================================================================================
PYTHON SIMPLE SEARCH - PAGE INDEX
================================================================================

Research question:
Russian AI capabilities

Created:
2026-09-02T10:24:48.675862

================================================================================
SEARCH QUERIES
================================================================================

1. Russian AI capabilities
2. Russian hackers AI capabilities
3. Russian hackers use of AI agents on the Internet

================================================================================
WEB PAGES
================================================================================

################################################################################
SOURCE 1
################################################################################

TITLE: How Russia Is Building a Sovereign Drone Ecosystem for AI-Driven Autonomy
URL: https://www.csis.org/analysis/how-russia-building-sovereign-drone-ecosystem-ai-driven-autonomy
DOMAIN: csis.org
AUTHOR: Kateryna Bondar
DATE: 2026-04-13
SEARCH QUERY: Russian AI capabilities
TEXT LENGTH: 50018

SEARCH SNIPPET:
Apr 13, 2026 · Russia is not competing with major powers in the race for frontier AI; instead, it is pursuing a pragmatic strategy focused on applied AI capabilities. Rather than developing large foundational models from scratch, Russia focuses on building practical solutions on top of existing open-weight models from Western developers such as Llama and ...

--------------------------------------------------------------------------------
PAGE TEXT:

How Russia Is Building a Sovereign Drone Ecosystem for AI-Driven Autonomy
Executive Summary
This paper examines how Russia is developing military artificial intelligence (AI) and incrementally moving toward autonomous decisionmaking, particularly at the tactical edge. The takeaways below outline the core findings on how these capabilities are built, adapted, and scaled within Russia’s wartime military ecosystem.
- Russia has identified unmanned systems and AI as two overarching strategic priorities across all levels of policymaking. These priorities appear consistently in federal, regional, and sector-specific strategies and are most often framed in civilian and dual-use contexts. However, given Russia’s transition to a wartime economy and the limited visibility into classified military programs, investments and progress in these areas are highly likely to translate directly into military capabilities and operational gains.
- Russia has likely fielded a fully autonomous unmanned system in combat and continues to iterate on its deployment despite resulting civilian casualties. Ukrainian technical analysis of intercepted V2U drones indicates the absence of communication components required for operator control, alongside the presence of onboard computing sufficient to run AI-enabled perception and decisionmaking software. Observed battlefield behavior—including autonomous flight in denied environments, independent target selection, and coordinated group activity using visual markings for swarm-like coordination—suggests that V2U represents a qualitative departure from remotely piloted expendable drones toward fully autonomous, AI-driven systems.
- Russia’s drone ecosystem reveals an adaptive procurement logic in which innovation originates outside formal defense industrial structures and is scaled only after battlefield validation. Projects such as Molniya demonstrate a recurring pattern: rapid experimentation by civilian engineers and volunteer groups at the “garage” level, followed by selective state intervention to finance, standardize, and mass-produce systems that prove operationally effective. This approach allows the state to capture the benefits of decentralized innovation while avoiding the inefficiencies of attempting to centrally design solutions under wartime pressure.
- One of the most critical enablers of unmanned systems integration has been the rise of private drone schools and parallel training initiatives, which operate as rapid accelerators of technological adoption. Unlike traditional state-run training facilities, these organizations adapt with startup-like speed, continuously updating curricula, integrating new platforms directly into instruction, and allowing operators to test systems extensively during training. This structure creates direct feedback loops between end users and engineers, accelerating refinement of both hardware and tactics. By embedding new capabilities into training pipelines faster than formal institutions, these schools convert emerging technologies into operational competence at scale, effectively making training itself a central engine of combat power.
- More than 50 percent of all AI-enabling components recovered from Russian unmanned systems originate from companies headquartered in the United States and consist primarily of commercial-grade, dual-use electronics. Across 705 identified AI-relevant components (e.g., spanning processors, memory units, and sensors) U.S. firms account for roughly 69 percent of memory hardware, 57 percent of processors, and 38 percent of sensors, representing the largest national share in each category. By comparison, China supplies less than 9 percent of total AI-enabling components and does not rank among the top providers of onboard computing hardware. These findings underscore that the technical backbone of Russia’s expanding battlefield autonomy remains deeply embedded in globally integrated semiconductor markets, where commercially available Western technologies continue to play a decisive role despite sanctions and export controls.
- Russia is not competing with major powers in the race for frontier AI; instead, it is pursuing a pragmatic strategy focused on applied AI capabilities. Rather than developing large foundational models from scratch, Russia focuses on building practical solutions on top of existing open-weight models from Western developers such as Llama and Mistral, as well as Chinese models such as Qwen and DeepSeek. These models are adapted into custom applications designed for both government-wide integration and military use.
- Russia is deliberately building a comprehensive, end-to-end ecosystem for AI and unmanned systems rather than pursuing isolated capabilities. This effort integrates compute expansion to one exaflop by 2030, production targets of 130,000 large-scale unmanned aircraft systems (UASs) annually, rapid growth in AI markets and corporate investment, and a planned output of 15,500 AI specialists graduating each year by 2030. Anchored in national strategies and operationalized through state programs, the ecosystem links infrastructure, regulation, industry, and talent development into a unified system designed to sustain AI-enabled autonomy and military relevance over the long term.
- Russia is focusing on creating a dedicated infrastructure to enable civilian-operated unmanned aviation at national scale by 2030. This includes the expansion of test ranges, construction of new production facilities, and deployment of unified airspace integration and digital traffic management systems designed to support the safe, large-scale operation of UASs. Creation of such infrastructure will not only support civilian adoption but also serve as a critical enabler for the accelerated development, scaling, and operational integration of unmanned systems within the military domain.
- Russia expects demand for 1 million UAS specialists by 2030, making human capital a central pillar of its unmanned systems strategy. To meet this scale, the state is expanding drone-focused education across schools, vocational pathways, and universities, while introducing unified competency standards and continuous training programs to keep skills aligned with industry and operational requirements.
- Russia is combining a deliberately soft approach to AI regulation with growing centralization of state control over its deployment through the creation of a National AI Headquarters and a presidential-level commission. Rather than rushing formal legislation, the government has emphasized phased regulation, experimentation, and institutional learning, while relying on selective restrictions, certification of “trusted” technologies, and controlled access to state-managed data. At the same time, Moscow is moving to concentrate authority through the creation of a National AI Headquarters above individual ministries—designed to coordinate AI implementation across regions and sectors under a single, state-led command structure—alongside a Commission on the Development of Artificial Intelligence Technologies under the president.
- Russia’s most successful integration of AI occurs within companies that operate across both civilian and military markets rather than within purely defense-oriented enterprises. Dual-use firms can draw on far larger and more varied datasets, iterate software in real operational environments, and continuously retrain models based on civilian and security applications. This access to data, testing opportunities, and feedback loops allows AI capabilities to mature faster and transition more smoothly into battlefield use than systems developed exclusively inside closed military programs.
- Russian unmanned systems development is characterized by modularity and rapid functional adaptation rather than platform specialization. Once a design proves viable, it is quickly repurposed across multiple roles—for example, as a loitering munition, reconnaissance platform, or logistics carrier—through minimal airframe changes and software updates. Simple construction and modular architecture allow fast iteration based on frontline feedback, accelerating the diffusion of successful designs across different mission sets.
For the United States, the central lesson is that success in AI-enabled unmanned systems requires an ecosystem approach. To advance its ambitions in autonomous technology, the United States must implement a national systems project approach that incorporates and aligns training, testing, dual-use innovation, government implementation, and civil-military cooperation.

Introduction
Four years into Russia’s full-scale invasion of Ukraine, the war has revealed something that, until recently, remained largely theoretical—the emergence of fully autonomous weapons systems deployed in the battlefield. While early assessments of Russia’s military performance showed institutional rigidity and technological underperformance, battlefield evidence now suggests a more complex picture. Under sustained pressure from electronic warfare (EW), GPS denial, and mass attrition, Russia is moving beyond remote-controlled unmanned systems and is fielding platforms capable of operating, navigating, and selecting targets without external communication, marking a qualitative shift in how autonomy is applied in combat.
This development does not reflect a breakthrough in frontier AI, nor the realization of long-promised kill-chain-wide autonomy architectures. Instead, Russia’s progress has been driven by a pragmatic focus on applied AI, embedding narrowly defined machine learning functions directly into unmanned systems and battlefield software. Rather than competing with the United States or China in foundational AI research, Russian developers adapt existing Western and Chinese open-weight models and integrate them into domestic applications optimized for wartime conditions. The result is not comprehensive autonomy but functional independence at the tactical edge.
This report examines how Russia is integrating AI into its unmanned systems and what this process reveals about the evolving character of Russian military power. The central question is not whether Russia has achieved autonomy in a doctrinal sense, but how effectively it deploys limited AI capabilities that deliver operational advantage at scale.
The analysis is structured in three parts. The first section examines Russia’s policy architecture for AI and unmanned systems, showing how presidential-level priorities translate into national programs, regulatory approaches, and sectoral initiatives. It highlights how a civilian innovation ecosystem—spanning regulation, industry, and workforce development—supports the expansion of military capabilities.
The second section presents a set of case studies that illustrate different models of AI development and deployment, ranging from centralized, state-led programs to commercially driven systems that scale through battlefield validation.
The third section analyzes three key factors enabling Russia to maintain speed and scale in innovation: (1) training as the primary channel for integration and force-wide adoption, (2) the origin of the hardware backbone underpinning AI-enabled systems, and (3) the role of international partnerships in sustaining access to critical technologies.
Research Approach and Sources
This analysis is based exclusively on open-source research and does not rely on classified information. The research draws on four primary-source categories, which were systematically cross-referenced to assess both Russian intent and observed battlefield performance:
- Official Policy Documents: The first set of sources consists of official Russian strategic documents, action plans, and legislative frameworks. These materials make it possible to identify the formalized priorities, policy directions, and institutional mechanisms through which the Russian state articulates and operationalizes its technological objectives.
- Media Reports and Statements: The second set of sources includes official media reporting and public statements by senior Russian leadership, including President Vladimir Putin, ministers, and other senior officials. These communications demonstrate how the Kremlin frames technological priorities, signals shifts in strategic direction, and publicly communicates progress in AI and unmanned systems development.
- Telegram Channels: The third set of sources comprises systematic monitoring and analysis of more than 150 Russian Telegram channels, including closed and semi-closed groups associated with civilian engineers, volunteer technologists, and military-affiliated developers supporting the war effort. These communities provide granular, near-real-time visibility into how specific systems evolve, what technical challenges developers encounter, how they adapt to constraints such as EW and component shortages, and how effective solutions diffuse across units. This source base enables tracking not only innovation itself, but also the processes of scaling, adaptation, and institutionalization within the Russian military ecosystem.
- Interviews: The fourth source set of sources consists of interviews with Ukrainian military personnel. These interviews were used to cross-check open-source findings against observed frontline realities and to provide ground-truth assessments of how Russian unmanned systems perform in combat and how Russian tactics and technologies have evolved over time.
Please note, that some of the links referenced in this report may only be accessible through appropriate VPN services or from specific geographic locations.
To further validate the analysis, interviews also included foreign military experts specializing in the Russian Armed Forces, who helped verify technical interpretations and contextualize findings derived from Russian sources and battlefield reporting. By triangulating these sources, this analysis aims to provide a grounded, empirically anchored assessment of how AI and autonomy are being integrated into Russia’s military systems under wartime conditions.

Russia’s Policy Architecture for AI and Autonomous Systems
This section examines the architecture of Russia’s strategic planning and the mechanisms through which innovation policy in AI and unmanned systems is formulated and implemented. For analytical clarity, Russia’s policy planning and implementation are examined across three interrelated layers—strategic, tactical, and operational—as shown in Table 1. The analysis proceeds across each of these layers to identify how specific initiatives and institutional mechanisms support the advancement of Russia’s wartime capabilities.
The assessment draws on official strategic documents and implementation frameworks to illuminate how declared priorities are translated into actionable programs and measurable outcomes.
In addition, this section provides an overview of AI-related regulation to clarify the Russian government’s evolving approach to governance, experimentation, and control in the AI domain. The objective is to move beyond political rhetoric and evaluate the underlying system of planning, coordination, and state oversight that shapes Russia’s approach to innovation under wartime conditions.
Strategic Layer
At the strategic level, Russian leadership defines National Development Goals—broad, long-term priorities that shape the country’s overall trajectory. These goals are established through the highest-level policy instrument, a presidential decree, which sets the overarching direction for state policy across sectors. The decree articulates national development objectives and provides strategic guidance for implementation across all domains, including those that influence innovation and technological advancement relevant to the war effort.
The latest decree On the National Development Goals of the Russian Federation for the Period up to 2030 and for the Perspective until 2036 was adopted on May 7, 2024. In this decree, the national goal called “Technological leadership” is defined through a set of measurable objectives and tasks that collectively reflect Russia’s strategic priorities in science and innovation. Notably, the document directly identifies three technological streams—unmanned systems, autonomous vehicles, and AI—as particularly critical areas for achieving global competitiveness.
The decree sets ambitious quantitative benchmarks. By 2030, Russia aims to rank among the world’s top 10 nations in research and development (R&D), to raise domestic R&D spending to at least 2 percent of GDP, and to double private-sector investment in innovation. Additionally, it emphasizes the growth of “small technology companies” (i.e., startups) as engines of innovation and promotes localization of high-tech production as a key pillar of national resilience across all development goals.
Tactical Layer
The second layer is formed by the strategies that translate the National Development Goals into actionable priorities. At this level, two major documents stand out—the national strategies on AI and on unmanned systems. Both have a clear dual-use character, and both were recently updated, signaling that the Russian leadership is actively adjusting its innovation policy in response to rapid changes in these strategically important domains.
The National Strategy for the Development of Artificial Intelligence for the period up to 2030, approved in October 2019 and updated in February 2024, remains the cornerstone of Russia’s long-term vision for AI. It defines AI as a key driver of economic growth, quality of life, and national security. The document mandates the integration of AI across all levels of governance and production, from federal ministries and state-owned enterprises to private industry, aiming to embed AI into the very architecture of the Russian state and economy.
In contrast to the United States and China, which are explicitly named in the strategy as the leading global players, Russia does not position itself as a competitor in frontier AI research. Acknowledging its limited access to advanced computing resources and international scientific cooperation, the strategy instead focuses on the applied, dual-use dimensions of AI. In practice, Russia seeks to leverage algorithms and models already developed abroad, integrating them into domestic applications across defense, security, and industrial automation.
The strategy is structured around a set of pillars that directly support the application layer of AI—the point where technologies transition from research to operational use. The overview of the following core pillars shows that, collectively, their interconnection enables large-scale deployment across the economy and state systems:
- The infrastructure development pillar underpins the entire system. Russia plans to expand its domestic computing capacity from 0.073 exaflop to 1 exaflop by 2030, ensuring technological sovereignty and continuity of AI model training under sanctions. This compute foundation will support both civilian and defense applications.
- Support for AI developers is designed to stimulate local innovation and commercialization. The state targets an AI services market of 60 billion rubles (~$760 million) annually by 2030—up from 12 billion rubles (~$150 million) in 2022—creating sustained demand for homegrown solutions integrated into industry and government systems.
- Research and scientific advancement connects infrastructure and industry through state-funded university centers. By 2030, Russian researchers are expected to produce 450 top-level conference papers and 450 journal publications per year, maintaining visibility and continuity of applied research despite international isolation.
- Human capital development ensures the diffusion of skills across the labor market; 15,500 AI specialists are expected to graduate annually by 2030 (up from 3,048 in 2022), and 80 percent of the workforce is to attain basic AI literacy, reflecting the state’s intent to institutionalize AI competence across society.
- Sectoral integration operationalizes these layers. By 2030, 95 percent of priority industries are to achieve high readiness for AI adoption, with corporate investment rising from 123 billion to 850 billion rubles annually (from ~$1.5 billion to ~$11 billion).
This ecosystem builds the foundation for integration of AI across the Russian economy, linking compute power, education, applied research, and industrial deployment into a single complex. It represents a tightly interwoven system designed to scale AI implementation. Inevitably, the results of this approach are most visible in the military domain, where the practical orientation of Russia’s strategy has already translated into tangible progress on the battlefield, rather than remaining confined to policy documents or strategic declarations.
Military AI has clearly emerged as a strategic priority for Russia, as reflected in President Putin’s remarks at the April 2025 meeting of the Military-Industrial Commission. Framing AI as the defining factor in the future of Russian defense and weapons development, the Russian president stressed the priority of integration of domestically produced “protected” AI into automated command systems. This creates technological impetus to pursue broader reforms in production, doctrine, and training, illustrating how all national AI priorities converge in the defense domain.
Another crucial initiative for Russia’s military effort is the new Strategy for the Development of Unmanned Aviation, which lays out an ambitious vision for building a sovereign, large-scale, and fully integrated UAS ecosystem by the early 2030s. Although this is still a draft updating the previous strategy, it already makes clear how Russian leadership intends to shape the sector. The document presents unmanned aviation as both a national security priority and a catalyst for economic modernization, outlining coordinated measures to move the field from a fragmented, import-dependent niche to a high-capacity domestic industry.
At the center of the strategy is a clear priority—Russia intends to replace foreign UASs, components, and software with its own systems. This drive for technological sovereignty runs through the entire document. The government plans to localize airframes, engines, electronics, flight controllers, payloads, navigation modules, and protected communications systems, while simultaneously creating a national certification regime tailored specifically to unmanned aircraft and AI-enabled autonomous systems. Certification is meant to ensure that domestically produced UASs meet standardized military and civilian requirements.
These structural reforms are paired with a strong push to expand domestic production capacity. By 2030, Russia plans to manufacture around 130,000 UASs, increasing to 350,000 by 2035. The market value of unmanned aviation is expected to surpass 145 billion rubles (~$1.9 billion) by 2030 and more than 350 billion rubles (~$4.6 billion) by 2035. The strategy envisions roughly 200 additional organizations entering UAS component production, building on the 220 already active in the sector, and aims for Russian companies to meet at least 75 percent of national UAS demand by the end of the decade.
To support these ambitions, the state aims to build the infrastructure needed for a national unmanned aviation ecosystem. This includes expanded test ranges, new production sites, unified airspace-integration tools, and digital traffic management systems that will allow UASs to operate safely at scale. It also includes investments in protected radio communications, interference-resistant navigation, and alternative Global Navigation Satellite System (GLONASS) solutions capable of functioning under electronic warfare conditions.
The strategy devotes considerable attention to human capital. Russia expects demand for UAS specialists to reach nearly 1 million people by 2030, with the majority trained as operators, technicians, and applied specialists and a minority as engineers and programmers. To meet this need, the government is expanding UAS-focused programs in schools, building vocational pathways, and integrating drone-related training into universities and technical institutes. Initiatives such as creating unified competency standards and continuous training programs aim to keep this workforce aligned with industry requirements.
Research and development priorities reflect both wartime urgency and long-term ambitions. The document prioritizes core R&D efforts on swarm control, autonomous navigation, multispectral computer vision, advanced propulsion, and resilient communications. The government plans to coordinate these efforts through joint programs linking industry, specialized research centers, and federal ministries.
Another important document is the State Armament Program. It is Russia’s 10-year strategic plan that outlines how the country’s armed forces will be technically modernized and re-equipped. It defines a list of new weapons systems to be developed, as well as existing ones that require modernization, based on current and anticipated national security threats.
The document is classified, making it difficult to determine the specific goals and technological priorities it outlines. However, based on statements made in June 2025, President Putin ordered that the new State Armament Program be explicitly oriented toward the large-scale integration of advanced technologies, particularly AI. He emphasized that future weapons systems and military equipment should incorporate cutting-edge digital technologies, AI applications, and weapons based on new physical principles, as well as ground and naval robotic complexes.
These strategic documents illustrate Russia’s attempt to build a structured, sovereign ecosystem for UASs with an accelerated shift toward autonomy. The vision extends far beyond producing drones. Moscow aims to establish the industrial base, software infrastructure, regulatory frameworks, technology stacks, and human capital pipelines needed to sustain large-scale UAS and AI development, deployment, and innovation well into the 2030s.
Operational Layer
National projects function as one of the central operational tools for translating presidential development goals and sectoral strategies into concrete, measurable action plans. They break down broad strategic priorities into specific initiatives with defined budgets, timelines, performance indicators, and personal responsibility assignments. Each national project is overseen by a designated official who is directly accountable to the president, creating a clear chain of responsibility and a mechanism for top-down oversight.
Although several national projects have been reclassified or renamed as federal programs, the shift is mostly cosmetic, and the core governance architecture remains unchanged, as shown in Table 2. Despite the change in terminology, the underlying logic, structure, and purpose remain essentially the same, with both national projects and federal programs operationalizing strategic goals through targeted state investment, coordinated implementation, and strict monitoring of results.
Two specific national projects/federal programs intersect most directly with Russia’s efforts to advance AI-enabled and unmanned systems, which constitute the central focus of this study:
- The Unmanned Aerial Systems National Project was launched to secure Russia’s technological independence and establish a competitive domestic drone industry across civilian and dual-use sectors. It is a cornerstone of the country’s effort to achieve the “technological leadership” goal under the 2024 presidential decree and reflects Moscow’s recognition of unmanned systems as a critical domain for industrial, military, and economic competitiveness.
The project’s overarching goal is to build a full-cycle ecosystem for the design, production, and application of UASs by 2030, with Russian-made drones expected to capture 70 percent of the national market. It consists of several interlinked components: workforce development programs to train engineers, operators, and software specialists; the creation of a standardized system for design, testing, and serial production through a nationwide network of 48 research and production centers; mechanisms to stimulate demand such as subsidies, state order, and leasing incentives; and the advancement of next-generation technologies in autonomy, navigation, communications, and materials.
This project reveals crucial details about Russia’s broader AI and autonomy strategy. It institutionalizes the state’s approach to scaling dual-use technologies by linking education, industry, and government procurement. At the same time, it reduces dependence on foreign components and promotes local innovation.
- The Data Economy and Digital Transformation of the State National Project aims to modernize Russia’s governance, economy, and social systems through large-scale digitalization and the pursuit of technological sovereignty. Within this framework, several federal programs—smaller, targeted initiatives—address specific aspects of the national project. Two of the most consequential among them are the programs Internet Access Infrastructure and Artificial Intelligence, both of which are central to building the foundation of Russia’s emerging dual-use AI ecosystem.
- The Internet Access Infrastructure program aims to ensure universal connectivity and to secure Russia’s information space by 2030. Its centerpiece is the creation of a national low Earth orbit satellite constellation of 292 satellites, designed to provide complete internet coverage across Russia’s territory and, eventually, globally. Strategically, this initiative reflects Moscow’s effort to reduce dependence on foreign technologies while establishing resilient communications for its unmanned systems (similar to how Starlink has proven critical for Ukrainian sea drones), thereby guaranteeing connectivity even when full AI-enabled autonomy is not achieved.
- The Artificial Intelligence program is designed to embed AI technologies across the economy, social services, and public administration. It focuses on developing domestic AI solutions, integrating them into state decisionmaking, and creating personalized digital services for citizens and businesses. By 2030, at least 100 government services are expected to be delivered proactively, meaning without user requests and based on predictive data analytics and user behavior modeling. The program also emphasizes the development of algorithms for autonomous decisionmaking, natural language processing, and secure data use, reinforcing AI as a strategic enabler of digital governance and industrial competitiveness. In addition, the program aims to cultivate AI competencies from an early age, including the launch of an All-Russian Olympiad on Artificial Intelligence for grades 8–11.
These two programs demonstrate how Russia is building the technological and data infrastructure necessary to sustain centralized digital control and expand AI deployment across sectors. These programs are critical because they operationalize the state’s vision of autonomy in the information domain and illustrate how AI and connectivity are being fused into the architecture of Russian governance and power projection.
AI Regulation
Russia’s first legal definition of artificial intelligence was introduced in Federal Law No. 123-FZ on April 24, 2020, which established a five-year experimental regulatory regime for AI development and deployment only in Moscow. The law defines AI as “a complex of technological solutions that enables the imitation of human cognitive functions, including self-learning and the search for solutions without a predetermined algorithm, and allows the achievement of results in specific tasks comparable, at a minimum, to those of human intellectual activity.”
Beyond setting a legal precedent, the 2020 law marked Russia’s first attempt to test AI governance in practice, combining regulatory flexibility with control over data use and privacy in a contained urban environment, turning Moscow into a national testbed for algorithmic governance and AI-driven public services.
In February 2025, Deputy Prime Minister Dmitry Grigorenko outlined Russia’s emerging federal approach to AI regulation, announcing that no legislative framework would be introduced for at least the next two years. Speaking at the presentation of the Data Economy National Project, he argued that it was “not yet the moment” for formal regulation and that the state must intervene “neither too early nor too late.” His remarks signaled a phased and cautious strategy, prioritizing observation, experimentation, and institutional learning over premature legal codification.
However, Russia’s gradual movement toward formalizing its AI governance framework took a material step forward in the first draft of the Concept for AI Regulation until 2030, which appeared in August 2025 and included additional steps by the government aimed at defining a legal basis for AI.
Although the full text of the document has not been publicly released, its preliminary contours, developed by the Ministry of Digital Development, outline what experts have described as a “distinctly Russian approach.” The concept envisions a hybrid regulatory model that combines state oversight with elements of self-regulation, seeking to encourage innovation while maintaining firm control over strategically sensitive and security-critical sectors. In practice, this means that most regulatory measures are expected to have a stimulating or enabling character, complemented by targeted restrictions and limited self-regulatory mechanisms. For instance, within the framework of experimental legal regimes for digital innovation, the draft specifies cases requiring mandatory insurance for damages caused by the use of AI technologies.
Russia’s regulatory philosophy situates itself between two global poles: the United States, which relies on a technocratic, market-driven model assigning responsibility to developers and users, and China, characterized by centralized state control and mandatory algorithmic approval. Russia claims that it seeks strategic flexibility, combining selective restrictions, certification of “trusted technologies,” and controlled access to state-managed anonymized data with incentives for industrial growth. While the concept underscores technological sovereignty and industrial scalability, it appears to lack explicit provisions for privacy or human rights protection, reflecting a regulatory orientation toward state security, institutional control, and pragmatic economic modernization rather than liberal models of data protection or open innovation.
The draft concept also formally asserts that Russia’s future AI regulation should rest on a “human-centered approach” guided by principles of technological sovereignty, trust in technology, respect for human autonomy and free will, the prohibition of harm to humans, and the rejection of excessive anthropomorphization of AI systems.
The document also reveals significant structural and methodological weaknesses. Despite its formal status as a strategic planning document, it lacks coherence with earlier frameworks such as the National AI Strategy, resulting in fragmented governance and regulatory uncertainty. Analysts note the absence of implementation mechanisms, or evaluation criteria, while the document overrelies on soft law and self-regulation without defining their legal boundaries. The strong influence of the AI Alliance, an association representing tech businesses which co-authored the document, shifts its focus toward corporate interests—particularly data access and reduced liability—rather than public accountability or citizen protection. The draft also does not offer mechanisms for resolving conflicts between ethical, safety, and sovereignty principles. Overall, it reads more as a political declaration than a coherent legal blueprint for Russia’s AI governance.
However, Russia’s approach toward AI development and implementation was recently clarified by Vladimir Putin himself. In November 2025 statements, he outlined a clear push toward the centralization and state orchestration of Russia’s AI development, particularly in the generative AI domain. He called for the creation of a dedicated National Headquarters to coordinate AI deployment across all regions and key sectors, arguing that existing working groups lack the “administrative resource” needed to drive system-wide implementation. This new centralized structure would operate above individual ministries or industries, unifying the country’s AI efforts under a single command architecture.
Putin emphasized that the state must direct the overall trajectory of AI development while remaining in close dialogue with technological businesses. He encouraged bold, unconventional regulatory proposals and the broad use of experimental legal regimes—already active in Moscow, Sakhalin Island, and soon across the Russian Far East—to accelerate testing and deployment. At the same time, he insisted that critical domains such as public administration, security services, and defense must rely exclusively on sovereign, domestically developed AI technologies.
The president also called for large-scale investments in national data center infrastructure to support AI development, with open access for startups, research institutions, and technology companies. He linked regional AI adoption rates directly to Russia’s annual digital transformation rankings, signaling a move toward performance-driven oversight. Overall, Putin framed AI not only as a technological priority but as a strategic economic engine, projecting that AI will contribute more than 11 trillion rubles to Russia’s GDP by 2030.
This vision resulted in Presidential Decree No. 116 on February 26, 2026, in which Russia established the Commission under the President on the Development of Artificial Intelligence Technologies, elevating AI governance to the highest level of state coordination. The commission is tasked with ensuring technological leadership in AI, including the creation of domestic large language models, advanced AI-enabled services, dedicated computing infrastructure, the required electronic component base, and the energy supply necessary to sustain these systems. It is also mandated to define key directions for improving legal regulation in AI development and deployment, explicitly linking economic modernization with national defense and security objectives.
The composition of the commission is particularly telling: Alongside senior economic officials and representatives of major technology actors such as Yandex sit the minister of defense and the director of the FSB, composing a relatively small decisionmaking circle. This configuration signals that large-scale AI projects will be shaped and overseen jointly by security institutions and state-aligned technology champions. The structure suggests a centralized, state-driven approach in which civilian AI development, regulatory policy, compute capacity, and military applications are strategically integrated under direct presidential supervision.
In the most recent step toward AI regulation, on March 18, 2026, Russia put forward for public discussion a draft law “On the Fundamentals of State Regulation of the Application of Artificial Intelligence Technologies in the Russian Federation.” The bill introduces AI regulation that introduces new rules for developers, businesses, and users while significantly expanding the state’s role in governing the technology. If adopted, it is expected to enter into force on September 1, 2027.
The draft AI law reflects a dual-track strategy that combines formal alignment with global regulatory norms and a deeper restructuring of the AI ecosystem around state control and technological sovereignty. On the surface, it adopts familiar elements—risk-based regulation, user rights, liability frameworks, and transparency requirements—but its core logic centers on institutionalizing “sovereign” and “trusted” AI systems tied to domestic infrastructure, data localization, and state certification mechanisms.
The requirement that development, training, and deployment occur within Russia, alongside the integration of security services into certification processes and the introduction of “traditional values” as a regulatory principle, signals that AI is being treated not only as a technological domain but as a tool of political control and regime resilience.
At the same time, the explicit exemption of defense and security applications creates a bifurcated system—tight civilian oversight paired with opaque, unconstrained military development. Strategically, this hybrid model, blending elements of EU-style compliance, U.S.-style protectionism, and Chinese-style centralization—may limit openness and innovation but enable Russia to build a vertically integrated, security-driven AI stack capable of supporting both domestic control and wartime technological adaptation.
Conclusion
Russia’s strategic documents, national projects, regulatory experiments, and presidential directives reveal a coherent and increasingly centralized effort by the Russian state to build the foundations of a sovereign ecosystem for unmanned systems and AI. Russia is pursuing these goals systematically at the highest political level, combining long-term strategic planning with a pragmatic focus on applied technologies rather than competing in the global frontier AI race. Instead of attempting to leap directly into foundational research and spending enormous resources on frontier model development, Moscow concentrates on the application layer—on deploying algorithms, integrating autonomy into unmanned systems, and embedding AI into administrative and industrial workflows.
This pragmatism is reinforced by a comprehensive system of incentives and support mechanisms. Favorable regulatory regimes, experimental legal frameworks, and selectively liberalized data access rules are paired with massive investment in domestic component manufacturing and large-scale human capital programs spanning schools, universities, and vocational pathways. Across the ecosystem, emphasis is placed on technological sovereignty—replacing foreign components, building domestic software stacks, and ensuring that critical functions, especially in defense and state administration, rely solely on Russian technologies.
Yet these ambitions also reveal the deeply political character of Russia’s approach to innovation. Despite the rhetoric of flexibility and partnership with the private sector, President Putin ultimately has applied his characteristic authoritarian logic to AI governance as well. His call for a National Headquarters for generative AI marks a decisive move toward centralizing decisionmaking, consolidating administrative power, and placing the entire AI domain under direct state supervision.
Thus, Russia’s strategy remains tightly controlled from the top. The result is an ecosystem that blends pragmatic technological development with rigid political centralization, a duality that will continue to shape how Russia advances unmanned systems and AI throughout the remainder of this decade.

Russia’s Path to Autonomous Unmanned Systems
This section analyzes how Russia is integrating AI into unmanned systems at the tactical edge and how this process is reshaping its military-industrial ecosystem under wartime pressure. The analysis focuses on how machine learning and onboard decisionmaking are embedded into real platforms, with the goal of operating in GPS-denied, electronically contested environments and at scales that matter operationally. It also examines the practical integration of AI, exploring how Russian manufacturers approach technology development and scaling.
This analysis proceeds through a set of representative case studies that illustrate contrasting models of AI development and deployment, from state-centric, top-down programs to commercially driven, bottom-up systems. These cases provide a comparative assessment of how collaboration with the government, industrial practices by manufacturers, and feedback loops with frontline users shape technological and operational outcomes.
This section explores whether battlefield effectiveness depends less on advanced, formally declared autonomy and more on practical factors such as lowering cost, easing production, and enhancing the ability to deploy simple AI functions directly to the front line.
Case Study 1: Kronshtadt Group—Centralized AI Architectures Without Battlefield Scale
The analysis of Kronshtadt Group serves as a cautionary case study within Russia’s unmanned systems ecosystem. While the company has positioned itself as a flagship developer of long-range UASs and AI-enabled autonomy, its trajectory illustrates the structural risks of ambitious technological signaling unsupported by sustained industrial execution and battlefield validation. In the context of Russian drone development and AI integration, Kronshtadt demonstrates how expansive claims regarding autonomy, swarming, and decision support architectures do not automatically translate into deployable capability. Examining this gap between conceptual presentation and operational reality provides an important lesson for assessing Russia’s broader progress in AI-enabled unmanned warfare.
Kronshtadt Group is a privately held company which develops and produces UASs. The company has operated as an independent entity since 2022, with limited transparency regarding its shareholders, governance structure, or financial performance. Despite this opacity, Kronshtadt has positioned itself as one of Russia’s flagship developers of large, long-range unmanned systems.
The company’s current public-facing portfolio of unmanned systems appears quite small. At present, the company’s website primarily presents two operational systems: Orion and Sirius. Both are large, Group 4 and 5 UASs designed for long-range intelligence, surveillance, and reconnaissance (ISR) missions, with an advertised capability to conduct strike operations.1
Open sources provide limited insight into the specific software architectures embedded in Kronshtadt’s unmanned systems, yet the company’s public statements and exhibition materials allow a reconstruction of its approach to integrating AI. Rather than presenting AI as a discrete capability, Kronshtadt frames it as a process of gradual progress towards autonomy, most clearly articulated in relation to the Orion UAS, shown in Figure 1. This system does not represent edge-based autonomy in the strict sense, but rather showcases an advanced decision support architecture that assists the operator by fusing multi-sensor data and automating elements of its analysis.
In 2021, prior to the full-scale invasion of Ukraine, Kronshtadt CEO Sergey Bogatikov described Orion as undergoing phased development of autonomous features. A key milestone was the introduction of a new automated operator workstation showcased at the 2021 Dubai Airshow. This workstation was presented as a functional shift in human-machine interaction, designed to offload a growing share of control and decision support functions from the operator to computational systems. The manufacturer claimed that within this architecture, AI supports mission management, sensor data processing, and operator assistance rather than replacing human oversight altogether.
One concrete implementation of this approach is the integration of augmented reality into the operator interface. Kronshtadt reports the use of AI-assisted visualization that constructs a three-dimensional representation of terrain and operational objects, including elements that are known to exist but are not clearly visible in raw sensor feeds. This fusion of AI and augmented reality aims to enhance situational awareness and reduce cognitive burden during ISR and strike missions. The company claimed that this system is already implemented in operational versions of Orion as of 2021.
While the company publicly articulated a vision of enhanced operator assistance and AI-enabled mission support, the sophistication of the unmanned platform itself appears limited. The operational record of the Orion system underscores this gap. Orion drones have been repeatedly intercepted and shot down by Ukrainian forces, indicating limited survivability, absence of meaningful self-protection measures, and no observable capability for adaptive maneuvering to evade air defenses. Post-recovery technical examinations conducted by Ukrainian specialists revealed extensive reliance on commercially available U.S. components and a lack of advanced onboard computing architectures typically required for edge AI processing. Although intercepted variants exhibited some variation in internal components over time, the overall technological baseline remained consistent. Taken together, these findings suggest that Orion does not meet the threshold of an autonomous or even genuinely semi-autonomous system in operational terms, but rather functions as a conventionally piloted platform with limited automated assistance.
Despite the absence of publicly confirmed information on the current deployment status of AI software embedded in operators’ workstations or Kronshtadt’s operational unmanned platforms, the company’s actual level of competence in computer vision and object recognition can be inferred from a different product—the Mushtrа-E system. It is a machine learning complex for military UASs, designed to support continuous training and retraining of neural networks used in AI-enabled UASs during intelligence, surveillance, target acquisition, and reconn

[TEXT TRUNCATED]

================================================================================

################################################################################
SOURCE 2
################################################################################

TITLE: If You Can't Beat Them, Steal: Russia's AI Strategy
URL: https://kcsi.uk/kcsi-insights/if-you-cant-beat-them-steal-russias-ai-strategy
DOMAIN: kcsi.uk
AUTHOR: Dr Elena Grossfeld KCSI
DATE: 2025-11-03
SEARCH QUERY: Russian AI capabilities
TEXT LENGTH: 12324

SEARCH SNIPPET:
Nov 3, 2025 · Despite 'import-replacement' strategies promoted since Crimea's annexation and intensified after the 2022 invasion, Russian AI development faces formidable obstacles: Western sanctions, massive brain drain, chronic underinvestment, and pervasive corruption.

--------------------------------------------------------------------------------
PAGE TEXT:

During the Cold War, Western export controls attempted to limit Soviet access to advanced technologies. Soviet intelligence responded by investing heavily in technology theft: the KGB (the Soviet security and intelligence service) and GRU (Soviet military intelligence) recruited sources to enable these thefts, established front companies, and ran extensive operations to acquire Western advances in technology deemed essential for Soviet defense industries. This approach saved Moscow significant time and resources while propping up Soviet military capabilities.
When the Soviet Union collapsed, this changed. The West eagerly partnered with the new Russian Federation, selling advanced technologies that enabled resource extraction and enriched a new oligarch class. This honeymoon ended abruptly in 2014 when Putin annexed Crimea, triggering Western sanctions that intensified dramatically after Russia's 2022 invasion of Ukraine. Once again cut off from Western technology, Russian defense and economy sectors are now struggling to access everything from nails to advanced electronics and manufacturing equipment. As a result, Moscow has reverted to Cold War tactics, working to circumvent sanctions across the board.
Nowhere is this technology gap more dramatic than in artificial intelligence (AI). The United States leads global AI development, with billions in investment driving capabilities viewed as potentially transformative for societies and labour markets. China follows in close second, maintaining competitive AI capabilities despite US export controls on advanced chips and technologies. Due to US sanctions Russia, by contrast, is encountering critical AI deficits. While European nations can access advanced chips from the US and Taiwan, Russia must rely on domestic production that lags 13-fold behind China and 33-fold behind the US. Its AI research capacity shows similar weakness, trailing China and the US by 20-30 times, with its top university ranking only 213th globally in AI research output, whereas leading European institutions such as the École Polytechnique Fédérale de Lausanne (EPFL), Eidgenössische Technische Hochschule(ETH) Zurich, and the University of Edinburgh rank among the top 30 institutions.
Despite 'import-replacement' strategies promoted since Crimea's annexation and intensified after the 2022 invasion, Russian AI development faces formidable obstacles: Western sanctions, massive brain drain, chronic underinvestment, and pervasive corruption. As Russia still struggles to produce nails and continues to operate machinery received as reparations from Germany eight decades ago, developing cutting-edge AI domestically remains a fantasy.
Russia's homegrown technology gap - generative AI
Generative AI represents a particularly significant development for intelligence services. A long-awaited breakthrough in artificial intelligence, a field born in the 1950s but constrained by hardware limitations until recently, generative AI, unlike previous systems that focused on pattern recognition and classification, is able to create new content, such as text, images, code, and synthetic media, making it ideal for use in disinformation campaigns, social engineering, deepfake creation, and automated hacking. Advanced electronics have finally enabled Large Language Models (LLMs) - systems powering chatbots like ChatGPT that can generate text, write code, and reason through problems after training on massive datasets. However, developing and training these models requires enormous computational resources and advanced specialized hardware - particularly high-end graphics processing units (GPUs) costing millions of dollars and consuming massive amounts of electricity. This hardware dependency explains Russia's AI disadvantage: Western sanctions have cut off access to cutting-edge chips, making it impossible to train frontier models domestically. Evidence of this dependency emerged in 2024 when cybersecurity researchers discovered that APT28 (Advanced Persistent Threat 28), a Russian military intelligence unit conducting offensive cyber operations, was relying on API (Application Programming Interface, a set of rules that allows different software programs to communicate with each other, share data, and perform actions) calls to a Chinese-developed LLM (Qwen2.5-Coder-32B-Instruct) hosted on Hugging Face's cloud infrastructure for real-time malware command generation. Despite proclamations of domestically developed and hosted AI capabilities, Russian intelligence operations depend on publicly accessible foreign services, underscoring both the strategic importance of generative AI for offensive cyber operations and Russia's inability to develop equivalent domestic capabilities. Russia's pariah status further compounds the problem - AI development, like all modern science, thrives on international collaboration, but Western researchers increasingly avoid partnerships with Russian institutions. Simultaneously, the Russian state views scientific collaboration as a vector for foreign espionage, a paranoia reflected in the imprisonment of numerous Russian scientists on fabricated espionage charges. Yet once trained elsewhere, models can be accessed remotely or deployed on far less sophisticated hardware - an asymmetry Russian intelligence readily exploits.
China, despite facing US sanctions, remains able to develop competitive AI systems, training models like DeepSeek, which through algorithmic innovation achieves competitive performance on less advanced GPUs at a fraction of US training costs. equivalents. China's success reflects several advantages: massive state investment in science, technology, and research including AI development, a large and sophisticated domestic technology sector capable of algorithmic innovation, and stockpiles of advanced chips accumulated before export controls tightened. In contrast, Russia faces stricter export controls, invests far less in technology development, and suffers from deeper technological deficits. This gap has made technology theft not merely convenient but essential. And when the target is digital, theft becomes remarkably easy. Unlike smuggling semiconductors or machine tools, AI models can be downloaded, copied, and deployed without complex supply chains. Russian intelligence services weaponize generative AI tools across multiple domains.
Generative AI in hybrid warfare
The most visible application for generative AI is disinformation. Russian operations leverage publicly available LLMs to generate content at scale, creating personas, crafting narratives in multiple languages, and flooding social media platforms with manufactured commentary. The volume is so significant that it has begun poisoning AI models themselves: whether intentional or not, Russian disinformation proliferating online contaminates training datasets. When chatbots like ChatGPT and other LLMs train on web data, they inadvertently ingest and reproduce Russian propaganda, serving it to ordinary users as if it were legitimate information. This creates a self-reinforcing cycle where disinformation becomes embedded in the very tools designed to provide knowledge, reinforcing what historian Timothy Snyder calls the 'politics of eternity', a cyclical narrative that erases factual history and traps societies in mythologized past grievances, a new approach in information warfare.
Beyond disinformation, Russian intelligence weaponizes generative AI in cyber operations. Russian intelligence has integrated generative AI directly into malware for command-and-control functions. Unlike previous cases where hackers used AI to generate phishing emails or assist in coding, these advanced systems integrate AI into the operational phase itself: during active intrusions, the malware queries LLMs in real-time to request tailored instructions, receiving custom code that executes immediately and makes dynamic decisions on lateral movement and exfiltration based on the specific victim environment. This dynamic, adaptive approach complicates defence: security tools rely on detecting consistent patterns, but AI-generated malware varies its tactics with each intrusion, evading traditional detection methods.
Russian intelligence also leverages commercial generative AI systems throughout their attack lifecycle. Google reported that Russian APT actors used its Gemini model to research infrastructure and hosting providers, conduct reconnaissance on targets, identify vulnerabilities, develop payloads, and craft malicious scripts with evasion techniques. OpenAI documented Russian state-backed actors using ChatGPT to develop and refine Windows malware, debug code, and establish command-and-control infrastructure. Notably, these operators demonstrated operational security awareness: they deployed temporary email addresses to create ChatGPT accounts and limited each account to single conversations about incremental code improvements, avoiding detection patterns that might flag suspicious activity.
This ecosystem extends beyond intelligence services. Russian cybercriminals, often co-opted into working for intelligence agencies in exchange for protection from prosecution, actively participate in AI-enabled operations. Russian-language criminal forums freely share jailbroken LLMs like FraudGPT and WormGPT designed specifically for malicious code generation, phishing, and evading security controls, blurring the lines between state-sponsored operations and organized crime.
The weaponization likely extends beyond these documented cyber and disinformation operations into targeting, intelligence analysis, and operational planning. While Russian disinformation campaigns have demonstrated AI-powered multilingual content generation and translation, these same capabilities enable intelligence services to process intercepted communications (COMINT) and open-source materials (OSINT) at unprecedented scale, identify patterns across vast datasets, and rapidly synthesize intelligence assessments. Operators can query multiple AI platforms until finding ones without robust military-use restrictions, the same exploitation strategy used for disinformation and cyber operations. This pattern is evidenced by OpenAI and Google's repeated suspension of accounts linked to Russian disinformation campaigns, malware development, and intelligence analysis, cconfirming both the scale of Russian reliance on commercial AI platforms and the ongoing challenge of controlling access to these dual-use technologies.
Russian intelligence's rapid adoption of generative AI follows an established pattern: these services have long deployed earlier AI generations based on deep and machine learning. The embrace of generative AI represents a natural evolution, motivated by the same quest for productivity gains that have led Western companies to integrate these tools for employee augmentation, except Russian intelligence applies this productivity boost to their everyday work - disinformation generation and offensive cyber operations.
Lessons to learn
This pattern reinforces a fundamental lesson about technology and intelligence: technological leadership matters less than operational effectiveness. Russia's inability to develop cutting-edge AI has not prevented its intelligence services from weaponizing available tools with devastating effectiveness. The Cold War playbook - steal, adapt, deploy - proves remarkably durable in the digital age, perhaps even more effective when the target can be downloaded rather than smuggled. Western policymakers face a stark reality. Sanctions can deny Russia the ability to innovate, but cannot prevent exploitation of openly available systems. Lacking the legal constraints, public accountability, and oversight that try to keep Western intelligence services on the straight and narrow, Russian counterparts play fast and furious, deploying whatever technology they can access without ethical review or democratic constraints. As generative AI capabilities advance and new dual-use technologies emerge, Russia will continue replicating this asymmetric approach across domains, consistently lagging in innovation while leading in weaponization. Defenders must focus less on who builds the best capabilities and more on who deploys them most destructively.

================================================================================

################################################################################
SOURCE 3
################################################################################

TITLE: Russia's Drive to Weaponize a State-Directed AI Ecosystem: From Digital Modernization to Military Mobilization
URL: https://www.saratoga-foundation.org/p/russias-drive-to-weaponize-a-state
DOMAIN: saratoga-foundation.org
AUTHOR: The Saratoga Foundation
DATE: 2026-07-13
SEARCH QUERY: Russian AI capabilities
TEXT LENGTH: 22316

SEARCH SNIPPET:
13 Jul 2026 · Russian Armed Forces were integrating AI, robotics, and automated command systems into military management. Russian government increasingly ...

--------------------------------------------------------------------------------
PAGE TEXT:

In June 2026, Defense Minister Andrei Belousov stated that the Russian Armed Forces were integrating AI, robotics, and automated command systems into military management. The statement reflects a broader shift in Russia’s AI policy since the full-scale invasion of Ukraine. Whereas the original National Strategy for the Development of Artificial Intelligence framed AI primarily as an instrument of digital modernization and economic development, wartime priorities have increasingly repositioned it as a strategic enabler of military effectiveness, technological sovereignty, and state resilience. This evolution is reflected in the revised National Strategy for the Development of Artificial Intelligence until 2030, approved in February 2024, which places substantially greater emphasis on technological sovereignty, domestic software development, and reducing dependence on foreign digital infrastructure. Taken together, these developments suggest that AI has become an integral component of Russia’s wartime mobilization strategy, with civilian AI initiatives increasingly serving as a foundation for military innovation by strengthening the country’s data infrastructure, software ecosystem, and human capital.
This analysis proceeds as follows. First, it examines the institutional and legislative shifts that have altered the trajectory and centralized AI governance since February 2022. Second, it considers how civilian AI development across business, healthcare, education, and infrastructure has become increasingly tied to Russia’s broader sovereignty agenda. Third, it assesses the primary military applications of AI, specifically command-and-control, reconnaissance, drones, logistics, and battlefield management. Finally, it explores Russian writings on the role of AI in information-psychological operations, concluding with an analysis of what Russia’s post-2022 AI trajectory reveals about the relationship between technological sovereignty, military adaptation, and long-term confrontation with the West.
Institutional and Legislative Changes After February 2022
In the post-2022 period, implementation of Russia’s AI strategy has become increasingly centralized. For instance, the Government Sub-commission on the Development and Implementation of Artificial Intelligence has emerged as the principal coordinating body responsible for synchronizing AI policy across ministries, regional governments, state corporations, and research institutions. Unlike many Western AI governance frameworks, the Russian model prioritizes centralized coordination and state-led implementation.
This shift became particularly evident at the AI Journey conference in late 2025. Speaking at the event, President Vladimir Putin argued that Russia should move beyond isolated AI projects toward a comprehensive national implementation plan spanning ministries, industries, and regions. He maintained that AI should become integrated into “virtually every management and production process” by 2030 and presented it as essential for preserving Russia’s technological competitiveness under conditions of geopolitical confrontation. Putin also emphasized that dependence on foreign AI systems creates strategic vulnerabilities, reinforcing technological sovereignty as a central objective of AI policy. AI is thus increasingly framed not simply as an economic technology but as an instrument of national sovereignty and resilience.
As in other strategic sectors, AI development is expected to rely on strong state coordination and financial support. Discussing Russia’s “new digital leap“, Izvestiya argued that AI should become the technological foundation of the country’s next phase of economic development while emphasizing that success depends on coordinated government policy, investment in domestic infrastructure, and strategic state support. Similarly, experts interviewed by Rossiyskaya Gazeta argued that sustained AI development requires stronger mathematics education, expanded domestic supercomputing capacity, increased public investment in research, and support for domestic software ecosystems, drawing parallels with Soviet approaches to strategic technological development. Together, these institutional developments indicate that Moscow increasingly treats AI as a state-directed sovereignty project rather than a conventional modernization program.
Civilian AI: Trends and Changes
Although Russia’s AI strategy increasingly prioritizes national security, military modernization does not operate independently from civilian technological development. Rather, one of the defining characteristics of Russia’s post-2022 AI policy is the gradual erosion of boundaries between civilian and military innovation. Moscow increasingly treats healthcare, education, public administration, logistics, and industrial modernization as components of a broader AI ecosystem capable of supporting long-term strategic competition. Three civilian domains illustrate this trend. These areas matter not because they are military in a narrow sense, but because they build the data, personnel, software, and institutional infrastructure on which military AI adoption ultimately depends.
First, business and economic development. Following the introduction of Western sanctions, the Russian government increasingly identified AI as a mechanism for offsetting labor shortages, improving productivity, and supporting import substitution across strategic industries. The Yakov & Partners report, published in late 2025, estimated that AI could contribute between 7.9 and 12.8 trillion rubles annually to the Russian economy by 2030 while improving productivity across manufacturing, finance, transport, healthcare, and public administration—sectors facing acute labour shortages. The report also found that more than 70 percent of surveyed companies had already deployed generative AI in at least one business function, while nearly half had begun experimenting with AI agents, suggesting that AI adoption has moved beyond pilot projects into mainstream business operations. Similarly, Russian business media present an optimistic outlook. According to RBC, Russia’s AI market could reach approximately $2.1 billion in 2025 while maintaining annual growth rates approaching 45 percent. These projections should be treated cautiously, but they show the weight assigned to AI in Russian industrial policy despite sanctions and hardware constraints.
Second, healthcare has emerged as one of the fastest-growing civilian applications of AI. According to Vedomosti, Moscow’s digital healthcare platform has connected nearly 2,000 medical organizations across more than 70 regions, enabling AI systems to assist physicians in analysing medical images and improving diagnostic accuracy. Beyond healthcare itself, these applications expand Russia’s domestic AI ecosystem by generating large datasets, improving machine-learning models, and strengthening national computational infrastructure.
Third, education and human capital occupy a strategic position within Russia’s AI agenda. Rather than emphasizing digital literacy alone, Russian policy increasingly treats education as a prerequisite for technological sovereignty. The Yakov & Partners report identifies shortages of qualified specialists as a principal constraint on AI development and argues for closer cooperation between universities, state institutions, and technology companies. It recommends expanding mathematics, computer science, and engineering education while strengthening university-industry partnerships to sustain Russia’s AI ecosystem under conditions of international isolation.
Since 2022, given internal developmental trajectory, even nominally civilian AI sectors have moved closer to civil-military fusion. In Russia’s wartime setting, healthcare data, education, software ecosystems, robotics, cryptography, and drone technologies increasingly feed into the same sovereign AI infrastructure that the armed forces can draw upon.
Military AI: Areas of Application
While civilian AI provides the foundation of Russia’s sovereign AI ecosystem, the armed forces have increasingly become its principal destination. Official statements and military publications indicate that the war against Ukraine has reshaped Russian AI priorities – rather than pursuing fully autonomous weapons as an end in themselves, Moscow has concentrated on integrating AI into command-and-control systems, battlefield management, logistics, reconnaissance, and drone warfare. During a meeting of the Military-Industrial Commission in April 2025, President Vladimir Putin argued that “whoever begins using AI in military affairs faster will enjoy enormous – indeed colossal – advantages on the battlefield” and called for accelerating domestic software development for automated command systems alongside expanded production of unmanned aerial systems. This emphasis continued in June 2026, when Defence Minister Andrei Belousov stated that the Russian Armed Forces were actively integrating AI technologies, robotics, and automated command systems into military management, indicating that AI has moved beyond experimental projects to become part of Russia’s broader military modernization agenda.
The modernization of command systems has become the principal area of AI integration with lessons from the war in Ukraine underscoring the importance of rapid data processing, sensor fusion, and real-time situational awareness. Following Belousov’s inspection of tactical command modernization in July 2025, Moskovskii Komsomolets reported continuing efforts to integrate digital communications, automated battlefield management, and AI-assisted command support capable of combining information from drones, reconnaissance assets, electronic warfare units, and artillery into a common operational picture. Similarly, an article published by APNI argues that AI should strengthen tactical command by processing battlefield data, identifying operational patterns, supporting target prioritization, and improving coordination among different branches of the armed forces. One example of practical implementation of this approach is the AI platform Svod, reportedly designed to collect and synthesize operational information from multiple sources to provide commanders with integrated situational awareness rather than raw intelligence streams, illustrating Russia’s preference for decision-support systems over autonomous command architectures.
The war has also accelerated interest in AI-enabled navigation, computer vision, swarm coordination, and autonomous target recognition. According to Arsenal Otechestva defence magazine, future combat effectiveness will increasingly depend on integrating AI with robotics, precision-guided weapons, and unmanned systems capable of operating under conditions of electronic warfare, suggesting that AI will reshape not only individual weapons but also the organization of military operations.
Russian military writing after 2022 presents AI primarily as a decision-support technology rather than a substitute for commanders. Romashkina argues that AI’s main value lies in processing battlefield information, improving logistics, strengthening cyber defence, supporting reconnaissance, and assisting operational decision-making (Romashkina, N. P. “Iskusstvennyi intellekt v voennom dele: vozmozhnosti, ugrozy, perspektivy.” Voprosy kiberbezopasnosti, no. 6 (70) (2025): 158–165). A related study titled “Artificial Intelligence in Military Affairs: Essence, Problems of Development and Operation, Main Areas of Application” advocates a “human-in-command“ model in which AI helps construct digital representations of the battlefield, prioritize threats, model alternative courses of action, and prepare operational orders, while final authority remains with human commanders. Both studies argue that AI should function as a force multiplier embedded throughout command-and-control processes rather than as an autonomous decision-maker. Another analysis broadened this argument by treating AI as a strategic technology and introducing the concept of “cognitive weapons“: tools designed to degrade adversary AI systems through poisoned data, adversarial inputs, or attacks on software and hardware. This moves the discussion beyond AI-enabled weapons to AI itself as a contested battlespace. In other words, Russian military thinkers increasingly view AI systems not only as tools for enhancing combat effectiveness, but also as targets that can be deceived, degraded, or manipulated. Thus, the analysis postulates an idea that Russia must invest not only in military AI capabilities but also in protecting AI systems against manipulation, reinforcing the view that AI will increasingly shape military competition and international power relations.
The clearest articulation of this emerging Russian view appears in an article by Col. (ret.) V. Orlianskii and Col. (ret.) P. Dulniev in the Russian military journal Voyennaya Mysl (Military Thought), which links battlefield lessons from Ukraine directly to the need for AI-enabled command systems and a more flexible force structure. The authors argued that the experience of the war in Ukraine since 2022 demonstrates that Russia’s traditional, fixed organizational model is no longer adequate for high-intensity, technology-driven warfare. The principal lesson is that tactical units must become dynamically organized, capable of being reinforced in real time with drones, artillery, aviation, electronic warfare, and other assets according to rapidly changing battlefield conditions rather than relying on permanently assigned force structures. They contend that the speed of modern combat, the ubiquity of drones, and the transparency of the battlefield have shifted the decisive advantage toward forces able to process information faster, adapt organizational structures more rapidly, and coordinate multi-domain assets with minimal delay.
To achieve this transformation, the authors advocate integrating artificial intelligence into a unified automated command-and-control system spanning tactical, operational, and strategic levels. AI is presented not as a replacement for commanders but as a decision-support tool capable of processing massive volumes of reconnaissance data, identifying targets, modelling courses of action, allocating reinforcement assets, coordinating joint operations, and continuously updating decisions in near real time while leaving final authority with human commanders. They further argue that AI-enabled command systems should underpin a transition to “dynamic force organization,” improve reconnaissance, logistics, and electronic warfare, facilitate the employment of robotic and directed-energy systems, and ultimately reshape Russian military art. At the same time, the authors acknowledge that this vision faces major obstacles, including deficiencies in Russian computing power, microelectronics, software development, data quality, and AI expertise, warning that overcoming these technological shortcomings is essential if Russia is to avoid falling behind the United States and China in the next generation of warfare.[1]
Information-Psychological Confrontation and AI
Military modernization represents only one dimension of Russia’s expanding AI strategy. AI has also become an increasingly important instrument supporting Moscow’s information operations abroad. While AI has not fundamentally transformed Russian influence activities, it has increased their speed and scale, even if its practical effectiveness remains uneven. A revealing example emerged during Hungary’s parliamentary campaign. According to The Moscow Times, Russian political strategists developed a disinformation campaign – which turned out to be a failure – intended to strengthen Prime Minister Viktor Orbán by portraying him as the defender of Hungarian sovereignty while simultaneously discrediting his political opponents. Subsequent investigations by Reuters found that coordinated Telegram networks amplified these narratives while increasingly relying upon AI-generated content and localized messaging. The pattern resembles earlier Russian influence operations such as the Doppelgänger campaign targeting European audiences – rather than replacing human operators, generative AI enables faster production of fake news articles, manipulated imagery, multilingual social media posts, and synthetic videos.
In this regard, Russian military thought is paying growing attention to AI’s role in gray-zone and sub-threshold operations. An article titled “Teoriya «Myatezhevoyny» E.E. Messnera kak instrument osmysleniya prirody sovremennykh voennykh konfliktov” (”E.E. Messner’s Theory of ‘Subversive Warfare’ as an Instrument for Understanding the Nature of Modern Military Conflicts) in a recent issue of Voyennaya Mysl’ (Military Thought) argues that Evgeny Messner’s concept of “global insurgent warfare” retains significant explanatory value for understanding 21st century conflicts. The authors contend that digital technologies, social media, and artificial intelligence have transformed myatezhevoyna into a “digital-ideological” form of confrontation, in which information, narratives, and collective consciousness become primary targets of strategic competition. They conclude that contemporary national security must protect not only territory and infrastructure but also the state’s cognitive and value space, reflecting the growing importance of non-military instruments in achieving strategic objectives.[2]
Another article, “Doktrinal’nye transformatsii v sfere psikhologicheskikh operatsiy SShA i NATO s tochki zreniya vozmozhnykh posledstviy dlya bezopasnosti Rossii” (Doctrinal Transformations in the Sphere of US and NATO Psychological Operations from the Perspective of Potential Consequences for Russia’s Security) published in the same journal, argues that recent U.S. and NATO doctrinal changes in psychological operations (PSYOP) represent an expanding threat to Russian national security. The authors contend that Washington’s return to the concepts of PSYOPs, combined with increased funding and broader operational scope, signals an intensification of psychological pressure against Russian society and the Armed Forces. Particular attention is devoted to artificial intelligence, which is portrayed as a force multiplier capable of generating persuasive synthetic content in real time, enabling unprecedented penetration of Russia’s information space. The article also argues that AI-enabled micro-targeting, supported by big data analytics, substantially enhances the effectiveness of Western information campaigns by allowing tailored influence operations against vulnerable social groups. Overall, the authors present AI as a critical enabler of next-generation psychological warfare and gray zone competition rather than merely a technological innovation.[3]
Taken together, these developments suggest that AI is becoming an increasingly important enabler of Russia’s information-psychological confrontation rather than a revolutionary new instrument of influence. While generative AI has expanded the speed, scale, and adaptability of disinformation campaigns, Russian military thought increasingly views AI in broader strategic terms – as a tool for shaping Western perceptions, protecting the state’s cognitive space, and countering perceived psychological operations organized by the West. This perspective complements Russia’s wider post-2022 AI strategy, in which technological sovereignty, military modernization, and information confrontation are treated as mutually reinforcing components of a single state-directed effort to strengthen national resilience under conditions of prolonged geopolitical competition.
Outlook
Russia’s post-2022 AI trajectory suggests that Moscow is not trying to win the global AI race on the terms set by Silicon Valley or China’s largest technology firms. Instead, it is building a sovereign, state-directed AI ecosystem shaped by wartime pressure, sanctions, and long-term confrontation with the West. The significance of this shift lies less in frontier-model competition than in the way Russia is integrating AI into command systems, logistics, battlefield management, drones, education, healthcare data, and information operations. This does not mean Russia has overcome its technological constraints. Access to advanced chips, computing power, and globally competitive commercial platforms remains limited. It does mean, however, that Russia may gain practical advantages from selective, state-coordinated AI adoption. This marks an important evolution from the pre-war logic of digital modernization – AI is no longer treated primarily as a tool for improving economic efficiency or public administration; it is increasingly understood as infrastructure for wartime governance, military adaptation, and strategic autonomy. The key implication is that Russian AI strategy is assuming the form of a resilience strategy – one designed to preserve military adaptability, state capacity, and informational reach under conditions of prolonged geopolitical confrontation. Judging by repeated statements from President Putin and Russia’s military-political leadership, this confrontation is viewed not as a temporary phase but as a long-term strategic condition likely to endure for the lifetime of the current political system.
[1] Voyennaya Mysl (Military Thought), No. 2 (February 2026), pp. 10 – 27).
[2] Voyennaya Mysl (Military Thought), No. 6 (June 2026), pp. 152–158).
[3] Voyennaya Mysl (Military Thought), No. 6 (June 2026), pp. 77 – 89).
About the Author
Dr. Sergey Sukhankin is a Senior Fellow at The Saratoga Foundation specializing in Russian military and security affairs, as well as Russo-Chinese relations. He is also an Advisor at Gulf State Analytics (Washington, D.C.) and Fellow at the North American and Arctic Defense and Security Network (Canada).
Thank you for your support! Please remember that The Saratoga Foundation is a non-profit 501(c)(3) organization. Your donations are fully tax-deductible. If you seek to support The Saratoga Foundation, you can make a one-time donation by clicking on the PayPal link below! You can also subscribe to our website to support our work.

================================================================================

################################################################################
SOURCE 4
################################################################################

TITLE: How Russia Is Reshaping Command and Control for AI-Enabled Warfare
URL: https://www.csis.org/analysis/how-russia-reshaping-command-and-control-ai-enabled-warfare
DOMAIN: csis.org
AUTHOR: Kateryna Bondar
DATE: 2026-02-10
SEARCH QUERY: Russian AI capabilities
TEXT LENGTH: 50018

SEARCH SNIPPET:
Feb 10, 2026 · Focusing on both strategic ambitions and battlefield practice, the takeaways below summarize how automated C2 systems, unmanned platform management software, and emerging AI applications are being developed, adapted, and scaled within Russia’s military ecosystem.

--------------------------------------------------------------------------------
PAGE TEXT:

How Russia Is Reshaping Command and Control for AI-Enabled Warfare
Executive Summary
This paper examines how Russia is transforming its command and control (C2) architecture under wartime pressure, how these changes shape the country’s incremental move toward battlefield-required software solutions, and what lessons U.S. policymakers can learn from Russia’s experiences. Focusing on both strategic ambitions and battlefield practice, the takeaways below summarize how automated C2 systems, unmanned platform management software, and emerging AI applications are being developed, adapted, and scaled within Russia’s military ecosystem.
- Russia is no longer prioritizing the construction of a single, comprehensive automated C2 architecture comparable to Western joint concepts; instead, it is reallocating effort toward tactical, task-specific software, driven by battlefield necessity. Prolonged, high-intensity combat in Ukraine exposed the limits of centralized, system-wide C2 modernization and elevated the importance of accelerating the tactical kill chain. The emergence of systems such as the “Svod” Tactical Situational Awareness Complex and other integrated reconnaissance-strike tools reflects a pragmatic shift in which operational control of unmanned systems and real-time battlefield management now deliver greater military value than achieving end-to-end C2 integration.
- Because unmanned systems now conduct up to 80 percent of Russian fire missions, the center of gravity in C2 innovation has shifted toward software that manages drones and integrates them with artillery and other fire units. Civilian engineers and volunteer developers have focused on closing this gap by building tools that provide situational awareness, automate fire correction, and link unmanned aircraft systems (UAS) operators directly to firing units. Russia’s “Glaz/Groza” software complex demonstrates this trend, functioning as a unified reconnaissance-strike workflow that converts drone footage into targeting data and compresses the time from detection to impact from hours to minutes.
- The Russian military assesses its AI capabilities for visual and audio data processing as relatively mature, placing computer vision, sensor fusion, and signal analysis at technology readiness level (TRL) 6–9, while natural-language processing remains at an early, experimental stage, TRL 1–3. This disparity reflects a deliberate prioritization of AI applications that deliver immediate battlefield utility—such as target recognition, guidance, and autonomous terminal functions for unmanned systems—and where abundant data and combat validation are available. By contrast, text analysis AI, which underpins document processing and higher-level C2 decision support, remains constrained by immature architectures, limited certified software, and organizational barriers, slowing progress toward fully AI-enabled command workflows.
- Within Russian C2 systems, AI is primarily envisioned as a support function rather than a replacement for human decisionmaking. Russian military doctrine assigns AI two core roles: enhancing the processing and interpretation of sensor data and providing predictive decision support through forecasting, scenario generation, and recommendations for commanders. Across strategic and tactical levels, AI is intended to augment situational awareness and analytical capacity, while formal authority and responsibility for decisions remain firmly with human commanders.
- Russia began its C2 digitalization effort by building a dense layer of standards governing terminology, system architecture, hardware-software integration, and information management. This standardization drive, coupled with the transition to the domestically controlled Astra Linux operating system, reflects an attempt to create a unified technical foundation capable of supporting data integration, interoperability, and future AI insertion across the command hierarchy. While this framework provides structural coherence, it has not, on its own, resolved deeper institutional and methodological constraints that continue to limit system-wide C2 integration.
- To enable AI-driven tactical software, the Russian military launched a systematic data collection effort in 2025 focused on unmanned operations and strike outcomes. The emerging data infrastructure aggregates UAS video feeds, operator telemetry, strike effects, and individual pilot performance metrics, each linked to unique personal identifiers. These datasets serve multiple functions simultaneously: operational analysis, training evaluation, and the creation of labeled data for AI model development, establishing a feedback loop that ties battlefield performance directly to software refinement.
- Despite efforts to reduce dependence on foreign commercial technologies, Russia’s military AI development remains heavily reliant on open-weight models and civilian software ecosystems. The transition from tools such as AlpineQuest and Discord toward domestic alternatives like ZOV Maps and Astra-based platforms reflects a push for security and sovereignty at the application layer. At the same time, Russian developers actively adapt open-weight and commercially available AI models, including Mistral, Qwen, LLaMA, YOLO, and related architectures, for military use, embedding them into on-premise, tightly controlled environments. This hybrid approach allows Russia to mitigate sanctions and accelerate AI adoption without building foundational models from scratch.
Russia’s approach to AI-enabled command and control reflects a decisive shift away from abstract, large-scale modernization concepts and toward solving concrete battlefield problems. Rather than pursuing a fully integrated, end-to-end C2 architecture, Russia has focused on tactical, task-specific software that directly accelerates the kill chain and improves the effectiveness of unmanned systems where operational payoff is immediate and measurable. Its investment in AI follows the same pragmatic logic—prioritizing computer vision, sensor fusion, and signal processing applications that have proven mature under combat conditions, while treating more ambitious uses of AI, such as text analysis and higher-level decision support, as secondary and experimental.
Where Russia’s own AI capabilities remain underdeveloped, particularly in natural-language processing, it compensates not by attempting to build frontier models, but by adapting open-weight architectures developed elsewhere. By leveraging U.S., Chinese, and European advances and embedding them into controlled, military-specific environments, Russia accelerates adoption while avoiding the cost and risk of foundational model development. These choices show a broader pattern: Russia is not chasing technological elegance or conceptual completeness but rather applying AI selectively and ruthlessly in service of battlefield effectiveness.

