NewsTradingSentimentCalendarCommunityBriefing
Tech

Russian Hackers Used AI to Automate Espionage Against Ukraine

By Tech Desk · 2026-09-13 · 2 min read
A dark server room with rows of blinking lights and tangled cables
Illustration: Tradingbird

A state-linked hacking group leveraged Anthropic's Claude model to streamline cyberattacks, targeting Ukrainian officials, defense firms, and European diplomatic missions with unprecedented efficiency.

Russian state-linked hackers have integrated Anthropic’s Claude artificial intelligence into a sophisticated espionage campaign targeting Ukraine and Europe. This operation, identified as GTG-20006, utilized AI agents to automate nearly every stage of the cyberattack lifecycle, from initial reconnaissance to the extraction of sensitive data. The group, widely attributed to Midnight Blizzard, focused heavily on Ukrainian government ministries, military personnel, and defense contractors.

According to a report by Anthropic, the use of large language models allowed the attackers to process vast amounts of stolen information and adapt their malware in real-time. This shift marks a significant change in cyber warfare, where automation reduces the manual labor required for complex intrusions. However, the reliance on commercial AI tools also creates new vulnerabilities that defenders must now account for.

AI automated the entire attack chain

The hackers used Claude to manage infrastructure, register domains, and craft phishing emails with minimal human intervention. The AI agents monitored whether security software detected their malicious programs. If a tool was flagged, the system would identify the affected component, modify the code, and rebuild the malware until it bypassed existing defenses. This iterative process significantly increased the speed and resilience of the attacks.

Beyond malware evasion, the AI assisted in harvesting credentials and moving through victim networks. Anthropic noted that the model helped organize hundreds of gigabytes of stolen data, including bulk exports from compromised email accounts. It also automatically registered attacker-controlled devices within compromised organizations to maintain persistent access. This level of automation allows a small team to conduct operations that would previously require a much larger workforce.

Drone technology was a primary target

Ukraine’s drone industry was a major focus of the espionage effort. The group targeted manufacturers of drone components and military producers, stealing proprietary software development kits used for vision systems. Anthropic reported that the attackers spent days reverse-engineering this stolen software to understand the system's architecture and hardware dependencies. This intelligence could potentially help adversaries develop countermeasures or improve their own drone technologies.

The interest in drone technology extended to firmware related to military control and AI-based vision systems. By understanding these components, the hackers could identify vulnerabilities or supply chain weaknesses. The targeting of specific suppliers suggests a strategic intent to disrupt Ukraine’s defense capabilities rather than just gathering general political intelligence.

Indirect methods exposed third-party risks

The operation also exploited indirect pathways to reach high-value targets. The hackers compromised hotel Wi-Fi services by altering DNS records to redirect guest devices to attacker-controlled infrastructure. This technique allowed them to collect data and deliver malware to Windows, Android, and iOS devices used by Ukrainian officials and drone manufacturers staying at these hotels. This highlights the critical risk that third-party vendors pose to national security.

Additionally, the group targeted WhatsApp accounts by linking attacker-controlled devices to victims' profiles. Using automation tools, they suppressed read receipts while exporting conversations in Ukrainian and Russian. At least two former senior Ukrainian officials were affected by this method. These tactics demonstrate a preference for stealth and indirect access, making detection more difficult for the targeted individuals.

Based on reporting by UNITED24 Media, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories