Anthropic assigned the group the internal designation GTG-20006. The company said its methods and targeting match public reporting on Midnight Blizzard, also known as APT29 and Cozy Bear, a hacking unit that the United States and Britain have tied to Russia's Foreign Intelligence Service. One of the operators speaks Russian and uses the handle JackPoterz, according to Anthropic.
The group's targets included government ministries, intelligence and defense agencies, embassies and think tanks. The hackers probed email services and remote-access systems at more than 20 Ukrainian state organizations.
Ukraine's drone market drew particular attention. The hackers downloaded the contents of mailboxes at at least two manufacturers of drone components and attacked a producer of military unmanned aerial vehicles. In one case they stole a software development kit for a drone computer-vision system. Over the following days they studied the stolen software, reconstructing the product's architecture, its component list and its supplier dependencies. Some of the data concerned a product that had not yet been announced.
To reach individuals, the group hacked hotel Wi-Fi providers. After gaining administrative access to at least three providers, the hackers altered DNS settings and routed guests' traffic through their own infrastructure in an attempt to infect devices running Windows, Android and iOS. People connected to Ukraine were of particular interest.
Anthropic noted that Microsoft described the same technique in July under the name CaptiveCrunch.
WhatsApp accounts were another target. The hackers linked controlled devices as additional ones through the open-source WPPConnect library, configured so that read receipts would not appear. They used this to mass-download conversations in Russian and Ukrainian. Anthropic said it knows of at least two former senior Ukrainian officials attacked this way.
The group also searched for vulnerabilities in video surveillance services. Exploiting authorization flaws, the hackers stole access tokens and watched live feeds from victims' cameras.
The report describes a separate episode involving an attack on a state technology body in a North African country. According to Anthropic, the hackers took control of a central account server and stole a database containing more than 300,000 national identity records and registry data on more than half a million companies.
AI was used at almost every stage of the operations, from gathering information on targets and preparing phishing to breaking into systems, stealing credentials and processing stolen data. The group had its own toolset: five Windows programs (PowerChrome, WUEngine, Shadow C2, MiniPlasma and CloudSyncSvc), an Android trojan called GiftDrop and an iOS exploit chain called DarkSword. Claude helped rework these tools: agents monitored whether antivirus software detected the malware and, when it did, independently modified and rebuilt the program until it again went undetected.
Anthropic blocked accounts tied to the group and passed the information to authorities and industry partners.
In the same report, Anthropic described the use of Claude by Russian pro-government media outlets. The company blocked four accounts whose owners, in its assessment, passed generated material to Sputnik Moldova, RIA Novosti, Sputnik en Español, Sputnik Africa and the English-language editorial desk of RT. According to Anthropic, a former editor-in-chief of Sputnik Moldova used Claude to turn news from Romania and Moldova, polling data and opposition publications into Russian-language articles, including ones with "fabricated and defamatory statements" about Moldovan President Maia Sandu ahead of parliamentary elections in September 2025.
Another episode concerns sanctions evasion. A "procurement manager at a Moscow design bureau" used Claude to look for intermediaries in China and Hong Kong to buy products from European manufacturers. Among the items he sought, Anthropic said, were German triaxial magnetometers, several thousand space triple-junction photovoltaic cells and aircraft oxygen systems. In generated memos for management, the scheme was described outright as a way to circumvent trade restrictions.
The report also mentions a "group of freelancers" from Russia that was designing a swarm of autonomous FPV kamikaze drones. Video recordings of combat in Ukraine were among the material used to train the computer vision.
Separately, Anthropic accused DeepSeek of large-scale distillation, using Claude's responses to train its own models. The company alleged that in some cases DeepSeek quietly routed clients' real requests to Claude Opus without their knowledge. That happened with an IT specialist working with data from a Russian agency tied to the Defense Ministry: his requests contained account credentials for access to a state database.