Introduction
This white paper is the first in a series examining how Russia is moving toward AI-enabled autonomy in military operations. The paper establishes the C2 layer as the foundational substrate of this transformation, arguing that autonomy in unmanned systems, decision support, and battlefield management cannot be understood without first analyzing how Russia conceptualizes, builds, and adapts its automated command infrastructure under wartime conditions.
This paper focuses on Russia’s long-running effort to create an automated C2 system for forces and weapons (ACCS)—a concept that, in Russian military thinking, represents a fully digital, end-to-end environment linking sensors, commanders, and weapons into a single decision-execution loop. While this vision closely parallels Western concepts such as Joint All-Domain Command and Control (JADC2), the Russian path has been shaped by different institutional constraints, technological dependencies, and, most recently, the operational pressures of the war in Ukraine. As a result, Russia’s approach has evolved from attempts to field comprehensive, centralized systems toward a more fragmented, but pragmatically effective, ecosystem of task-specific software, many of which are optimized for unmanned systems and rapid kill-chain acceleration.
The analysis proceeds from the strategic to the tactical level. It begins by outlining how ACCS is defined in Russian doctrine and professional military literature, tracing its origins, architecture, and the standardization framework the Ministry of Defence has built to support long-term C2 modernization. It assesses the actual state of progress at the strategic level and then shifts to the tactical level, where wartime necessity has driven experimentation with new battlefield management tools, especially for unmanned systems, and where Russia’s most tangible advances in automated C2 have occurred.
The analysis also examines the role of AI in Russian C2 systems and assesses its current state of development and implementation at different levels of command, from strategic decision support concepts embedded in automated control architectures to tactical applications that process sensor data, manage unmanned systems, and accelerate battlefield decision cycles.
Research Approach and Sources
This analysis is based on open-source research and does not rely on classified information. The source base comprises Russian primary materials, including official military journals published by the General Staff and affiliated defense research institutions, which provide insight into doctrinal thinking, technical priorities, and the formal conceptualization of automation, C2, and AI within the Russian Armed Forces.
In parallel, the research systematically monitored and analyzed more than 150 Russian Telegram channels and closed or semi-closed groups associated with civilian engineers, volunteer technologists, and military-affiliated developers supporting the Russian war effort. These communities offer granular, near real-time visibility into how specific systems evolve, what technical problems developers encounter, and how they adapt to constraints.
Finally, this report includes analysis of official Russian media, government publications, and public statements by senior leadership, including President Vladimir Putin, Defence Minister Andrei Belousov, and other senior officials, to assess how the Kremlin frames technological priorities, projects progress, and signals shifts in strategic direction through formal communication.
Russian Command and Control in Transition Toward Autonomy
In Russian military doctrine and professional discourse, the push toward automation and a fully digital operating environment is framed as the creation of “automated command and control system for forces and weapons,” commonly referred to as the Automated Command and Control System (ACCS). According to Russian military thinking, ACCS is a set of integrated automated control and information systems, complexes of equipment for automation, software-hardware complexes, and remote automated workstations distributed across the command hierarchy.1 Though the definition may appear somewhat complex, this concept most closely aligns with the United States’ JADC2.
This section examines the evolution of Russia’s efforts to develop all-encompassing, automated C2 systems and its subsequent shift toward smaller, functional software solutions deployable on the battlefield. It assesses the current state of progress in developing these systems, traces their origins, and analyzes the role of civilian and commercial technologies, including AI, in shaping their development and operational use.
Assessing Russia’s Advancement in Automated C2 Technologies at a Strategic Level
As shown in Figure 1, ACCS is a system of systems in which command structures, operational headquarters, reconnaissance assets, and weapons platforms are interconnected within a single integrated environment for decisionmaking and execution. The central purpose of such a meta-system, as described in Russian military literature, is to increase the effectiveness of force employment by automating core command processes, namely
- continuous collection, processing, and visual display of data outlining the operational picture at the level of operators’ workstations;
- receipt, evaluation, and transmission of combat orders, alerts, identification signals, and targeting instructions; and
- real-time documentation, storage, and processing of operational information and combat documentation as actions unfold.
Figure 1: Automated Command and Control System (ACCS) Architecture
The ACCS concept emphasizes the seamless fusion of technical systems and workflows to integrate decisionmaking with execution. Its central objective is to minimize the temporal gaps between target detection, situational assessment, command issuance, and the application of force. The model aspires to establish a unified, interoperable, and secure digital environment that connects all tiers of the C2 structure, from tactical units to strategic leadership.
Publicly available data provides limited insight into the actual progress achieved in developing this concept. Nevertheless, military and technical literature indicates that Russia’s efforts to build the ACCS began in the early 2000s, with an initial emphasis on standardization. Over the subsequent two decades, the Russian Ministry of Defence has pursued a comprehensive approach to formalize and standardize the evolution of its automated C2 systems. This approach has centered on developing a coherent classification framework for C2 systems, delineating them by functional purpose and hierarchical level, and harmonizing technical, informative, and organizational parameters across all stages of their life cycle.2
To institutionalize these developments, the Ministry of Defence has introduced a set of state military standards regulating the design, production, maintenance, and integration of automated C2 systems, as shown in Figure 2. These standards encompass terminology, system architecture, software-hardware integration, information management, and communication protocols. Together, they provide the regulatory backbone of Russia’s C2 modernization program, establishing a coherent technical foundation that supports interoperability, data integrity, and the gradual incorporation of AI and autonomous capabilities into military decisionmaking.
Figure 2: Categories of Standards for Russia’s Automated C2
An important step toward technical standardization and technological sovereignty has been the Russian military’s shift from Microsoft Windows to a domestic operating system, Astra Linux. A software company RusBITech began developing the system in 2008, and the Ministry of Defence formally adopted it as the unified operating platform for automated C2 systems in 2013. Built on open-source Linux, Astra Linux allows full access to and control over source code, enabling customization for military security requirements that were not possible with closed-source Western software. The Astra Linux Special Edition is now marketed as a single system deployed across C2 systems, servers, and onboard equipment and weapon systems that integrates with secure government document and geospatial systems and that supports domestic processors such as Elbrus and Baikal, reducing reliance on foreign software and hardware.
These actions—standardization efforts and the introduction of locally developed software—suggest that the Ministry of Defence has sought to consolidate military digital infrastructure around a secure, domestically controlled digital infrastructure. These measures were taken to reduce external technological dependencies and ensure that critical military and administrative systems operate in a unified, certified environment aligned with national security requirements.
This effort points to an attempt to establish a foundational layer for automated C2 through standardization and the adoption of a single operating environment. At the same time, the absence of a fully deployed, end-to-end ACCS at the tactical level and the continued reliance of frontline units on volunteer-developed and commercial tools, indicate limited success in translating this foundational work into a functioning, large-scale automated C2 system.
Russia’s development of an integrated ACCS remains constrained by deep-seated methodological and institutional barriers. One central problem is that the Ministry of Defence continues to rely on Soviet-era, state-owned research and development (R&D) institutes whose engineering cultures, processes, and incentives are optimized for traditional hardware-centric programs. These institutions perform well when producing familiar legacy systems such as missiles, electronic warfare (EW) complexes, and other conventional platforms, but they lack the talent base, methodology, and organizational agility required for modern software, data-centric architectures, and AI-enabled capabilities. They also cannot match the speed, flexibility, and iterative innovation cycles characteristic of private technology companies.
Additional inefficiencies compound this problem and, in many cases, stem directly from it. One of the most persistent issues is the poor quality and delayed delivery of foundational data to system developers. As a result, design and modernization work often begins without complete, consistent, or timely information on operational needs, integration pathways, or user requirements.
This information gap originates in outdated procedures for conducting “informational surveys,” the preliminary phase in which necessary data on system requirements and operating conditions is collected and analyzed before software development begins. Russia’s methods, which still rely heavily on paper-based questionnaires and on collecting inputs from a wide array of stakeholders, create significant aggregation and synthesis challenges, diverge from modern data collection and storage practices, and fail to match the complexity of contemporary digital architectures or the demands of network-centric warfare.
Compounding the problem is fragmented institutional responsibility. Data collection and ownership are dispersed among multiple organizations with poorly defined accountability, resulting in duplication, delays, and inconsistent datasets across military and industrial actors.
Finally, the regulatory base itself remains partly obsolete. Existing standards fail to address emerging requirements for interoperability, cybersecurity, and data governance, and do not clearly define the structure or documentation of survey and design processes.
Overall, Russia’s difficulties in advancing its automated C2 systems are rooted less in technological constraints than in methodological and organizational shortcomings that undermine coherence, timeliness, and system integration across the defense establishment.
Assessing Russia’s Advancement in Automated C2 Technologies at a Tactical Level
Russia’s announcement of the “Svod” Tactical Situational Awareness Complex in August 2025 triggered a noticeable wave of discussion among military analysts, largely because it signals yet another attempt to resolve a long-standing problem inside the Russian Armed Forces: the persistent gap between ambitions for network-centric warfare and the uneven performance of actual C2 systems in combat.
The announcement by Defence Minister Andrei Belousov was particularly striking not merely because Svod is a new system, but also because the system was described as the next major step in Russia’s effort to build a coherent digital ecosystem at the tactical level. According to official statements, the system has been under active development since 2024, and was expected to begin experimental field deployment in Russian units in the fall of 2025, with plans for large-scale production and integration across all operational units to follow. This tight timeline reflects broader institutional pressure to modernize Russia’s C2 apparatus amid the ongoing war in Ukraine.
Yet the origins of Svod remain ambiguous. It is unclear whether this is a genuinely new architecture or simply a reconfiguration of earlier projects that never achieved operational maturity. The most relevant precedent system is the Unified Tactical-Level Control System (UTLCS), a program that Russian authorities once positioned as their breakthrough in digital C2. UTLCS reportedly was used during the Kavkaz 2016 exercises and moved into production stage by 2018. Its concept was tied to Russia’s declared vision of network-centric warfare—a tactical environment where secure multifunctional radios, onboard computing nodes, and distributed data links would give units a real-time operational picture and enable faster decision cycles.
In practice, however, UTLCS never lived up to that promise. Reports from the field suggested substantial technical and organizational failures: unreliable data links, inconsistent integration across units, and limited resistance to EW—each of which undermined Russia’s aspiration for seamless digital command. The system became a symbol of the gap between theoretical modernization rhetoric and actual battlefield performance.
Svod is being positioned as a new solution to these old problems. It will only matter, however, if it represents not an incremental upgrade but an entire system that addresses the vulnerabilities exposed in earlier attempts at tactical digitalization. These include the need for survivable communications under heavy EW pressure, interoperable data formats across disparate units, faster processing of battlefield sensor inputs, and user interfaces adapted to real operational conditions rather than laboratory assumptions.
The emergence of Svod should be read less as a single programmatic bet and more as evidence of Russia’s capacity to absorb failure and adapt under pressure. Russian military innovation rarely follows public-facing, large-scale presentations or declared breakthroughs. Instead, systems are typically developed with limited visibility, deployed experimentally, and iterated directly through combat use. If lessons from earlier failures such as UTLCS have been internalized, the indicator of success will not be formal announcements but rather a qualitative shift in how Russian units conduct operations—shorter decision cycles, tighter integration between sensors and fires, and more resilient tactical coordination. Whether through Svod or a successor system, such changes would signal that Russia has translated battlefield experience into functional C2 adaptation rather than merely rhetorical modernization.

