Opens in a new tab

Russian hackers used AI in attacks as Houthis developed weapons

Tuesday 15th September 2026 on 10:45 in Estonia

artificial intelligence, cyberattacks, Russia

Russian hackers used Anthropic’s Claude artificial intelligence model in cyberattacks, while Houthi rebels tried to use it to code weapon guidance systems, ERR reports, citing a threat intelligence report published by Anthropic last week.

According to the report, the Russian government-backed cyber group GTG-20006 used AI to increase the speed of its operations through automation. The group has also been linked to Midnight Blizzard, which is associated with Russia and has reportedly tried to attack Microsoft since 2023 to gain access to email addresses and the company’s source code.

One operator identified in the report used the alias JackPoterz. The operator’s methods and choice of targets indicated Russian espionage, the report said.

The group targeted military intelligence agencies in Ukraine and Europe, as well as diplomatic and defence organisations and people linked to US foreign policy. AI was used to automate several stages of the attacks, including development, infrastructure acquisition, phishing, maintaining access through command servers and extracting data.

The attackers also used AI to monitor how effectively their tools remained undetected by known security systems. When the agents monitoring the attacks identified a security solution that had detected malware, they autonomously modified and recompiled the malware to evade new detection methods.

AI was also used for phishing, a cyberattack in which criminals pose as a trusted organisation to obtain people’s personal data.

In Estonia, well-known examples include telephone scams. The Estonian Artists’ Union fell victim to one such scheme and lost 700,000 euros.

Government agencies have also been targeted with spear phishing, in which the targets are selected rather than chosen at random. A similar cyberattack against high-profile people in Estonia took place in the spring and was most likely carried out by Russia, according to the report.

The investigation identified more than 20 organisations that the group had planned to attack, had attacked or had monitored. They included ministries, defence and intelligence agencies, embassies and diplomatic missions, think tanks and defence industry companies.

The targets were mainly in Ukraine and Europe, but the attacks also reached the Middle East and government agencies involved in maritime affairs in Asia.

The attacks primarily targeted Ukraine, as well as companies producing military drone technology and related supply chains. Exceptions included a Southeast Asian government agency responsible for maritime shipping and surveillance, and a North African national technology agency.

Houthis used AI to develop weapon systems

The report also said that Houthi rebels in northern Yemen used AI to vibe-code different solutions for weapon systems.

Source 
(via ERR)