Russia-linked hackers used Claude in major cyberespionage campaign

654     0
Russia-linked hackers used Claude in major cyberespionage campaign
Russia-linked hackers used Claude in major cyberespionage campaign

A Russia-linked hacker group has used Claude for a large-scale espionage campaign against Ukrainian state structures, military drone manufacturers, and organizations in Europe.

This is stated in a new report by Anthropic. The company writes that its identification of the group aligns with public data on Midnight Blizzard — hackers whom the US and the UK link to Russia’s Foreign Intelligence Service.

According to Anthropic, the group targeted more than 20 organizations, including ministries, intelligence and defense agencies, embassies, think tanks, and defense industry enterprises. Most of the targets were located in Ukraine and Europe. The hackers automated a significant portion of their operations using Claude-based AI agents: they were involved in reconnaissance, phishing, system infiltration, and data theft. The hackers also scanned the email services and remote access systems of more than two dozen Ukrainian state organizations.

One of the primary targets was the Ukrainian drone industry. The hackers dumped the contents of the mailboxes of at least two drone component manufacturers, attacked a military drone manufacturer, and stole a software development kit (SDK) for a drone computer vision system. They then spent several days studying the system, reconstructing the product’s architecture, its list of components, supplier dependencies, and information about a yet-to-be-unveiled product. According to Anthropic, firmware related to the control of military drones and machine vision was of particular interest.

AI agents were used at virtually all stages of the attacks. They gathered data on potential targets, helped create and maintain phishing infrastructure, executed commands within the victims’ systems, stole credentials, and processed hundreds of gigabytes of stolen information. The agents performed some tasks autonomously: for example, they monitored whether security systems were detecting the group’s malware, and if the program started being recognized, they independently modified and recompiled it until it became undetectable again.

One of the group’s operators, according to Anthropic, speaks Russian and uses the nickname JackPoterz. The company considers his methods and choice of targets to be characteristic of Russian state-sponsored cyberespionage.

The hackers also breached at least three hotel Wi-Fi network providers. Having gained administrative access, they redirected guest traffic to servers under their control and attempted to infect Windows, Android, and iOS devices. They were particularly interested in people linked to Ukraine, including officials and employees of drone manufacturing companies. Anthropic notes that Microsoft described this same technique in July under the name CaptiveCrunch.

According to data from Microsoft Threat Intelligence, hackers linked to Midnight Blizzard intercepted hotel Wi-Fi traffic worldwide and installed malware on victims’ devices under the guise of browser or operating system updates. Microsoft reported at the time that artificial intelligence helped conduct a significant part of the group’s operations.

Anthropic now provides additional details on this operation. Specifically, the hackers intercepted WhatsApp accounts and stealthily dumped correspondence in Russian and Ukrainian languages. In this manner, they attacked at least two former high-ranking Ukrainian officials. Furthermore, the group found vulnerabilities in video surveillance services that allowed them to gain access to live camera feeds.

Another target was a state technological structure in a North African country. The hackers, as Anthropic claims, gained control of its central account server and stole a database with more than 300,000 national identity card records, as well as registry data on over half a million companies. The company blocked accounts linked to the group and passed the information to authorities and industry partners.

Editorial Team

Emma Davis

Deputy Editor

Print page

Comments:

comments powered by Disqus