Evolving C2 for Unmanned Systems
The war in Ukraine has reshaped the priorities and urgency of the problems that Russian military leadership seeks to solve first. Colonel Sergey Ishtuganov, deputy head of the Armed Forces’ Unmanned Systems Forces, explained in an interview that UASs now carry out up to 80 percent of all fire missions in the war. Russian forces strike roughly 300 targets each day, including armored vehicles and fortified positions.3 These figures illustrate both how decisive unmanned systems have become in combat and that the Russian military increasingly ties the success of its operations to how effectively it manages these systems.
Yet, Russian forces operate an increasingly heterogeneous mix of platforms, rely on human-centric control with limited autonomy, use incompatible communication channels, and face constant spectrum congestion—all of which make it difficult to scale unmanned systems, limit interoperability, slow deployment, and disrupt effective C2. Therefore, the Russian Armed Forces now view integration of all types of unmanned platforms, the codification of combat lessons, and the establishment of an automated, unified combat management architecture as an essential and top priority.
By early 2025, however, Russian military scholars openly acknowledged that, despite the urgency, the Ministry of Defence and the emerging unmanned systems branch still had not fielded a fully functional, full-scale UAS management system. The scholars argued that Ukraine had already deployed comparable automated tactical C2 systems—such as Delta, with its integrated UAS control modules—in the field, putting Russian forces roughly 1.5 to 2 years behind Ukraine.4
Recognizing the scale of the problem, both military and volunteer civilian engineers have focused on developing software that provides situational awareness, refines fire correction, and enables more integrated control of unmanned systems.
Government-Led Efforts to Develop a Combat Management System
The Russian military prototypes that do exist, including several ground and air control or sensor integration systems, either largely treat unmanned platforms as remote sensors or provide only narrow functions, and none of them can manage large-scale, heterogeneous UAS operations. As a result, Russian military leaders have realized that they cannot manage the rapidly expanding UAS force by means of legacy control concepts or fragmented, stalled C2 initiatives. Leadership has therefore begun shifting its focus from broad automated C2 concepts, such as ACCS, to a more targeted system built specifically for unmanned systems management.
Russia has not released a full plan, but its direction becomes clear when the fragmented initiatives showcased in state media are viewed in tandem. These signals reveal a consistent push to build new systems and to embed AI-enabled technologies into their architecture. Two sets of actions in particular reveal Russia’s larger push for a new, centralized system.
First, the military began collecting large volumes of drone footage and turning it into structured datasets. Precise timelines for the first centralized directives remain unclear, but available reporting indicates that Defence Minister Andrei Belousov initiated this effort in mid-2025 by directing the establishment of a unified database to record and analyze enemy losses inflicted by drones. Building such a database required a system capable of automatically recording, aggregating, and processing information from UAS operators, thereby generating data both for operational analysis and for training AI models intended to enhance drone operations effectiveness.
In late August 2025, the Ministry of Defence shared a video of Belousov inspecting the command post of the “Center” force grouping. Although most likely part of Russian propaganda efforts, the video provides a glimpse into what the Russian military is working on currently. During the minister’s visit, the staff reported that they had fulfilled his directive to create and populate a database capturing effects achieved by UASs. They also demonstrated a software system that automatically aggregated and analyzed operator-reported drone activity. Staff assured Belousov that the system was able to integrate all classes of drones currently in use.
The video showcased an emerging system that not only captures how each drone performs but also how each operator develops over time. Instructors gain access to detailed performance trajectories for every pilot, tracking whether individual skills improve or deteriorate. Each operator’s footage is linked to a unique personal identification number assigned to every trainee. This linkage between personal IDs and video streams eliminates opportunities to manipulate results or falsify performance data. All stored material contributes directly to AI training datasets.
Second, the military began developing a battlefield management system designed specifically for drone operations. In September 2025, the Ministry of Defence convened a Technical Council on the Development of the Drone Management System to advance efforts aimed at creating a unified system for managing drone missions. The council brought together senior leaders from the military, research institutes, industrial enterprises, and operational units, with a central focus on improving C2 of unmanned systems across the air, ground, and potentially maritime domains.5
The database aggregating detailed records of enemy losses functions both as a training tool and as an analytical resource for refining drone employment tactics. As these tactics evolve, they feed directly into updates of the system’s design and the outputs it can generate. In parallel, the ministry is testing a software platform that allows field operators to transmit UAS data automatically into a different database from which a drone management system synthesizes and analyzes the information in an automated mode. The broader objective is to create a continuous feedback loop that links drone operators, command elements, and system developers, ensuring that tactical insights translate rapidly into technical improvements.
Out-of-Government Efforts to Develop Battlefield Management Software
Beyond the formal military initiatives, a parallel ecosystem of software solutions has emerged from the commercial sector, volunteer civil engineers, and often anonymous developers. The dynamic resembles a trend observed in Ukraine: Commercial technologies are rapidly weaponized and adapted for military needs by civilian innovators and volunteer groups, who operate with greater speed, agility, and creativity than traditional military institutions shaped by older R&D cultures and methods.
Russian forces have leaned heavily on commercial off-the-shelf software, most notably AlpineQuest, a civilian navigation app repurposed by Russia as a battlefield mapping tool. Originally designed for hikers and off-road users, AlpineQuest enabled Russian troops to work with offline topographic maps, mark targets and artillery positions, plan routes, and share coordinates across units. Its accessibility and support for multiple coordinate systems had made AlpineQuest a de facto navigation aid discussed openly in military Telegram channels. This reliance, however, created a major security vulnerability. In early 2025, a compromised version of the app circulated through unofficial channels, embedding spyware that quietly exfiltrated geolocation data, contacts, files, and GPS logs. The episode demonstrated how dependence on unsecured commercial software exposed Russian units to surveillance and intelligence collection through their own digital tools.
A similar pattern emerged with Discord, a commercial communication platform originally built for gaming. Russian units adopted it for ad hoc C2, using voice channels, text chat, and live video to stream drone feeds, exchange targeting data, and coordinate attacks in real time. Discord’s ease of use and ability to run on personal devices made it especially attractive to frontline drone teams. Yet this convenience also became a liability. In 2024, Russian authorities banned Discord, designating it a foreign platform accused of hosting extremist or illicit content. This move abruptly disrupted improvised coordination networks and forced Russian units to rely on VPNs to retain access to Discord. Despite the ban, many have continued to use the platform due to the lack of comparable alternatives.
These cases demonstrate that while Russia’s rapid repurposing of civilian technologies addressed urgent battlefield needs, it also introduced systemic vulnerabilities. In response, volunteer networks and civilian developers supporting the war effort began building domestic alternatives that were later taken up, formalized, and scaled by the Russian Armed Forces.
Beginning in early 2024, the first references to new domestically developed battlefield management systems started to appear in Russian media and official communications. These initiatives signaled a wider effort to replace the many improvised and often compromised commercial tools that had dominated the first years of the war in Ukraine. What emerged was the outline of a deliberate push to build secure, purpose-designed systems that could withstand both external threats and the structural vulnerabilities exposed by earlier ad hoc solutions.
The “Glaz/Groza” software system represents one of Russia’s efforts to digitize military operations. Though its developer remains unknown, that is typical for many of the civilian-military initiatives which have become fielded Russian battlefield technologies. Originally designed for artillery and mortar fire adjustment, Glaz/Groza developed into a much broader solution. Available evidence suggests that the system was developed in 2023 and that pilot versions had entered operational units in early 2024, likely for troop-level trials under combat conditions. However, reporting from August 2025 suggests that Glaz/Groza has since become relatively widespread, with drone units, artillery batteries, fire control crews, and supporting reconnaissance elements all making routine use of its hardware and software.
The Glaz/Groza complex functions as a layered digital ecosystem designed to link UAS reconnaissance, geospatial mapping, and artillery fire control into a single integrated workflow. At its core, the system consists of three major components: the Glaz family of applications used by drone operators, the Groza fire control and mission management environment, and the auxiliary ZOV Maps platform that extends the overall system’s cartographic and geospatial capabilities.
Glaz represents the drone operator–facing segment of the complex. Installed on DJI and Autel remote controllers as well as on Android tablets, it provides UAS pilots with real-time tools for geolocation, target marking, and rapid extraction of coordinates directly from drone footage. Despite the variety of versions—ranging from lightweight builds for commercial drones to more advanced types optimized for professional platforms—the Glaz suite performs one function: transforming UAS footage into precise digital target data and passing this information seamlessly into the broader system.
If Glaz is the reconnaissance interface, Groza serves as the decisionmaking and fire support hub. Running on Windows laptops or Android tablets, Groza offers a full-featured digital map environment, automated artillery adjustment tools, and channels for rapidly transmitting coordinates, corrections, and impact assessments to artillery, mortar, and tank crews.
Over time, Groza has expanded beyond traditional fire control. In its more recent iterations, it integrates newly introduced drone mission planning capabilities aimed at solving two chronic, related operational problems inside Russian UAS units: the uncontrolled competition for frequencies and regular friendly jamming. The new module allows units to reserve frequencies within their area of responsibility, plan routes for drone flights with radio-visibility calculations, and maintain an inventory of drones, effectively centralizing coordination of strike UAS missions within the same digital environment used for reconnaissance and artillery support.
Complementing both systems, ZOV Maps provides an alternative to AlpineQuest. ZOV Maps is a domestic mapping platform, compatible with Groza and other Russian military applications, that offers online and offline geospatial layers, improved tools for annotating and editing objects on the map, and more stable handling of live geolocation feeds. ZOV Maps functions as the cartographic backbone of the Glaz/Groza complex, allowing military units to navigate terrain, share positional data, and build a shared operational picture using domestic mapping resources.
Figure 3: The Glaz/Groza Digital Kill Chain
As shown in Figure 3, the Glaz/Groza complex functions as an integrated reconnaissance-strike system that links UAS operators, fire direction centers, and firing units into a single digital kill chain. The process of conducting a strike begins with a drone team. The UAS operator conducts aerial reconnaissance using Glaz, which is installed on a remote controller. Once a target is identified, the operator places the crosshair on the object and marks it with one click. Glaz immediately extracts the coordinates from the drone’s telemetry and sends them to a second team member equipped with a tablet running Groza.
Groza operates as the fire control hub. The marked target appears instantly on its digital map, after which the system automatically performs ballistic calculations using pre-loaded firing tables for Russian artillery and mortar systems. The fire direction officer receives a complete fire mission package—range, deflection, and elevation—and transmits it directly to the firing units. The moment the first round lands, the UAS operator shifts the crosshair to the impact point and sends a correction, if needed, which Groza converts into updated firing data. This digital feedback loop replaces earlier manual orientation and voice reports, reducing the time from detection to impact from hours to just a few minutes.
In conversations with CSIS researchers, Ukrainian military sources have mentioned another Russian system, Astra-M, which visually resembles Ukraine’s Delta situational awareness platform and is reportedly intended either to provide similar functions to Delta or to serve as a replacement for Discord in Russian units. Its name strongly echoes Astra Linux, the secure operating system developed for the Russian military and government mentioned previously, suggesting that Astra-M may be linked to the same developer or built on a military-approved technological stack. Whether this system will reach full deployment remains to be seen.
The Glaz/Groza complex and the possible existence of the Astra-M system demonstrate that while the Russian military continues to experiment and often lags behind Ukraine in developing new innovations, it rapidly scales any tools that prove effective. New software solutions are rolled out systematically, and they begin with training. Instruction now takes place across formal Russian military academies, dedicated training centers, and volunteer-run drone schools. At the training range of the “Center” force grouping, for instance, mortar crews are learning to operate the newly fielded Glaz/Groza software complex—a system also included in the curriculum of the Mikhailovskaya Military Artillery Academy and the “Arkhangel” school, where the training program spans 10 days.
Together, these components—Glaz for UAS sensing, Groza for command and fire control functions, and ZOV Maps for geospatial support—form a unified digital architecture intended to accelerate Russia’s kill chain at the tactical level. The recent integration of drone mission management indicates a further evolution toward consolidating reconnaissance, strike planning, and artillery coordination within a single software ecosystem.
This larger developmental ecosystem highlights the central role of Russia’s volunteer and civilian engineering community in addressing the military’s most urgent battlefield gaps. Drawing on a broad civilian talent pool, volunteer groups rapidly adapt commercial technologies and develop bespoke software that supports combat operations using the latest available tools, often faster than formal defense institutions can respond.
Where the Russian military consistently demonstrates strength is not in initial innovation but in scaling what works. Once a software solution proves operationally useful, it is quickly formalized, standardized, and propagated throughout the Russian force, with military training serving as the primary vector of diffusion. From the outset of drone instruction, soldiers are trained not only on platforms and tactics but also on the accompanying digital tools, ensuring that software adoption becomes embedded in routine operations rather than treated as an auxiliary capability.
The Role of AI in Russia’s C2 Systems
Publicly available information provides only a limited basis for assessing the actual degree to which AI-enabled technologies have been introduced or deployed within Russia’s C2 systems. Nevertheless, materials published by the Russian Ministry of Defence and other military institutions outline a coherent vision for how AI is expected to function within the ACCS. According to these sources, the AI-enabled subsystem serves as an “intelligent component” (see Figure 4) that complements existing C2 processes, information flows, and communication channels while drawing on the full spectrum of data circulating within the broader ACCS architecture.
The main task of the AI-enabled subsystem is to generate predictive assessments of the likely trajectory and outcomes of ongoing or future military engagements. Within this framework, AI augments the traditionally creative and analytical work of commanders and staff by producing forecasted metrics—such as the depth and tempo of advance, projected losses, and other aggregate indicators—which are then mapped to develop alternative courses of action for both friendly and opposing forces. Through such prognostic outputs, the “intelligent” subsystem will be able to provide decision support intended to offer more rational operational choices, while the ultimate decisionmaking remains the responsibility of the commander.6
Figure 4: The Role of AI in ACCS
Russian military writings argue that two foundational technological components must be resolved before a fully functional, AI-enabled ACCS can emerge: advanced visual data analysis and mature natural-language processing. Russian specialists view these domains as progressing at markedly different rates.
Visual and Audio Analysis
In the realm of sensory and visual data processing, AI integration has advanced considerably. Automated systems for collecting and analyzing sensor information already employ neural networks for real-time recognition of visual, radar, hydroacoustic, and other signals. Computer vision technologies in particular have reached a relatively high technological readiness level (TRL)—estimated at TRL 6–9—and are usable in practical, field-tested applications. These technologies support automatic target recognition (ATR) and guidance capabilities in unmanned platforms that operate as loitering munitions.
One example of software from this category is Platform-GNS, short for “Unified Software Platform for Developing End-Oriented Complexes for Automatic Object Recognition Using Neural Network Approaches.” This is a Russian software environment designed to supply a full technological stack for developing applied solutions based on deep neural networks. Platform-GNS was developed by the Center for Artificial Intelligence Technologies of the Zhukovsky Research Center, an institution established by leading aviation research bodies, including the State Research Institute of Aviation Systems and the Central Institute of Aviation Motors. Platform-GNS was created for advancing both aviation-related systems and AI-enabled autonomy more broadly. Notably, the platform and its associated tools are distributed free of charge to Russian defense enterprises, Ministry of Defence organizations, and educational institutions under a specialized licensing framework, facilitating widespread adoption across the national defense and research ecosystem.
Platform-GNS is a unified environment for developing AI applications based on deep convolutional neural networks. It supports the entire AI application development lifecycle, from dataset preparation to model training, testing, and deployment. It includes a graphical no-code interface and advanced tools for engineers, enabling a wide range of machine vision tasks such as detection, classification, segmentation, tracking, and image enhancement. The system works with multispectral data, includes signal processing modules, and allows integration of custom solutions through an open Application Programming Interface (API). Planned upgrades for 2025–2026 will add support for large language models to enable smart assistants and more autonomous AI systems.
Platform-GNS Avtomat is a specialized version of the platform designed specifically for high-precision object recognition, particularly the identification of ground targets from airborne sensors. While inheriting the full development workflow of the core platform, Avtomat adds capabilities optimized for target recognition missions, automated testing, and deployment on Russian processors such as Elbrus and NeuroMatrix. Avtomat supports a comparable range of machine vision functions, with models exportable in ONNX format for flexible use across different hardware. In short, Platform-GNS provides the general-purpose foundation, while Avtomat serves as its more specialized, mission-tailored extension.
The Platform-GNS family of systems is used, for example, at the ERA military innovation technopolis and provides the underlying infrastructure for training neural networks that support real-time machine vision.7 These capabilities are being incorporated into prototype AI-enabled control and targeting systems across Russia’s defense industrial base.
In combination, these developments indicate that Russia has deliberately concentrated its AI investment where technical feasibility, data availability, and operational payoff align. Visual and sensory data processing have emerged as mature domains because they support concrete military tasks such as target detection, tracking, and guidance that can be validated directly in combat and refined through continuous feedback.
Platforms such as Platform-GNS reflect an industrial strategy focused on enabling scale rather than producing singular breakthrough systems. A common development environment, broad licensing across defense and education, and compatibility with domestic hardware all lower barriers to adoption and accelerate diffusion. While these tools do not yet constitute fully autonomous control systems, they do provide a robust backbone for incremental autonomy in unmanned platforms. The result is an AI capability that advances unevenly across domains but progresses steadily where battlefield utility is clear, reinforcing Russia’s pattern of prioritizing applied effectiveness over conceptual completeness.
Textual Analysis
Textual analysis presents a far more difficult challenge than that of visual or sensory data. Automated systems for natural language processing (NLP), which underpin analytical functions and many C2 subsystems, lag significantly behind visual processing tools. Russian assessments place current NLP technologies available to the Russian military at roughly TRL 1–3, reflecting an early research and experimental stage. As a result, key tasks—such as constructing semantically structured documents, performing context-aware searches, and generating meaningful automated textual decision support—remain technically immature and far from operational deployment.8
Textual analysis capability is particularly important because, for example, analysis of commanders’ time distribution indicates that the largest share of time during mission planning and execution is absorbed by the preparation of documents—that is, paperwork. More than half of the allotted time (over 55 percent) is devoted to drafting, presenting, and approving documentation, while less than half is spent on substantive decisionmaking and coordinating essential elements of combat organization, including communication, command, and support. This creates a clear operational demand for an intelligent capability for paper flow management that could enhance the efficiency of command personnel.
The main obstacles in the domain of textual analysis are both technological and organizational. They arise from the difficulty of designing neural network architectures capable of capturing meaning, context, and intent in Russian-language military texts, as well as from the absence of certified, military-grade AI tools suitable for secure deployment within the Russian Armed Forces. At present, no such certified systems are in operational use.
To close the widening gap between relatively advanced visual data processing and the far less mature field of automated text analysis, the Russian military will likely follow the global pattern of adapting commercial large language models (LLMs) for defense needs. Although no public evidence indicates formal partnerships between major Russian tech companies and the Ministry of Defence, the foundational models of private tech companies are well positioned to be repurposed for military applications. Adaptation of commercial LLMs would require controlled collaboration and access to classified datasets to support tasks such as semantic text structuring, contextual searching, and automated information extraction for C2 environments.
More probable than these partnerships would be a dispersed, bottom-up process in which civilian engineers work informally to tailor existing commercial models for military tasks to support the Russian war effort. Over time, this wave of integration of commercial technology is likely to produce a new generation of adapted LLMs capable of processing unstructured textual data at scale, thereby narrowing the gap with visual processing technologies and bringing automated decision support tools closer to operational maturity.
Recent trends in the Russian job market show how the country’s AI stack is taking shape and what developers actually use to build applications. By mid-2025, companies had already moved from isolated LLM experiments to full-scale deployment. Retrieval-augmented generation (RAG) has become the dominant architecture. More than a third of AI-related vacancies mention it, and developers increasingly build systems that combine LLMs with structured document repositories for search, analysis, and automation. Companies no longer focus on simple chatbots.
The technology stack in the Russian innovation ecosystem has also settled. Enterprise teams rely on Russian LLMs such as GigaChat or YandexGPT, while startups and R&D groups choose open-weight mod

[TEXT TRUNCATED]

================================================================================

################################################################################
SOURCE 5
################################################################################

TITLE: The Role of AI in Russia’s Confrontation with the West
URL: https://www.cnas.org/publications/reports/the-role-of-ai-in-russias-confrontation-with-the-west
DOMAIN: cnas.org
AUTHOR: Samuel Bendett
DATE: 2024-05-03
SEARCH QUERY: Russian AI capabilities
TEXT LENGTH: 13225

SEARCH SNIPPET:
May 3, 2024 · As Russia increasingly operates in the air, sea, ground, space, cyber, and information domains, it views its ability to access, understand, manage, and act upon the massive amounts of data generated by multiple sources and systems as a key battlefield requirement.

--------------------------------------------------------------------------------
PAGE TEXT:

