Friday, September 11, 2026

News

Anthropic Exposes Russian Espionage Campaign and Disinformation Networks Using Claude

CybersecurityPatryk Raba

A new Anthropic report describes how a Russian group linked to Midnight Blizzard used Claude to attack Ukrainian government institutions, while French and Turkish networks built disinformation operations reaching millions of fake accounts on top of the model.

Contents
  1. Russian spies and Claude
  2. Disinformation factories
  3. Model copying at industrial scale
  4. Why Anthropic is disclosing this

Anthropic has published another report on abuses of its AI models, this time focused on espionage, disinformation, and the illicit copying of Claude by Chinese labs. The report describes how a Russian group linked to Midnight Blizzard used the model to attack Ukrainian government institutions, while commercial networks from France and Turkey built factories of fake content and social media accounts on top of Claude.

Russian spies and Claude

According to Anthropic, the group designated GTG-20006, whose modus operandi matches the known Russian actor Midnight Blizzard, ran operations targeting Ukrainian government, military, and diplomatic institutions, as well as defense contractors and drone manufacturers. The operator, using the alias JackPoterz, used Claude at nearly every stage of the attack, from reconnaissance of targets, through setting up phishing infrastructure, to data exfiltration.

The group's arsenal included malware named PowerChrome, WUEngine, Shadow C2, MiniPlasma, and CloudSyncSvc for Windows, as well as GiftDrop for Android and DarkSword for iOS. The attackers breached defenses through device-code phishing aimed at cloud email services, hijacking hotel Wi-Fi networks via compromised hospitality service providers, and taking over WhatsApp accounts using headless browsers.

A year ago, if someone wanted to optimize a drone or missile software, the models just weren't as good at it as they are now - Jacob Klein, head of Anthropic's threat intelligence team

Disinformation factories

The second major thread of the report concerns commercial disinformation networks. The network designated GTG-54002, linked to the French digital advertising agency LKM Company, published at least 8,913 articles in about 20 languages through 70 fake news sites, backed by 70 affiliated X accounts and more than 250 inauthentic commenting accounts. The content reached audiences on six continents, with particular focus on the United States, Brazil, France, and the Democratic Republic of Congo.

A separate network, GTG-84005, linked to the Turkish firm BBS Bilisim Teknolojileri based in Istanbul, focused on Malaysia. The operators launched around a thousand fake X accounts and one synthetic news portal, and in their own materials demanded millions of artificial views for the account of a senior Malaysian official. The campaign microtargeted 222 parliamentary constituencies using census and electoral data, playing on racial, religious, and monarchy-related divisions.

Model copying at industrial scale

The report also describes a seventh category of misuse, illicit distillation, meaning the unauthorized copying of Claude's capabilities. Anthropic says seven labs from China, including Alibaba, Moonshot, DeepSeek, and Xiaomi, engaged in such activity. Alibaba's operators allegedly accounted for the largest of these attacks, sending 151 million queries through the model between May and July 2026, from more than 3,500 accounts Anthropic describes as fake, reaching nearly 3 million queries a day at peak.

Moonshot and DeepSeek, meanwhile, allegedly routed their customers' live conversations through Claude and used the resulting responses as training data for their own models. Anthropic distinguishes this from legitimate knowledge transfer, defining illicit distillation as covert data harvesting conducted at industrial scale without consent.

Why Anthropic is disclosing this

The company stresses that it is publishing the details of these abuses even though some of the information is hard to verify independently, since outside researchers lack access to the underlying data, prompts, or network indicators behind Anthropic's findings.

We are publishing this work because we believe we have an obligation to disclose malicious use of our services - Anthropic

Anthropic also notes that newer, more powerful models require stricter safeguards than older versions, since they can assist with tasks they previously refused, for example research into biological weapons. The company openly admits that with its latest models it cannot offer the same safety guarantees that older, weaker versions of Claude provided.

For Polish companies and institutions, the report is another signal that the barrier to entry for AI-driven cybercrime and disinformation operations keeps falling. Groups that once needed resources comparable to state intelligence services can now automate target reconnaissance, phishing preparation, and defense evasion using a widely available language model, a development that directly affects sectors such as public administration and defense, regularly named in Poland as targets of AI-assisted attacks.

Anthropic says that in each of the described cases it banned the accounts responsible for the abuse, strengthened its safeguards based on what it learned, and, where warranted, shared information with law enforcement and industry partners. The company does not disclose, however, whether or how this has changed in practice for Claude's availability to ordinary users.

Share: