Russian hackers used Claude AI to attack Ukrainian government agencies and military – Anthropic report

- 11 September, 09:18

Anthropic has said it has detected and disrupted a Russian cyber-espionage campaign targeting Ukrainian government, military and diplomatic organisations. The attackers used Claude models at almost every stage of the attacks and automated parts of the process.

Source: Anthropic in a new Threat Intelligence report

Details: This report covers the malicious use of Anthropic's models over the past eight months. According to the company, AI is increasingly being used not merely as an auxiliary tool but to coordinate and carry out a significant portion of cyber operations.

Anthropic linked the attacks on Ukrainian organisations to the Russian group Midnight Blizzard. The attackers used phishing campaigns, interception of hotel Wi-Fi traffic and WhatsApp account takeovers. Claude was used at virtually every stage of the operation.

AI helped the hackers create and modify malware. Anthropic said they even built a system that automatically checked whether security tools could detect the malicious code and modified it if they did.

The company noted that in such attacks, humans are increasingly acting as supervisors rather than directly carrying out operations. This allows threat actors to automate a much larger proportion of cyber operations.

Anthropic also identified the use of Claude in military programmes in Russia, China and Yemen. The model was used for work related to missiles, drones and munitions, as well as intelligence gathering and procurement.

Jacob Klein, head of cyber threat intelligence at Anthropic, said the growing capabilities of AI were creating new risks. According to Klein, modern models are already significantly better at tasks such as optimising drones or developing missile software than they were just a year ago.

Support Ukrainska Pravda on Patreon to help us keep reporting!