Executive Summary
Russian thinking about artificial intelligence (AI) development is consistent with that of other major powers that are seeking to respond to an evolving combat environment characterized by growing complexity and rapid technological change. Russia has made several pronouncements on the importance of AI in combat, yet it is often difficult to estimate whether the country’s Ministry of Defense (MOD) actually has utilized AI-enabled systems and weapons, including on the Ukrainian battlefield. Western sanctions and export controls also have the potential to increase the headwinds that Russia faces in its ability to meet its AI objectives.
Presently, the Russian military establishment is investing in AI research, development, testing, and evaluation (RDT&E) seen as most relevant today and in future combat. These investments are shaped both by the understanding of where such emphasis is placed among likely competitors, such as the United States and NATO, and where resources should be allocated based on the ongoing complicated combat in Ukraine.
Russian military discourse emphasizes that in the long term, there will be an eventual point where technologies subsume and then replace human involvement in military operations—yet in the near term, Russian military thinking affirms that humans must remain firmly in the loop. Like many major military powers around the world, the Russian MOD is investing in the development and application of different types of uncrewed systems for the air, maritime, and ground domains. At this point, as a reflection of combat in Ukraine, improving uncrewed aerial vehicle (UAV) capabilities with AI as a mechanism for command, control, communications, computers, intelligence, surveillance, and reconnaissance (C4ISR) is a key emphasis in both academic writing and research and development (R&D) across Russia’s defense-industrial complex. The use of AI for data collection and analysis is also a significant part of the MOD’s impending “intellectualized” warfare as a natural evolution from the current “digital” combat technology and systems development, with AI envisioned as a data analysis enabler and a decision-making aide to operators, commanders, and deployed forces.
      Russian thinking about artificial intelligence development is consistent with that of other major powers that are seeking to respond to an evolving combat environment characterized by growing complexity and rapid technological change.
According to public statements, the Russian government also places a significant emphasis on using AI in information and cyber operations. Russia also is likely to apply AI in its nuclear forces command, control, management, and use. However, Russia’s invasion of Ukraine has exposed multiple deficiencies in its conduct of the war, given significant personnel and matériel losses and battlefield setbacks in 2022 and 2023. To address these challenges, the Russian government is accelerating a centralized approach to AI development and forcing greater cooperation between the country’s military and civilian sectors. For its part, the military is enabling loitering munitions, aerial drones, and certain ground-based robotic systems with greater capabilities that include AI, while potentially using it in information and cyber operations.
Yet the war in Ukraine and the resulting international sanctions also are constraining Russia’s AI development to a certain extent, with the Kremlin trying to offset such disadvantages. To mitigate the impact of Western economic pressure, Russia is pursuing import substitution and technological sovereignty programs aimed at bolstering domestic high-tech R&D and manufacturing, as well as creating investment funds and programs for domestic AI companies and entrepreneurs, while also funding future workforce developments across the national academic establishment. Russia also will rely on China for AI-related technological and policy developments, as U.S. and international pressure aims to close off certain technology cooperation and procurement avenues and outlets for Russia’s domestic AI R&D.
Despite such constraints, Russia will retain certain AI capabilities that will pose challenges for the West. It is evident that despite the difficulties Russia is experiencing on the Ukrainian battlefield and at home as it tries to maintain domestic high-technology AI R&D, the Russian Federation is dedicating government, academic, industrial, and financial resources to ensure its AI development. Such efforts deserve close and continued scrutiny.
Introduction
Russian thinking about artificial intelligence (AI) development is consistent with that of other major powers that similarly are seeking to respond to an evolving combat environment characterized by growing multi-domain complexity and rapid technological change. As Russia increasingly operates in the air, sea, ground, space, cyber, and information domains, it views its ability to access, understand, manage, and act upon the massive amounts of data generated by multiple sources and systems as a key battlefield requirement. The Russian military’s development of AI has been a decades-long path that has accelerated significantly in the past 20 years. Improvements in technology developments, access to international software and hardware, increasing global competition that has driven the Russian Ministry of Defense (MOD) to achieve real results, and Russia’s gradual progress conceptualizing AI use in combat all have propelled Russian advances.
However, as the war in Ukraine has demonstrated, there is often a significant gap between Russian statements of its military capabilities and its real-world capacity. The same is likely to be true in terms of AI. Despite Russian pronouncements on the importance of artificial intelligence in combat in general, and for domestic weapons development in particular, it is difficult to estimate whether the MOD actually has utilized different AI-enabled systems and weapons on the Ukrainian battlefield. Moreover, Western sanctions and export controls only would increase the headwinds that Russia faces in its ability to meet its AI objectives. Russia is now excluded from certain well-established technological supply chains, causing numerous challenges, including the need to rapidly restructure domestic high-tech research, development, and implementation. The exodus of many Russian citizens in the aftermath of the invasion, many of whom included IT professionals, also may widen the gap between Russia’s objectives and capacity.
Although Russia faces obstacles to its AI development, the Kremlin will seek to offset the challenges it faces. The Kremlin and the MOD clearly are determined to maintain military primacy in the post-Soviet space, to withstand the pressure from the United States and NATO, and to emerge victorious in the war against Ukraine. Within this context, the development of AI is a key national security priority in what the Kremlin sees as a civilizational mission toward which it will seek to mobilize Russia’s entire national human and technological potential. Russia also can reach out to its allies and partners for military-technological cooperation that persists despite U.S. and Western efforts to limit such engagements.
Given the myriad challenges and shortcomings that Russia faces, it will lag behind the United States and China in AI in the near to mid term. However, Russia’s AI capabilities still create challenges that U.S. and international policymakers and defense planners must navigate. In other words, Russia will remain a capable power, whose AI capabilities pose real challenges that impact not just the battlefield, but the broader confrontation that Moscow sees itself as waging against the West. Moreover, Russia’s military setbacks in Ukraine may perversely amplify the risks that AI poses to the West as the Kremlin seeks AI to supercharge its asymmetric tools. The more Russia sees itself as falling behind the West in high-tech development, the more vulnerable it may perceive itself to be, which may lead Moscow to accept greater risk in the way that it deploys AI to keep apace.
This paper assesses Russian thinking on AI and its likely development, including how the war in Ukraine is shaping this trajectory. To that end, Section 1 provides an overview of Russia’s thinking about AI and its military applications and Moscow’s goals and objectives in this realm. Section 2 focuses more specifically on how Russia’s war in Ukraine is shaping Russia’s thinking on and approach to its AI sector. Because the war is ongoing, it is too soon to provide definitive conclusions about how the conflict in Ukraine will influence Russia’s AI trajectory. Moreover, it is difficult to assess the true state of Russia’s military AI development, especially given the decreasing amount of publicly available data post–Ukraine invasion and the classified environment for the nation’s military high-tech developments.
Nonetheless, the paper offers preliminary assessments based on the sources described below that factor in how the war has increased the challenges Russia will face in further developing its AI sector. Section 3 articulates the constraints that Russia faces, as well as the efforts the Kremlin is likely to make to mitigate those challenges. Finally, Section 4 spells out the key implications of Russia’s AI trajectory for U.S. policymakers and defense planners. An appendix provides additional details on Russia’s relations with external partners.
The paper’s assessments are based predominantly on public statements, announcements, and analyses in the Russian-language media, including from a military-academic ecosystem that comprises practicing and retired Russian civilian and military scientists, researchers, academics, and officers. Several key Russian documents merit highlighting. Major developments in this space are guided by the MOD’s Creation of Prospective Military Robotics through 2025 comprehensive target program launched in 2014. This classified document is supposed to be the main guiding roadmap for the development of aerial, ground, and maritime robotics.1 It no doubt discusses the development of autonomy and AI and likely is being edited, updated, or revised based on the ongoing invasion of Ukraine and the resulting trends and developments. Additionally, on July 26, 2022, the MOD adopted the Concept of the Russian Armed Forces Activity in the Development and Use of Weapon Systems Using Artificial Intelligence Technologies, an initiative that serves as one of the guiding roadmaps for AI adoption. This document was made public at the United Nations in March 2023.2 These and other sources have made it possible to piece together the main elements of this MOD-affiliated AI ecosystem and related research, development, testing, and evaluation (RDT&E) programs and efforts.
Such sources offer a glimpse into Russian deliberations and debates on the role and utility of AI on the modern battlefield and help analysts understand what the Russians emphasize in terms of AI research and development (R&D). This public discussion across the MOD has been characterized by arguments that the future of war, in whatever form it takes, will be dominated by AI-enabled warfare. It is that underlying belief that has driven the Russian military to invest in the resources and knowledge needed to prepare for such wars. This paper sheds insight into Russian thinking and Moscow’s priorities for the future.
- “The Ministry of Defense Approved a Program for the Development of Military Robots [Минобороны утвердило программу по созданию военных роботов],” Lenta.ru, December 4, 2014, https://lenta.ru/news/2014/12/04/robots. ↩
- K.V. Vorontsov, “Speech by Deputy Head of the Russian Delegation K. V. Vorontsov during the Thematic Discussion on the Section ‘Conventional Arms’ in the First Committee of the 77th Session of the UN General Assembly [Выступление заместителя руководителя российской делегации К.В.Воронцова в ходе тематической дискуссии по разделу «Обычные вооружения» в Первом комитете 77-й сессии ГА ООН],” (speech, First Committee of the 77th session of the UN General Assembly, October 20, 2022), https://russiaun.ru/ru/news/201022_v. ↩

================================================================================

################################################################################
SOURCE 6
################################################################################

TITLE: From Code to Combat, the Rise of Artificial Intelligence in Russia
URL: https://insidetelecom.com/artificial-intelligence-in-russia-a-push-for-technological-power
DOMAIN: insidetelecom.com
AUTHOR: Natalia El Hajj
DATE: 2025-10-06
SEARCH QUERY: Russian AI capabilities
TEXT LENGTH: 5420

SEARCH SNIPPET:
Oct 6, 2025 · In the pace of wars, the capability of artificial intelligence in Russia for military and civilian purposes is growing, drawing on lessons learned on the battlefield in Ukraine, and international cooperation with China to advance command systems, drones, cyber operations, and air defenses.

--------------------------------------------------------------------------------
PAGE TEXT:

In the pace of wars, the capability of artificial intelligence in Russia for military and civilian purposes is growing, drawing on lessons learned on the battlefield in Ukraine, and international cooperation with China to advance command systems, drones, cyber operations, and air defenses.
Moscow stresses on artificial intelligence in Russia, as a strategic priority. However, challenges exist, and results are determined by technology in Russia sanctions, talent shortages, and ideological constraints. The Kremlin’s effort aim to modernize military operations, enhance surveillance and targeting, and compete on a global level with digital leaders; US and China.
Digital Transformation vs Russian Military
The Russian AI plan goes back to the 1960s Soviet “science city” of Zelenograd, where the nation started to experiment early with neural networks and automated systems to support anti-missile and air defense technology. Russian naval cruise missiles like the P-700 Granit employed proto-AI in targeting sea and land targets.
The aftermath of the fall of the Soviet Union, Russian technology development lagged but gained momentum after the 2014 annexation of Crimea and escalating tensions with the west.
In 2019, Russia took a step towards legalizing its AI ambitions with the National Strategy on the Development of Artificial Intelligence (NAIS) to 20230, with a vision of gaining significant market share globally. Military applications were outlined in 2021 as fire control systems, air and missile defense, robotics, electronic warfare, and training simulators.
The invasion of Ukraine in 2022 marked the first war where artificial intelligence in Russia played a major role. Russian forces were confronted by strong Western AI systems like the US systems from Maven and Palantir, that let Ukraine decode and counter Russian operations in real-time. In response, the focus went on Russia AI development through command networks, like the Pantsir S-1, S-300, S-400, and S-350 Vityaz.
Intelligence was also applied in AI-guided drones Ukraine-Russia, allowing swarm deployments feasible with real-time task allocation.
In August 2023, Russian Ministry of Defence (MoD) overseed more than 500 AI projects. Flagship entities include Military Technopolis “Era,” JSC Ruselectronics – largest Russian manufacturer of radio electronic technologies-, and United Aircraft Corporation, all working on AI Russian military drones research and application.
Analysts note that Russia’s hands-on battlefield experience, is a likely “revolution in military affairs” providing unmatched real-world data for future technology in Russia development.
Russia AI Strategy and Global Ambitions
Despite the Putin AI investment, technological and human resource constraints stand as obstacles. Western-imposed sanctions have stopped high-end semiconductors and GPUs, limiting high-performance computing for AI. On the other side, attempts at Chinese, Indian, and Kazakh imports have been partially successful.
What affected the situation also is around 100, 000 IT professionals that left Russia after escalating tensions, affecting the local Russian weapons hybrid warfare capabilities. To rise from this use, the Kremlin created the Artificial Intelligence Development Center, tasked with coordinating AI projects across government, regions, and businesses, repeating proven solutions, and organizing international cooperation.
“Our task is to make those results accessible to all Russians and to make our country more competitive in world markets through the development of modern technologies,” Deputy Prime Minister Dmitry Grigorenko said.
Ideological constraints further complicate the situation. Past President Dmitry Medvedev went after Yandex’s Alice voice assistant for refusing to respond to politically sensitive questions, demonstrating the pressure on AI drone in Russia to conform to Kremlin narratives.
Simultaneously, Putin has emphasized AI must cover every corner of Russian life, framing leadership in Putin AI as a national calling to strengthen his country’s position amid escalating tensions.
To overcome limitations, global partnerships are the way to escape. Russia collaborates with China in the development of AI, explores cooperation with authoritarian states like Venezuela and even North Korea, and continues combat testing in Ukraine.
Russian experts are aware of the technology disadvantage against the US and China, but look to experience in direct battles, concentrated resource control, and strategic partnerships as ways to accelerate Russia AI weapons development.
Will Electronic Warfare Russia Surpass Major Powers?
AI initiatives driven by Russia, from the past till now guided by the imperatives of war, sanctions, and global competition, are a strategic push to change the modernization of armed forces and gain power over technology.
Amid unlimited challenges, growing artificial intelligence in Russia capabilities, back by real-time battlefield efforts and strategic collaborations, can really impact army dynamics and combat situations. The focus on Russia’s AI power is a proof of Moscow’s goal to bridge the technological gap with major global rivals, especially the US.
Inside Telecom provides you with an extensive list of content covering all aspects of the tech industry. Keep an eye on our Geopolitical Strategy sections to stay informed and up-to-date with our daily articles.

================================================================================

################################################################################
SOURCE 7
################################################################################

TITLE: Cyberwarfare by Russia - Wikipedia
URL: https://en.wikipedia.org/wiki/Cyberwarfare_by_Russia
DOMAIN: en.wikipedia.org
AUTHOR: 
DATE: 2009-01-14
SEARCH QUERY: Russian hackers AI capabilities
TEXT LENGTH: 50018

SEARCH SNIPPET:
Many countries, including the United States, United Kingdom, Russia, China, Israel, Iran, India, and North Korea, have active cyber capabilities for offensive and defensive operations.

--------------------------------------------------------------------------------
PAGE TEXT:

