14 September 2026

Russian hackers used Claude AI to attack Ukrainian government agencies and military – Anthropic report

Ukrainska Pravda | MYROSLAV TRINKO

Anthropic has disrupted a Russian cyber-espionage campaign targeting Ukrainian government, military, and diplomatic organisations that utilised the Claude artificial intelligence model to automate and execute operations. The threat group Midnight Blizzard deployed the large language model at almost every stage of their campaign, which included phishing, WhatsApp account takeovers, and hotel Wi-Fi traffic interception.

This operational integration allowed the hackers to build automated systems that continuously modified malware to evade detection by security tools. Consequently, human operators increasingly functioned as supervisors rather than direct executors, dramatically scaling cyber operations. Beyond Ukraine, the threat intelligence report identified the illicit use of Claude within military programmes in Russia, China, and Yemen. These activities focused on drone optimisation, missile software development, and intelligence procurement. AI capabilities are expanding rapidly. Jacob Klein, Anthropic’s head of cyber threat intelligence, warned that modern models are significantly more proficient at refining military hardware than last year.

Comment

Midnight Blizzard’s deployment of Claude to automate malware modification represents a significant evolution in offensive cyber operations. By integrating Claude into a closed-loop testing system, Midnight Blizzard bypassed traditional signature-based security tools without requiring manual code rewrites. This shift transitions Russian operators from active developers to high-level supervisors of automated exploit pipelines targeting Kyiv's ministries. Consequently, the speed of tactical cyber reconnaissance against Ukrainian networks has accelerated beyond manual defensive response times.

This automated evasion technique mirrors the introduction of the Dark Avenger Mutation Engine in 1992, which first automated polymorphism to defeat early antivirus software. While that historical tool relied on static cryptographic randomisation, the integration of Claude allows for dynamic, context-aware code restructuring. This evolution suggests that future cyber conflicts along the Dnipro will be defined by autonomous, Claude-mutated payloads competing against Ukraine's AI-enabled defensive scanners in real-time.

Strategic Question for Discussion
If offensive groups like Midnight Blizzard continue to leverage Claude for dynamic code mutation, how can defensive frameworks transition away from signature-based detection when the Dark Avenger style of static polymorphism has been supercharged by generative AI?
The trajectory indicates a necessary transition toward real-time behavioural analysis and heuristic monitoring at the endpoint level. My assessment is that traditional signature databases will face rapid obsolescence as Claude-enabled mutation pipelines generate unique, non-repeating payloads for every target. Consequently, effective mitigation likely relies on deploying specialised, local AI models capable of detecting anomalous process execution rather than waiting for centralised threat intelligence updates.
Share your assessment in the comments below.