Russia-linked hackers used Claude in major cyberespionage campaign

653     0
Russia-linked hackers used Claude in major cyberespionage campaign
Russia-linked hackers used Claude in major cyberespionage campaign

A Russia-linked hacker group has used Claude for a large-scale espionage campaign against Ukrainian state structures, military drone manufacturers, and organizations in Europe.

This is stated in a new report by Anthropic. The company writes that its identification of the group aligns with public data on Midnight Blizzard — hackers whom the US and the UK link to Russia’s Foreign Intelligence Service.

According to Anthropic, the group targeted more than 20 organizations, including ministries, intelligence and defense agencies, embassies, think tanks, and defense industry enterprises. Most of the targets were located in Ukraine and Europe. The hackers automated a significant portion of their operations using Claude-based AI agents: they were involved in reconnaissance, phishing, system infiltration, and data theft. The hackers also scanned the email services and remote access systems of more than two dozen Ukrainian state organizations.

One of the primary targets was the Ukrainian drone industry. The hackers dumped the contents of the mailboxes of at least two drone component manufacturers, attacked a military drone manufacturer, and stole a software development kit (SDK) for a drone computer vision system. They then spent several days studying the system, reconstructing the product’s architecture, its list of components, supplier dependencies, and information about a yet-to-be-unveiled product. According to Anthropic, firmware related to the control of military drones and machine vision was of particular interest.

AI agents were used at virtually all stages of the attacks. They gathered data on potential targets, helped create and maintain phishing infrastructure, executed commands within the victims’ systems, stole credentials, and processed hundreds of gigabytes of stolen information. The agents performed some tasks autonomously: for example, they monitored whether security systems were detecting the group’s malware, and if the program started being recognized, they independently modified and recompiled it until it became undetectable again.

One of the group’s operators, according to Anthropic, speaks Russian and uses the nickname JackPoterz. The company considers his methods and choice of targets to be characteristic of Russian state-sponsored cyberespionage.

The hackers also breached at least three hotel Wi-Fi network providers. Having gained administrative access, they redirected guest traffic to servers under their control and attempted to infect Windows, Android, and iOS devices. They were particularly interested in people linked to Ukraine, including officials and employees of drone manufacturing companies. Anthropic notes that Microsoft described this same technique in July under the name CaptiveCrunch.

According to data from Microsoft Threat Intelligence, hackers linked to Midnight Blizzard intercepted hotel Wi-Fi traffic worldwide and installed malware on victims’ devices under the guise of browser or operating system updates. Microsoft reported at the time that artificial intelligence helped conduct a significant part of the group’s operations.

Anthropic now provides additional details on this operation. Specifically, the hackers intercepted WhatsApp accounts and stealthily dumped correspondence in Russian and Ukrainian languages. In this manner, they attacked at least two former high-ranking Ukrainian officials. Furthermore, the group found vulnerabilities in video surveillance services that allowed them to gain access to live camera feeds.

Another target was a state technological structure in a North African country. The hackers, as Anthropic claims, gained control of its central account server and stole a database with more than 300,000 national identity card records, as well as registry data on over half a million companies. The company blocked accounts linked to the group and passed the information to authorities and industry partners.

Editorial Team

Emma Davis

Deputy Editor

Microsoft, Military, Ukrainian, Foreign intelligence, Cybersecurity, WhatsApp, Malware, Phishing, Cyberattacks, Artificial Intelligence, Anthropic, Europe, Ukraine, Russia

Read more similar news:

01.02.2023, 10:09 • Crime
Russian model killed after calling Putin a 'psychopath' was strangled by her ex
01.02.2023, 18:17 • Politics
Give Ukraine western fighter jets to fight Russians, urges Boris Johnson
02.02.2023, 05:21 • World
Ukrainian civilians 'made to cross minefields to find safe path' by Russian army
02.02.2023, 12:25 • Investigation
Russian tank commander takes out five of his own men in huge tank blunder
02.02.2023, 17:44 • World
Russian soldiers must be on drugs to commit 'very violent acts' seen in Ukraine
03.02.2023, 13:12 • Sport
Olympic chiefs warn Ukraine against boycotting Paris 2024 after Zelensky claim
03.02.2023, 14:56 • World
Vladimir Putin plotting ‘maximum escalation’ of war ahead of year anniversary
03.02.2023, 19:34 • World
Ukraine claims it's killed 130,000 Russian troops in year since Putin invaded
04.02.2023, 18:56 • Sport
Team GB 'unlikely' to support Olympics boycott over Russian athletes
06.02.2023, 22:30 • Politics
Speed-up UK weapons production to replace arms sent to Ukraine, warns Labour