news.mlab.sh
Back to the feed
threat-intel

Anthropic caught Russia-linked spies using Claude in hacking operations

High
Summary

Anthropic has revealed that Russia-linked cyber espionage groups, including affiliates of Midnight Blizzard (also known as BlueBravo, APT29, and Cozy Bear), have been utilizing its Claude AI tool for a range of malicious activities, including hacking government, intelligence, and defense organizations. The company disrupted several campaigns, sharing indicators of compromise (IOCs) with authorities and partners. Claude was used to reverse-engineer drone vision systems, identify vulnerabilities, scan for credentials, and even adapt to security product detections, effectively flipping the cost of defense back onto security teams. The report highlights a broader trend of AI lowering the barrier to entry for cyber operations, enabling both state-backed actors and smaller groups to conduct sophisticated attacks.

Anthropic has disclosed that Russia-linked cyber espionage groups, including affiliates of Midnight Blizzard (also known as BlueBravo, APT29, and Cozy Bear), have been leveraging its Claude AI tool in a series of hacking operations targeting government, intelligence, diplomatic, and defense organizations. The company’s threat report, covering activity between December 2025 and August 2026, details how these groups utilized Claude for a variety of malicious purposes.

In one instance, the spies compromised hotel Wi-Fi providers and altered DNS records to redirect travelers to attacker-controlled infrastructure. Anthropic cited Microsoft’s investigation linking the activity to Storm-2945, a sub-cluster of Midnight Blizzard. The hackers repeatedly targeted members of the Ukrainian government, military, and diplomatic staff, alongside entities involved in the drone supply chain. After gaining access to mailboxes from two drone-component manufacturers, they “targeted a military drone maker, and stole a complete proprietary software development kit for a drone vision system.”

Claude was then used to reverse-engineer the drone’s vision system, “recovering its product architecture, its hardware bill of materials, its supplier dependencies, and details of an unannounced product.” The report emphasizes that AI is narrowing the gap between state-backed groups and smaller operators by reducing the labor and expertise needed to run complex campaigns.

Beyond drone-related activities, the group used AI to monitor whether security products were detecting their hacking tools. “When their implants were flagged by security products, the actor used Claude to systematically identify, modify and redeploy the detected artifacts,” the report stated.

Furthermore, a Chinese-speaking group, including two undergraduates at a Chinese university in Hunan, utilized Claude in an “autonomous vulnerability research program.” The centerpiece of this program was sustained research against a major security product, resulting in several zero-day vulnerabilities. A French-speaking hacktivist also employed Claude in attacks on several European political parties, media organizations, and think tanks, though the specific motivations behind these attacks were not detailed.

The company noted that AI is not replacing traditional attack methods, such as phishing, stolen credentials, and software vulnerabilities, but it is significantly altering the landscape of cyber operations. The Five Eyes intelligence alliance had previously warned about the potential for frontier AI models to transform both offensive and defensive cyber capabilities.

Anthropic emphasized that the disclosure of this information is driven by a commitment to transparency and a responsibility to share malicious misuse of its services, acknowledging that AI’s increasing capabilities necessitate proactive measures from AI developers and cybersecurity defenders.

Read the full article at The Record