remote-access systems belonging to more than two dozen Ukrainian government organizations, according to Anthropic.
Drone technology was another major focus. The hackers exported mailboxes belonging to at least two drone component manufacturers, targeted a military drone producer, and stole a proprietary software development kit used for a drone vision system.
Anthropic said the attackers spent several days reverse-engineering the stolen software, reconstructing the system’s architecture, hardware components, supplier dependencies, and details of an unreleased product. Firmware related to military drone control and AI-based vision systems appeared to be of particular interest.
-a0902ae83e97e414cb136d1d1deafaf8.jpg)
Claude was also incorporated into malware development and evasion. Anthropic found that AI agents monitored whether security software detected the group’s malicious programs. When a tool was flagged, the system could identify the affected component, modify it, rebuild the malware, and repeat the process until existing security products no longer detected it.
The hackers also used AI to research and register domains, configure phishing infrastructure, send malicious emails, monitor successful compromises, harvest credentials, and move through victims’ networks.
According to Anthropic, Claude assisted with processing and organizing hundreds of gigabytes of stolen information, including bulk exports from compromised email accounts. The AI was also used to help preserve access to infiltrated systems and automatically register attacker-controlled devices inside compromised organizations.
The operation sometimes targeted organizations connected to intended victims rather than attacking them directly. Anthropic said the hackers compromised at least three companies providing hotel guest Wi-Fi services and changed DNS records to redirect connected devices toward infrastructure controlled by the attackers.
The technique allowed the group to collect information about hotel guests and deliver malware to Windows, Android, and iOS devices. Individuals connected to Ukraine, including government officials and drone manufacturers, were among the targets.

The hackers also targeted WhatsApp accounts by linking attacker-controlled devices to victims’ profiles. Using automation tools, they suppressed read receipts while exporting conversations in Ukrainian and Russian. Anthropic said at least two former senior Ukrainian officials were targeted through the method.
In another part of the operation, the group exploited authorization weaknesses in video surveillance services to obtain tokens providing access to victims’ live camera feeds.
The same actor was linked by Anthropic to an intrusion into a North African government technology agency, where hackers stole a database containing more than 300,000 national identity records and commercial registry information covering more than half a million companies.
Russian-linked hackers have also been tied to major cyberattacks against Western companies. In June, The New York Times reported that Russian hackers were behind the 2025 attack on Jaguar Land Rover, which halted production for five weeks and caused an estimated $2.5 billion in damage to the UK economy.
-9a7b3a98ed5c506e0b77a6663f5727c5.png)
Click Here For The Original Source.
