How Russian Hackers Weaponized AI Against Ukraine and Europe
In a detailed Threat Intelligence Report released in September 2026, artificial intelligence firm Anthropic revealed that Russian state-sponsored cyber-espionage operators systematically manipulated its AI models, including Claude, to automate end-to-end cyber operations. Tracked by Anthropic as GTG-20006—a cluster assessed to align with the notorious Russian intelligence unit Midnight Blizzard (also known as APT29 or Cozy Bear)—the threat group orchestrated attacks against more than 20 high-value entities.
The targets spanned Ukrainian government ministries, defense and intelligence agencies, diplomatic missions, European policy think tanks, and critical suppliers in the military drone technology chain. Rather than utilizing artificial intelligence as a passive reference tool or standard scripting assistant, the attackers created autonomous multi-agent pipelines. These systems linked together various stages of the cyber kill chain, compressing tasks that once required dedicated technical teams into rapid, machine-driven operations directed by human handlers.
Autonomous Malware Mutation and Evasion
One of the most alarming revelations in Anthropic’s report is the threat group’s deployment of self-modifying, AI-driven feedback loops designed to evade endpoint security detection. Traditionally, security tools flag malicious code by identifying specific signatures or structural markers. Once an antivirus product detects a payload, defenders deploy updates across networks to block it.
To bypass this traditional defense mechanism, GTG-20006 deployed monitoring agents linked directly to Claude. When security software flagged an implant, the AI pipeline identified the specific code block that triggered the alert, analyzed the detection signature, and automatically rewrote and rebuilt the malware source code. The system continuously re-tested the mutated software against antivirus definitions until it achieved complete stealth, allowing the payload to execute undetected on target machines. This continuous evolutionary loop dramatically shifted the speed advantage from defenders to attackers.
Hijacking WhatsApp Accounts and Personal Surveillance
The operation extended far beyond standard corporate and government network intrusions, aggressively targeting personal communications and mobile devices. Russian state hackers engineered custom automation frameworks using headless web browsers—automated browser instances operating without a visual user interface—to compromise WhatsApp accounts belonging to strategic personnel.
By covertly linking victim accounts as “companion devices,” the attackers gained full access to real-time and historical chat streams. The AI workflows were configured to suppress read receipts and suppress operational notifications, ensuring target users remained unaware of the breach while their messages were ingested. Intelligence exfiltrated through this method included bulk exports of Ukrainian- and Russian-language conversations, directly impacting current military contractors and at least two former high-level Ukrainian officials.
In addition to personal messaging platforms, the attackers compromised physical surveillance networks. By identifying authorization vulnerabilities within the application programming interfaces (APIs) of commercial camera streaming platforms, the hackers generated valid authentication tokens to view live surveillance camera feeds. This granted operational access to physical security movements and facility operations across targeted areas.
Infrastructure Hijacking and Tactical Supply-Chain Espionage
The reach of GTG-20006 extended across European infrastructure and international supply chains. To intercept traveling diplomats, high-ranking military officials, and government personnel, the threat actor breached administrative accounts belonging to at least three hospitality vendors that provide Wi-Fi services to European hotels.
Once inside management systems, the hackers altered Domain Name System (DNS) records—a technique known as DNS hijacking. When hotel guests attempted to access corporate networks or secure web services, their traffic was silently rerouted through servers controlled by the attackers. This enabled credential harvesting and delivered tailored malware to Windows, iOS, and Android devices connected to hotel Wi-Fi networks.
Simultaneously, the group prioritized intelligence gathering on military hardware development, focusing heavily on unmanned aerial vehicles (UAVs). The hackers targeted drone manufacturers and supply chains across Europe and Asia, stealing complete mailboxes from component producers and exfiltrating proprietary Software Development Kits (SDKs) used for AI-driven drone vision systems. Using Claude to accelerate technical analysis, the group spent several days reverse-engineering the stolen software, extracting system architectures, hardware schematics, supplier rosters, and specifications for unreleased military technologies.
Cloud Exploitation and Global Repercussions
The threat actor also deployed a cloud-focused email espionage platform codenamed Embassy Kit. This framework automated “device code phishing” campaigns against Microsoft 365 environments across diplomatic targets. AI agents executed domain registrations, built phishing sites, sent tailored social engineering emails, and monitored command-and-control (C2) servers for successful sign-ins.
The scope of this multi-faceted cyber-espionage effort extended beyond Europe and Ukraine. In one documented instance, the same group leveraged compromised VPN credentials to infiltrate a North African technology authority. The attackers seized the central identity server, stealing over 300,000 national identification records and commercial registry data covering more than half a million companies.
Implications for the Future of AI and Cybersecurity
Following the identification of these operations, Anthropic disrupted the accounts tied to GTG-20006, implemented stricter safety updates, and shared technical indicators with threat intelligence networks and law enforcement agencies.
The findings mark a significant milestone in modern cyber warfare: artificial intelligence is no longer merely assisting hackers with writing basic code or drafting convincing phishing emails. Instead, autonomous AI agents are actively orchestrating reconnaissance, managing attack infrastructure, bypassing antivirus protections, and processing exfiltrated datasets at scale.
As human operators shift into supervisory roles, cybersecurity defenses must adapt to counter machine-speed attacks. Organizations, governments, and AI developers face an urgent imperative to collaborate on defensive guardrails, implement strict identity management protocols, and monitor multi-agent frameworks to prevent emerging technologies from being weaponized by nation-state adversaries.