Russian spies ran a campaign against Kyiv on Anthropic’s Claude, and the AI chatbot’s maker caught them at it
A Russian state-linked espionage group ran much of its campaign against Ukraine on Claude, the AI assistant sold by US company Anthropic, which set out the case in a threat report published on 10 September, covering activity it disrupted between December 2025 and August 2026. Ukrainian government, military, and diplomatic staff recurred most often among the targets, with the drone supply chain second. Other Russian users of the same chatbot produced on-air tickers and voiceover scripts for state broadcasters, while Russian-speaking criminals went after the AI industry itself.
Ukrainian ministries and diplomats led the target list
Anthropic tracks the group as GTG-20006 and says its attribution matches public reporting that links it to Midnight Blizzard, a hacking group the US and UK governments attribute to Russia's SVR foreign intelligence service. A Russian-speaking operator using the handle JackPoterz ran campaigns against military intelligence targets in Ukrainian and European governments, plus diplomatic and defense bodies and individuals connected to US foreign policy.
More than 20 organizations appeared in the actor's planning and live operations, from ministries and embassies to think tanks and defense companies. Ukrainian government, military, and diplomatic staff came up most often, and the operators scanned email and remote-access systems across more than two dozen Ukrainian state organizations. Russia has worked these networks all war, treating Ukrainian media as a priority cyber target.
Drone technology was the other target
The operators bulk-exported the mailboxes of at least two drone component manufacturers and went after a military drone maker. They also stole a complete proprietary software development kit for a drone vision system, the code and documentation engineers need to build on that hardware, then spent days pulling it apart. They recovered the product architecture, the parts list, the supplier dependencies, and details of a product the company had not announced. Military drone control and AI vision firmware drew their particular interest.
To reach people indirectly, the group also compromised at least three vendors running hotel guest WiFi and redirected guests to its own servers, pushing malware at their devices and hunting for Ukrainian officials and drone manufacturers. To reach people indirectly, the group also compromised at least three vendors running hotel guest WiFi and redirected guests to its own servers, pushing malware at their devices and hunting for Ukrainian officials and drone manufacturers. Microsoft documented the same method on 31 July, calling it CaptiveCrunch and tracing it to a Midnight Blizzard sub-cluster. Russian services have tracked the weapons pipeline before, tapping private cameras in Europe to watch arms shipments bound for Ukraine.
What the chatbot did for the operation
Claude fingerprinted mail systems, built the phishing infrastructure, ran commands inside victim networks, harvested credentials, and organized hundreds of gigabytes of stolen data, Anthropic found. Automated agents also checked whether the group's implants were being detected, rewrote flagged malware until it passed, and staged it for the next intrusion. The operators also seized WhatsApp accounts and targeted at least two former high-level Ukrainian officials that way, and stole cloud email from at least eight bodies, including a national prosecutor office and a military education institute.
Russian state media used the same chatbot
Four individual operators fed state outlets, among them a former Sputnik Moldova editor-in-chief. Anthropic says content generated with Claude reached Sputnik Moldova, RIA Novosti, Sputnik en Español, Sputnik Africa, and RT's English newsroom, including fabricated claims about Moldova's President Maia Sandu before the parliamentary election of 28 September 2025.
A Russian-speaking operator in Bangui also supplied daily material to Radio Lengo Songo, a station investigators say the Wagner Group founded and funded in 2017, coordinating with RT, Sputnik Afrique, and TASS.
Two crews went after the AI company itself
A Russian-speaking actor moved from hotel-booking and fintech intrusions to attacking AI firms, planting instructions in one vendor's testing system and hitting roughly 30 companies in four days while chasing an unreleased Claude model. The hunt for the model failed, though the actor did take production API keys from that testing system, and Anthropic says its own systems were never breached. A Russian- and Ukrainian-speaking group meanwhile sold fake discounted access to the assistant, routing customers to a different model and stealing their logins.