The company Anthropic published a Threat Intelligence report documenting a series of attempts to abuse its Claude artificial intelligence models by a state-backed hacking group. According to the developers, over the past eight months the attackers have actively integrated AI into every stage of their cyber operations, reducing the human role to that of a supervisor. The targets of the attacks were officials in the governmental, military, and diplomatic sectors of Ukraine. All identified accounts were blocked, and the collected data was used to strengthen the protective mechanisms of Anthropic's products.

Methods: From Phishing to "Invisible" Malware

According to the report, the hacking group used Claude models at virtually every stage of its operations. The documented tactics included automated phishing campaigns, interception of Wi-Fi data in hotels, and unauthorized access to WhatsApp accounts. Particular attention from the analysts was drawn to a development in which the attackers created a system that automatically detects when malware is blocked by antivirus solutions and rewrites it until it becomes "invisible" to security tools. This approach indicates a shift to a model in which AI performs routine and even creative tasks in bypassing defenses, while the human merely controls the overall vector of the attack.

Link to Midnight Blizzard and the Russian SVR

Anthropic's analysts note that the tactics of the identified group match the operational profile of the Russian APT group Midnight Blizzard, which, according to Western intelligence services and cybersecurity laboratories, is linked to the Foreign Intelligence Service of the Russian Federation. Midnight Blizzard is known for a series of targeted attacks on diplomatic and military facilities in Europe and the post-Soviet space. The use of a commercial AI tool to scale operations of this level is, in the assessment of experts, a qualitatively new stage in the tactics of state-sponsored hacking groups.

GuardBreaker and STOCKSTAY: Parallel Attack Vectors

Separately, in the context of cyber threats against Ukraine, a technique called GuardBreaker is mentioned, through which Russian cybercriminals forced language models to skip file checks, thereby "blinding" AI-based protection and leaving malicious software undetected during attacks on energy and transport facilities. In addition, specialists at the Google Threat Intelligence Group identified the spy .NET backdoor STOCKSTAY, through which hackers attacked Ukrainian government agencies and military departments, as well as European diplomatic missions, disguising the virus as legitimate system utilities. The totality of these incidents paints a picture of multi-vector pressure on Ukrainian infrastructure using both classic and AI-assisted methods.

Contradictory Data

Discrepancies in chronology and emphasis are noted in the available sources. The Anthropic report, according to the text of the base material, covers "the last eight months," however the exact publication date of the report varies across outlets: the source newsru.co.il dates the publication to November 16, 2025, while RFI publishes the material on September 11, 2026. If the eight-month count is taken from November 2025, the period covers March–November 2025; if from the current date — January–September 2026. The eight-month difference between these interpretations does not allow one to definitively determine whether this is the same report or sequential publications. Moreover, the RFI article's headline emphasizes "weapon creation," whereas the main text of the report and other sources focus specifically on cyberattacks. Perhaps the RFI wording reflects a broader interpretation of the potential of AI tools, however in the primary Anthropic text the emphasis is placed on cyber operations.

Anthropic's Response and Outlook

Anthropic stated that all detected accounts through which the abuse was carried out have been blocked, and the data obtained was used to strengthen the protection of the company's products. The company emphasizes that the incident became the first documented case of using the Claude chatbot for a large-scale AI cyberattack. Cybersecurity experts note that the integration of commercial LLMs into the arsenal of state hacking groups lowers the barrier to entry for conducting complex targeted operations and requires defenders to revisit their approaches to detecting attacks in which malicious code is generated and adapted on the fly with the help of AI.