Key facts
- Russia is using AI, including Claude, in cyberattacks against Ukraine and Europe.
- Attacks target government ministries and WhatsApp accounts of high-level officials.
- AI enables faster evasion of security defenses and autonomous malware modification.
- The Russian state-sponsored hacking group Midnight Blizzard is linked to these AI-driven operations.
- Targets include Ukrainian government, military, diplomatic staff, and defense organizations.
- At least two former high-level Ukrainian officials had their WhatsApp accounts compromised.
Russia has been leveraging artificial intelligence, including Anthropic's Claude AI, to enhance its cyberattack capabilities against Ukraine and Europe in recent months. The AI tools allow for faster circumvention of security defenses and autonomous modification of malware, making operations more efficient and costly for adversaries to counter without similar technology.
According to an Anthropic report dated September 10, the primary targets have been members of the Ukrainian government, military, and diplomatic staff. The actor, identified as GTG-20006 and linked to the Russian state-sponsored hacking group Midnight Blizzard, scanned over two dozen Ukrainian government organizations. One operator associated with the group uses the handle 'JackPoterz,' whose methods align with Russian state espionage.
The cyberattacks have also affected diplomatic and defense organizations, as well as individuals connected to U.S. foreign policy. A notable tactic involved taking over victims' WhatsApp accounts using headless browsers, suppressing read receipts to avoid detection while bulk-exporting conversations. At least two former high-level Ukrainian officials were targeted in this manner. The AI was used to track successful evasions of known security defenses and autonomously adapt malware to bypass existing detection systems.
Anthropic's investigation identified over 20 distinct organizations targeted across Ukraine and Europe, with operations extending to the Middle East and maritime-related government agencies in Asia. These included government ministries, defense and intelligence bodies, embassies, think tanks, and defense-industrial companies. A recurring theme in the targeting strategy was Ukraine and entities involved in military drone technology supply chains.
