Anthropic has documented and disrupted a cyber operation linked to Russian foreign intelligence that used autonomous AI agents powered by Claude to develop malware and target Ukrainian drone technology, according to a public security report released by the US company.
Anthropic published a detailed investigation into the use of its Claude language model by hackers linked to Russia’s Foreign Intelligence Service (SVR), tracked by cybersecurity researchers under identifiers including Midnight Blizzard and GTG-20006.
According to the report, over the course of a 130-day operation, the Russian state-linked hackers used specially configured autonomous AI agents to target around 27 government bodies and organisations. The campaign focused primarily on Ukrainian government ministries, diplomatic institutions and private Ukrainian companies involved in the production and development of components for unmanned aerial vehicles.
A key objective of the operation was to obtain sensitive technological designs, engineering documentation and specialised software related to Ukrainian drones.
Anthropic said the operation demonstrated how state-linked hackers are increasingly delegating complex stages of cyber operations to autonomous AI agents. Claude was reportedly used to continuously monitor deployed malicious code and, when antivirus software detected it, to rewrite and recompile the code in an attempt to evade security systems.
The hackers also compromised hotel Wi-Fi networks to manipulate DNS records and took control of WhatsApp accounts belonging to former officials.
Anthropic said its security team blocked all identified accounts associated with the operation. The company described the case as evidence of the growing use of autonomous AI capabilities by state-sponsored cyber actors.