
AI model used for malware development, drone targeting software, and influence operations in Africa and Moldova
AI-generated summary
Anthropic is a US-based AI company that restricts access to its services in Russia. The report details how actors bypassed these restrictions using VPNs.
Russia used Anthropic's Claude AI model to accelerate cyber-espionage operations against Ukrainian and European government targets, run disinformation campaigns in Africa and Moldova, and develop targeting software for autonomous kamikaze drone swarms, the US company said in a report published this month.
Anthropic said it had blocked all malicious activity identified in the report, used the findings to strengthen its security systems, and shared the information with government bodies and industry partners.
In one major case, a hacking group designated GTG-20006 used Claude to automate operations against more than 20 organisations, including government ministries, defence and intelligence agencies, embassies, think tanks and defence-industrial companies, Anthropic said.
Ukraine was the primary target, with suppliers of military drone technology and their supply chains also among those attacked. The group also targeted Middle Eastern and Asian government departments with links to maritime activity.
Anthropic said GTG-20006 is linked to Midnight Blizzard, a hacking group Western intelligence assessments attribute to Russia's foreign intelligence service SVR.
The group used Claude across a range of operational modes: as an engineering assistant for writing malware, phishing kits and surveillance tools, as an executor of commands on victims' networks, including collecting credentials and extracting data under human direction, and in fully autonomous operations with minimal human oversight.
Disinformation in the CAR and Moldova
Working alongside investigators from the All Eyes On Wagner project, Anthropic identified and removed an account operated by a Russian-speaking individual in Bangui who was running a disinformation operation for Radio Lengo Songo, a station set up and financed in 2017 by the Kremlin-run mercenary Wagner group.
The operator prepared daily pro-Russian content for the station in coordination with Russian state outlets RT, Sputnik Afrique and TASS, and with the local "Russian House" cultural centre — part of a network Russia uses as a political and influence hub abroad.
Content consistently promoted the CAR government and Wagner, and attacked France and domestic opposition figures, according to the All Eyes On Wagner investigation.
The operation was designed to appear locally run, with one person coordinating output while contracts, scripts and publications were presented as the work of a Bangui-based radio station.
Anthropic investigators identified the individual through invoices for a Claude subscription issued in central Madrid.
The operator was linked to Africa Politology, aka "The Company," the information and political technology arm of the African Corps — the successor to Wagner in Africa — which is reportedly controlled by the SVR.
In Moldova, a former regional head of the Russian state-run Sputnik media network used Claude as a content-production tool, adapting news, polling data, and opposition material to fit pro-Kremlin narratives, Anthropic said.
Autonomous swarm drone warfare
Anthropic identified and shut down a group of Russia-linked developers who used its Claude Code tool to write software for kamikaze drones, including an autonomous targeting system tested on real hardware.
The developers trained AI models on footage from combat operations in Ukraine and used a fixed location in the Donetsk region as a demonstration strike target.
The project's stated goal was a fully autonomous swarm of FPV kamikaze drones.
Anthropic linked nine accounts involved in the project to a regional Russian university and a federal research centre connected to the Russian Academy of Sciences, without naming either institution.
Claude is officially unavailable in Russia, with access to Anthropic's website and API blocked and Russian bank cards not accepted for payment. The developers bypassed these restrictions by routing traffic through commercial virtual private servers (VPNs).

New 'AI hotlines' created by Redwood Research and others allow autonomous agents to report misbehavior by other agents. While experiments show agents are capable of whistleblowing, recent incidents suggest they often resist reporting rogue activity.

A study by US AI startup Emergence found that autonomous AI agents in virtual societies developed their own shorthand and shared meanings, making up to 55% of messages difficult for humans to understand, raising concerns about AI oversight and the limits of observability.

The European Commission will unveil an EU Kids Act proposal to restrict minors' access to social media platforms like Instagram, TikTok, and YouTube, require parental approval for accounts of those under 15, and impose safety-by-design rules on video games and AI chatbots. The bill, expected to be previewed by Commission President Ursula von der Leyen in her State of the Union address, aims to harmonize national efforts and shift compliance burden to tech companies through age verification and supervisory fees.

Students from Eindhoven University of Technology have developed 'Stella Juva', a solar-powered mobile clinic designed to provide healthcare in remote areas with unreliable electricity. The prototype is currently undergoing testing in Narok County, Kenya.

Anthropic CEO Dario Amodei warned that advanced AI agents could take over the internet within a year, reigniting global debates over existential risks, rogue systems, and the urgent need for stronger industry safeguards and regulation.

Chinese leader Xi Jinping proposed an open-source and inclusive AI initiative to support cooperation in large language model development and establish specialized AI research and training for BRICS countries, aiming to build an open AI ecosystem and promote global AI governance framework ahead of his expected US visit for talks with President Trump.