Back
Original version

Russians Tried to Use Claude for Attacks on Ukraine, Anthropic Says

Automatically translated version. May contain inaccuracies compared to the original.

Russian hackers attempted to use the artificial intelligence Claude from Anthropic to conduct cyberattacks against the Ukrainian government, military, and diplomatic structures.

Anthropic released Threat Intelligence, a report documenting abuses of its AI technologies over the past eight months. According to the developers, malicious actors are increasingly using AI to organize cyberattacks, leaving humans with only supervisory roles. How hackers attacked Ukraine A state-backed hacking group used Claude models at nearly every stage of its operations. They conducted phishing campaigns, intercepted Wi-Fi data in hotels, and gained access to WhatsApp accounts. All of these attacks targeted Ukrainian government, military, and diplomatic officials. By leveraging AI capabilities, the perpetrators built a system that automatically detected the subtraction of malware by antivirus and rewrote it until it became "invisible" to security tools. Analysts note that the group’s tactics align with the operations of the Russian group Midnight Blizzard, which is linked to Russia’s Foreign Intelligence Service. Not only hacking, but also weaponry and data leakage In addition to cyberattacks against Ukraine, the company identified other threats: Weapon development - Users from Russia, China, and Yemen attempted to use Claude to create software for firearms, missiles, combat drones, and guidance systems. Bioweapons development attempts - Experts blocked several accounts where researchers tried to plan experiments to adapt mammals to avian flu. Attacks on Chinese competitors - Seven Chinese laboratories (including Alibaba, Moonshot, and DeepSeek) carried out mass attacks to intercept Claude responses and use them to train their own AI models. All identified attacker accounts were blocked, and the obtained data used to strengthen Anthropic’s product protections.

Russian hackers attacking Ukraine By the way, this is not the first time Russian hackers have exploited technological vulnerabilities to attack Ukrainian structures. Recently, cybercriminals from the Russian Federation found a way to blind the AI protection during attacks on Ukrainian organizations. The technique, called GuardBreaker, caused language models to fail to verify files, enabling Russian hackers to "break" AI defenses and leave malware undetected during attacks on power and transportation sectors. In addition, Google Threat Intelligence Group researchers uncovered a spying .NET backdoor STOCKSTAY. Using this program, Russian hackers attacked government agencies and military departments of Ukraine, as well as European diplomatic institutions, masking the virus as legitimate utilities.

Open the news PDF proof

Document: PDF proof of the original version of the news item "Для кібератак на Україну росіяни намагалися використати Claude, - Anthropic". It records the publication content at the moment of the first scan, the preservation date and the source: RBC-Ukraine.

Document: PDF proof of the original version of the news item "Для кібератак на Україну росіяни намагалися використати Claude, - Anthropic". It records the publication content at the moment of the first scan, the preservation date and the source: RBC-Ukraine.

Російські хакери намагалися використати штучний інтелект Claude від компанії Anthropic для проведення кібератак проти українського уряду, військових та дипломатичних структур.

Компанія Anthropic оприлюднила звіт Threat Intelligence, у якому задокументувала зловживання своїми технологіями штучного інтелекту за останні вісім місяців. За даними розробників, зловмисники активніше використовують ШІ для організації кібератак, залишаючи людям лише функцію наглядачів. Як хакери атакували Україну Підтримувана державою-агресоркою хакерська група використовувала моделі Claude майже на кожному етапі своїх операцій. Вони проводили фішингові розсилки, перехоплювали дані Wi-Fi у готелях та отримували доступ до облікових записів у WhatsApp. Усі ці атаки спрямовувалися проти посадовців урядового, військового та дипломатичного секторів України. Використовуючи можливості ШІ, зловмисники створили систему, яка автоматично виявляла блокування шкідливого коду антивірусами та переписувала його доти, доки він не ставав "невидимим" для засобів захисту. Аналітики зазначають, що тактика цієї групи відповідає діяльності російського угруповання Midnight Blizzard, яке пов'язують із Службою зовнішньої розвідки РФ. Не лише хакерство, а й зброя та витік даних Крім кібератак на Україну, компанія виявила й інші загрози: Розробка зброї - Користувачі з Росії, Китаю та Ємену намагалися використовувати Claude для створення програмного забезпечення для вогнепальної зброї, ракет, бойових безпілотників та систем наведення. Спроби розробки біозброї - Фахівці заблокували кілька акаунтів, де дослідники намагалися спланувати експерименти з адаптації ссавців до пташиного грипу. Атаки на китайських конкурентів - Сім китайських лабораторій (зокрема Alibaba, Moonshot та DeepSeek) здійснювали масові атаки, щоб перехопити відповіді Claude і використати їх для навчання власних моделей ШІ. Усі виявлені акаунти зловмисників було заблоковано, а отримані дані використано для посилення захисту продуктів Anthropic.

Російські хакери атакують Україну Нагадаємо, це не перший випадок, коли російські хакери використовують технологічні уразливості для атак на українські структури. Нещодавно кіберзлочинці з РФ знайшли спосіб "засліпити" захист штучного інтелекту під час атак на українські організації. Техніка під назвою GuardBreaker змушувала мовні моделі відмовлятися від перевірки файлів, через що російські хакери "ламали" ШІ-захист і залишали шкідливе програмне забезпечення непоміченим під час атак на енергетику та транспорт. Крім того, фахівці Google Threat Intelligence Group виявили шпигунський .NET-бекдор STOCKSTAY. За допомогою цієї програми російські хакери атаковували урядові структури та військові відомства України, а також європейські дипломатичні установи, маскуючи вірус під легітимні утиліти.

Open the news PDF proof

Document: PDF proof of the original version of the news item "Для кібератак на Україну росіяни намагалися використати Claude, - Anthropic". It records the publication content at the moment of the first scan, the preservation date and the source: RBC-Ukraine.

Document: PDF proof of the original version of the news item "Для кібератак на Україну росіяни намагалися використати Claude, - Anthropic". It records the publication content at the moment of the first scan, the preservation date and the source: RBC-Ukraine.

Download Download PDF