Cyberwarfare by Russia includes denial of service attacks, hacker attacks, dissemination of disinformation and propaganda, participation of state-sponsored teams in political blogs, internet surveillance using SORM technology, persecution of cyber-dissidents and other active measures.[1] According to investigative journalist Andrei Soldatov, some of these activities were coordinated by the Russian signals intelligence, which was part of the FSB and formerly a part of the 16th KGB department.[2] An analysis by the Defense Intelligence Agency in 2017 outlines Russia's view of "Information Countermeasures" or IPb (informatsionnoye protivoborstvo) as "strategically decisive and critically important to control its domestic populace and influence adversary states", dividing 'Information Countermeasures' into two categories of "Informational-Technical" and "Informational-Psychological" groups. The former encompasses network operations relating to defense, attack, and exploitation and the latter to "attempts to change people's behavior or beliefs in favor of Russian governmental objectives."[3]
| Part of a series on |
| War |
|---|
Cyberwarfare is the use of cyberattacks against an enemy state, causing comparable harm to traditional warfare.[4] Some intended outcomes could be espionage, sabotage, propaganda, manipulation, or economic warfare.
Many countries, including the United States, United Kingdom, Russia, China, Israel, Iran, India, and North Korea, have active cyber capabilities for offensive and defensive operations. As states explore the use of cyber operations and combine capabilities, the likelihood of physical confrontation and violence playing out as a result of, or part of, a cyber operation is increased. However, meeting the scale and protracted nature of war is unlikely, thus ambiguity remains.[5]
There has been significant debate among experts regarding the definition of cyberwarfare, and even if such a thing exists.[6] One view is that the term is a misnomer, since no cyberattack to date could be described as a war.[7] An alternative view is that it is a suitable label for cyberattacks that cause physical damage to people and objects in the real world.[8]
The first instance of kinetic military action used in response to a cyberattack resulting in the loss of human life was observed on 5 May 2019, when the Israel Defense Forces targeted and destroyed a building associated with an ongoing cyberattack.[9][10]
US journalist Pete Earley described his interviews with former senior Russian intelligence officer Sergei Tretyakov, who defected to the United States in 2000:
Sergei would send an officer to a branch of the New York Public Library where he could get access to the Internet without anyone knowing his identity. The officer would post the propaganda on various websites and send it in emails to US publications and broadcasters. Some propaganda would be disguised as educational or scientific reports. ... The studies had been generated at the Center by Russian experts. The reports would be 100% accurate [11]
Tretyakov did not specify the targeted web sites, but made clear they selected the sites which are most convenient for distributing the specific information. According to him, during his work in New York City in the end of the 1990s, one of the most frequent subjects was the War in Chechnya.[11]
According to a publication in Russian computer weekly Computerra, "just because it became known that anonymous editors are editing articles in English Wikipedia in the interests of UK and US intelligence and security services, it is also likely that Russian security services are involved in editing Russian Wikipedia, but this is not even interesting to prove it — because everyone knows that security bodies have a special place in the structure of our [Russian] state"[12]
It has been claimed that Russian security services organized a number of denial of service attacks as a part of their cyber-warfare against other countries, such as the 2007 cyberattacks on Estonia and the 2008 cyberattacks on Russia, South Ossetia, Georgia, and Azerbaijan.[13][14] One identified young Russian hacker said that he was paid by Russian state security services to lead hacking attacks on NATO computers. He was studying computer sciences at the Department of the Defense of Information. His tuition was paid for by the FSB.[15]
The Russian invasion of Ukraine in February 2022 saw renewed interest in information warfare, with the widespread dissemination of propaganda and misinformation on social media, by way of a large-scale Russian propaganda campaign on social media,[16] especially in countries that abstained from voting on the United Nations Resolution ES-11/1 such as India, South Africa, and Pakistan. Bots played a disproportionate role in the dissemination of pro-Russian messages and amplified its proliferation in early-stage diffusion, especially on platforms like Twitter, where pro-Russian messages received ~251,000 retweets and thereby reached around 14.4 million users. Of these "spreaders", around 20.28% of the spreaders are classified as bots, most of which were created at the beginning of the invasion.[17]
In April 2007, following a diplomatic row with Russia over a Soviet war memorial, Estonia was targeted by a series of cyberattacks on financial, media, and government websites which were taken down by an enormous volume of spam being transmitted by botnets in what is called a distributed denial-of-service attack. Online banking was made inaccessible, government employees were suddenly unable to communicate via e-mail, and media outlets could not distribute news. The attacks reportedly came from Russian IP addresses, online instructions were in Russian, and Estonian officials traced the systems controlling the cyberattacks back to Russia.[18][19] However, some experts held doubts that the attacks were carried out by the Russian government itself.[20] A year after the attack NATO founded the Cooperative Cyber Defence Centre of Excellence in Tallinn as a direct consequence of the attacks.[21]
In response to the 2022 Russian invasion of Ukraine, Estonia has removed a Soviet-era tank monument near Narva.[22] After its removal, Estonia was subject to "the most extensive cyberattack" since the 2007 cyberattacks.[23]
In July 2009, central and eastern European leaders – including former presidents Václav Havel, Valdas Adamkus, Aleksander Kwaśniewski, Vaira Vīķe-Freiberga, Lech Wałęsa – signed an open letter stating:
"Our hopes that relations with Russia would improve and that Moscow would finally fully accept our complete sovereignty and independence after joining NATO and the EU have not been fulfilled. Instead, Russia is back as a revisionist power pursuing a 19th-century agenda with 21st-century tactics and methods. [...] It challenges our claims to our own historical experiences. It asserts a privileged position in determining our security choices. It uses overt and covert means of economic warfare, ranging from energy blockades and politically motivated investments to bribery and media manipulation in order to advance its interests and to challenge the transatlantic orientation of Central and Eastern Europe."[24]
— Valdas Adamkus, Martin Bútora, Emil Constantinescu, Pavol Demeš, Luboš Dobrovský, Mátyás Eörsi, István Gyarmati, Václav Havel, Rastislav Káčer, Sandra Kalniete, Karel Schwarzenberg, Michal Kováč, Ivan Krastev, Aleksander Kwaśniewski, Mart Laar, Kadri Liik, János Martonyi, Janusz Onyszkiewicz, Adam Daniel Rotfeld, Vaira Vīķe-Freiberga, Alexandr Vondra, Lech Wałęsa
Latvian journalist Olga Dragilyeva stated that "Russian-language media controlled by the Russian government and NGOs connected with Russia have been cultivating dissatisfaction among the Russian-speaking part of the population" in Latvia.[25] National security agencies in Lithuania, Estonia and Latvia have linked Moscow to local pro-Russian groups.[26] In June 2015, a Chatham House report stated that Russia used "a wide range of hostile measures against its neighbours", including energy cut-offs, trade embargoes, subversive use of Russian minorities, malicious cyber activity, and co-option of business and political elites.[27]
In 2015, UK media said that the Russian leadership under Putin saw the fracturing of the political unity within the EU and especially the political unity between the EU and the U.S. as among its main strategic goals,[28][29] one of the means in achieving this goal being rendering support to Europe's far-right and hard Eurosceptic political parties.[30][31] In October 2015, Putin said that Washington treated European countries "like vassals who are being punished, rather than allies."[citation needed]
On 9 May 2015, on the occasion of the attack by Albanian terrorists in the city of Kumanovo, the Putin-awarded and Russian intelligence agent,[32] as well as pro-Kremlin journalist Daria Aslamova published a commissioned article in the newspaper "Komsomolskaya Pravda", in which there was a map of "united Macedonia", including the "liberated" Pirin part of the region, which was declared "occupied" by Bulgaria. Bulgaria was accused of "supporting Albanian terrorists", regardless of the Bulgarian support it provided to the defense of Macedonia in 2001 and was declared "banished" from Orthodox civilization.[33] In the days, weeks and months after it was written, the article was shared on numerous Rashist and Putinist sites.
In November 2015, the president of Bulgaria, Rosen Plevneliev, said that Russia had launched a massive hybrid warfare campaign "aimed at destabilising the whole of Europe", giving repeated violations of Bulgarian airspace and cyber-attacks as examples.[34] In January 2016, senior UK government officials were reported to have registered their growing fears that "a new cold war" was now unfolding in Europe, with "Russian meddling" allegedly taking on a breadth, range and depth greater than previously thought: "It really is a new Cold War out there. Right across the EU we are seeing alarming evidence of Russian efforts to unpick the fabric of European unity on a whole range of vital strategic issues."[35] The situation prompted the US Congress to instruct James R. Clapper, the U.S. Director of National Intelligence, to conduct a major review of Russian clandestine funding of European parties over the previous decade.[35]
On numerous occasions Russia was also accused of actively supporting United Kingdom withdrawal from the European Union through channels such as Russia Today and the Russian Federation embassy in London.[36] An analysis of the Russian government's English-language news service, Sputnik, found "a systematic bias in favour of the "Out" campaign which was too consistent to be the result of accident or error."[37]
In February 2016, a film circulating in Hungary, in which recruited students expressed anger at the policy of the US, was identified as a version of a Russian movie with the same script funded by a pro-Putin organisation, Officers' Daughters.[38] Published in March 2016, Swedish security service Säpo's annual report stated that Russia was engaged in "psychological warfare" using "extreme movements, information operations and misinformation campaigns" aimed at policy makers and the general public.[39]
In June 2016, Russian Foreign Minister Sergey Lavrov stated that Russia will never attack any NATO country, saying: "I am convinced that all serious and honest politicians know perfectly well than Russia will never attack a member state of NATO. We have no such plans."[40] He also said: "In our security doctrine it is clearly stated that one of the main threats to our safety is the further expansion of NATO to the east."[40]
In late 2016, media in a number of states accused Russia of preparing grounds for a possible armed take-over at their territories in future, including Finland,[41] Estonia[42] and Montenegro. In the latter an armed coup was actually in progress but prevented by security services on the day of election on 16 October, with over 20 people arrested.[43] A group of 20 citizens of Serbia and Montenegro "planned to break into the Montenegro Parliament on election day, kill Prime Minister Milo Djukanovic and bring a pro-Russian coalition to power" according to Montenegro chief prosecutor Milivoje Katnić, adding that the group was led by two Russian citizens who fled the country before the arrest and "unspecified number of Russian operatives" in Serbia who were deported shortly after.[44][45] A few days after the failed coup Leonid Reshetnikov was dismissed by Putin from his duties as head of Russian Institute for Strategic Studies, which also had its branch in Belgrade where it supported anti-NATO and pro-Russian parties.[46] In 2019, a number of Montenegrin politicians and pro-Russian activists were convicted for the attempted coup as well as two Russian GRU officers Eduard Shishmakov and Vladimir Popov (convicted in absentia).[47]
In 2017, a cache of email was leaked demonstrating funding of far-right and far-left movements in Europe through a Belarusian citizen Alyaksandr Usovsky who funnelled hundreds of thousands of euros from Russian nationalist and oligarch Konstantin Malofeyev and reporting to Russian State Duma Deputy Konstantin Zatulin. Usovsky confirmed the authenticity of the emails.[48]
In 2017, three Alternative for Germany Bundestag deputies confirmed that they together received $29,000 in sponsored private jet visit to Moscow, which caused significant controversy in Germany.[49]
In 2019, a transcript was published from a meeting in Moscow where representatives of Italian nationalist Lega party were offered "tens of millions of dollars" of funding. The delegation to Moscow included Italy's deputy prime minister Matteo Salvini.[50] In 2020 chat transcripts were published by Dutch media of far-right politician Thierry Baudet indicating inspiration on his anti-Ukraine actions and possible financial support from Vladimir Kornilov, a Russian described by Baudet as someone "who works for president Putin".[51]
In 2020, a Spanish court looked at transcripts of calls between a Catalan independence activist Victor Terradellas and a group of Russians who came forward with an offer of up to 10,000 military personnel, pay out of Catalan debt and recognition of Catalan independence by the Russian Federation in exchange for Catalan recognition of Crimea. Frequent arrivals of known GRU operative Denis Sergeev into Spain, coinciding with major Catalan independence events, raised a questions about involvement of GRU Unit 29155 in escalation of the protests.[52]
On 28 April 2021, the European Parliament passed a resolution that condemned Russia's "hostile behaviour towards and outright attacks on EU Member States" explicitly mentioning suspected GRU operation in the Czech Republic in 2014, the poisoning and imprisonment of Alexei Navalny and escalation of the war in Donbas. The resolution called, among other things, for discontinuation of the Nord Stream 2 project.[53]
According to a 2022 report, Russia has spent over $300 million since 2014 on covert subsidies to various political parties and movements globally, including European Union, in exchange of pushing for policies favorable for Russian political goals.[54]
In 2023, an international group of journalists published an analysis of documents prepared in 2021 by Russian Directorate for Cross-Border Cooperation, part of Presidential Administration, detailing plans for interventions securing "strategic interests of the Russian Federation" in Estonia, Latvia, and Lithuania. Russia planned to grow pro-Russian sentiment in these countries, build fear of "NATO militarization", create a large number of pro-Russian NGOs and increase share of pro-Russian politicians in elections. Similar documents published earlier detailed Russia's plans to include Belarus into Russian Federation and return Moldova on pro-Russian path.[55]
In May 2026, Russian threatened Latvia and the Baltic region, over alleged support of Ukrainian drone operations in their air space. The diplomatic incident occoured when Russia's Permanent Representative to the U.N. Vasily Nebenzya warned that membership in NATO would not protect those countries from retaliation.[56] European Commission condemned what it described as “unacceptable” Russian threats directed toward the Baltic states, reaffirming the European Union’s solidarity with Estonia, Latvia and Lithuania.[57]
In 2015, the Paris-based French broadcasting service TV5Monde was attacked by hackers who used malicious software to attack and destroy the network's systems and take all twelve of its channels off the air. The attack was initially claimed by a group calling themselves the "Cyber Caliphate" however a more in-depth investigation by French authorities revealed the attack on the network had links to APT28, a GRU-affiliated hacker group.[58][59] In May 2017, on the eve of the French presidential election, more than 20,000 e-mails belonging to the campaign of Emmanuel Macron were dumped on an anonymous file-sharing website, shortly after the campaign announced they had been hacked. Word of the leak spread rapidly through the Internet, facilitated by bots and spam accounts. An analysis by Flashpoint, an American cybersecurity firm, determined with "moderate confidence" that APT28 was the group behind the hacking and subsequent leak.[60]
In February 2021 the Agence nationale de la sécurité des systèmes d'information said that "several French entities" were breached by Sandworm between late 2017 and 2020 by hacking French software company Centreon to deploy malware. Similar to the 2020 United States federal government data breach. The ANSSI said the breach "mostly affected information technology providers, especially web hosting providers". Russia has denied being behind the cyberattack. Centreon said in a statement that it "has taken note of the information" but disputed that the breach was linked to a vulnerability in their commercial software.[61][62][63]
On 20 July 2008, the website of the Georgian president, Mikheil Saakashvili, was rendered inoperable for twenty-four hours by a series of denial of service attacks. Shortly after, the website of the National Bank of Georgia and the parliament were attacked by hackers who plastered images of Mikheil Saakashvili and former Nazi leader Adolf Hitler. During the war, many Georgian government servers were attacked and brought down, reportedly hindering communication and the dissemination of crucial information. According to technical experts, this is the first recorded instance in history of cyberattacks coinciding with an armed conflict.[64][65]
An independent US-based research institute US Cyber Consequences Unit report stated the attacks had "little or no direct involvement from the Russian government or military". According to the institute's conclusions, some several attacks originated from the PCs of multiple users located in Russia, Ukraine and Latvia. These users were willingly participating in cyberwarfare, being supporters of Russia during the 2008 South Ossetia war, while some other attacks also used botnets.[66][67]
In 2015, a high-ranking security official stated that it was "highly plausible" that a cybertheft of files from the German Parliamentary Committee investigating the NSA spying scandal, later published by WikiLeaks, was conducted by Russian hackers.[68][69] In late 2016, Bruno Kahl, president of the Bundesnachrichtendienst warned of data breaches and misinformation-campaigns steered by Russia.[70] According to Kahl, there are insights that cyberattacks occur with no other purpose than to create political uncertainty.[71][72] Süddeutsche Zeitung reported in February 2017 that a year-long probe by German intelligence "found no concrete proof of [Russian] disinformation campaigns targeting the government".[73] By 2020 however German investigators had collected enough evidence to identify one suspect.[74]
Hans-Georg Maaßen, head of the country's Federal Office for the Protection of the Constitution, noted "growing evidence of attempts to influence the [next] federal election" in September 2017 and "increasingly aggressive cyber espionage" against political entities in Germany.[75] The New York Times reported on 21 September 2017, three days before the German federal election, that there was little to suggest any Russian interference in the election.[76] In 2021 the European Commission has accused Russia of trying to interfere in European democratic processes just days before the parliamentary election on September 26 in Germany.[77]
Beginning in mid-January 2009, Kyrgyzstan's two main ISPs came under a large-scale DDoS attack, shutting down websites and e-mail within the country, effectively taking the nation offline. The attacks came at a time when the country's president, Kurmanbek Bakiyev, was being pressured by both domestic actors and Russia to close a U.S. air base in Kyrgyzstan.[78] The Wall Street Journal reported the attacks had been carried out by a Russian "cyber-militia".[79]
A three-year pro-Russian disinformation campaign on Facebook with an audience of 4.5 million Poles was discovered in early 2019 by OKO.press and Avaaz. The campaign published fake news and supported three Polish politicians and their websites: Adam Andruszkiewicz, former leader of the ultra-nationalist and neo-fascist All-Polish Youth and, as of 2019[update]Janusz Korwin-Mikke; and Leszek Miller, an active member of the Polish United Workers' Party during the communist epoch and a prime minister of Poland during the post-communist epoch. Facebook responded to the analysis by removing some of the web pages.[80]
Between late April and early May 2022, in the midst of the 2022 Russian invasion of Ukraine, multiple Romanian government, military, bank and mass media websites were taken down after a series of DDoS attacks, behind which was a pro-Kremlin hacking group, Killnet. The hacking group described the cyberattacks to be a response to a statement made by then-Senate president, Florin Cîțu that Romania would provide Ukraine with military equipment.[81][82][83]
According to two United States intelligence officials that talked to The Washington Post, and also the findings of cybersecurity analyst Michael Matonis, Russia is likely behind the cyber attacks against the 2018 Winter Olympics in South Korea.[84] The worm responsible for these cyber attacks is known as "Olympic Destroyer".
The worm targeted all Olympic IT infrastructure, and succeeded in taking down WiFi, feeds to jumbotrons, ticketing systems, and other Olympic systems. It was timed to go off at the start of the opening ceremonies. It was unique in that the hackers attempted to use many false signatures to blame other countries such as North Korea and China.[84]
In March 2014, a Russian cyber weapon called Snake or "Ouroboros" was reported to have created havoc on Ukrainian government systems.[85] The Snake tool kit began spreading into Ukrainian computer systems in 2010. It performed Computer Network Exploitation (CNE), as well as highly sophisticated Computer Network Attacks (CNA).[86]
From 2014 to 2016, according to CrowdStrike, the Russian APT Fancy Bear used Android malware to target the Ukrainian Army's Rocket Forces and Artillery. They distributed an infected version of an Android app whose original purpose was to control targeting data for the D-30 Howitzer artillery. The app, used by Ukrainian officers, was loaded with the X-Agent spyware and posted online on military forums. CrowdStrike claims the attack was successful, with more than 80% of Ukrainian D-30 Howitzers destroyed, the highest percentage loss of any artillery pieces in the army (a percentage that had never been previously reported and would mean the loss of nearly the entire arsenal of the biggest artillery piece of the Ukrainian Armed Forces.[87]).[88] According to the Ukrainian army, this number is incorrect and that losses in artillery weapons "were way below those reported" and that these losses "have nothing to do with the stated cause".[89]
The U.S. government concluded after a study that a cyber attack caused a power outage in Ukraine which left more than 200,000 people temporarily without power. The Russian hacking group Sandworm or the Russian government were possibly behind the malware attack on the Ukrainian power grid as well as a mining company and a large railway operator in December 2015.[90][91][92][93][94][95] A similar attack occurred in December 2016.[96]
In February 2021 Ukraine accused Russia of attacking the System of Electronic Interaction of Executive Bodies a web portal used by the Ukrainian government to circulate documents by uploaded documents that contained macroscripts which if downloaded and enabled would lead to the computer to secretly download malware that would allow hackers to take over a computer.[97][98]
In January 2022, a cyberattack on Ukraine took down the website of the Ministry of Foreign Affairs and other government agencies.[99]
In February 2022, before and after Russian troops entered eastern Ukraine amid an environment of escalating tensions between Ukraine and Russia, several major Ukrainian governmental and business websites were taken down by a series of cyberattacks. U.S. officials attributed the attacks to Russian attackers, although the Russian government denied involvement.[100]
Pro-Russian hackers launched a series of cyberattacks over several days to disrupt the May 2014 Ukrainian presidential election, releasing hacked emails, attempting to alter vote tallies, and delaying the final result with distributed denial-of-service (DDOS) attacks.[101][102] Malware that would have displayed a graphic declaring far-right candidate Dmytro Yarosh the electoral winner was removed from Ukraine's Central Election Commission less than an hour before polls closed. Despite this, Channel One Russia "reported that Mr. Yarosh had won and broadcast the fake graphic, citing the election commission's website, even though it had never appeared there."[101][103] According to Peter Ordeshook: "These faked results were geared for a specific audience in order to feed the Russian narrative that has claimed from the start that ultra-nationalists and Nazis were behind the revolution in Ukraine."[101]
In the run up to the 2016 referendum on the United Kingdom exiting the European Union ("Brexit"), Prime Minister David Cameron suggested that Russia "might be happy" with a positive Brexit vote, while the Remain campaign accused the Kremlin of secretly backing a positive Brexit vote.[104] In December 2016, Ben Bradshaw MP claimed in Parliament that Russia had interfered in the Brexit referendum campaign.[105] In February 2017, Bradshaw called on the British intelligence service, Government Communications Headquarters, then under Boris Johnson as Foreign Secretary, to reveal the information it had on Russian interference.[106] In April 2017, the House of Commons Public Administration and Constitutional Affairs Select Committee issued a report stating, in regard to the June 2016 collapse of the government's voter registration website less than two hours prior to the originally scheduled registration deadline (which was then extended), that "the crash had indications of being a DDOS 'attack.'" The report also stated that there was "no direct evidence" supporting "these allegations about foreign interference". A Cabinet Office spokeswoman responded to the report: "We have been very clear about the cause of the website outage in June 2016. It was due to a spike in users just before the registration deadline. There is no evidence to suggest malign intervention."[107][108]
In June 2017, it was reported by The Guardian that "Leave" campaigner Nigel Farage was a "person of interest" in the United States Federal Bureau of Investigation into Russian interference in the United States 2016 Presidential election.[109] In October 2017, Members of Parliament in the Culture, Media and Sport Committee demanded that Facebook, Twitter, Google and other social media corporations, to disclose all adverts and details of payments by Russia in the Brexit campaign.[110]
In December 2023 the UK and its allies have accused Russia of a sustained cyber attacks dating back at least from 2015 until 2023. These attacks have included targeting parliamentarians from various political parties as well as universities, journalists and NGOs. The Star Blizzard group has been named as the group behind the attack is also thought to be subordinate to the Russian government.[111]
In 1999, Moonlight Maze was the US investigation of a 1996-1999 Russian cyberattack against NASA, the Pentagon, the US military, civilian academics and government agencies. The cyberattack was attributed to Russian-state-sponsored hackers.[112][113][114]
The 2008 cyberattack on the United States was connected to Russian language threat actors.[115]
In April 2015, CNN reported that "Russian hackers" had "penetrated sensitive parts of the White House" computers in "recent months". It was said that the FBI, the Secret Service, and other U.S. intelligence agencies categorized the attacks as "among the most sophisticated attacks ever launched against U.S. government systems."[116]
In 2015, CNN reported that Russian hackers, likely working for the Russian government, are suspected in the State Department hack. Federal law enforcement, intelligence and congressional officials briefed on the investigation say the hack of the State Department email system is the "worst ever" cyberattack intrusion against a federal agency.[117]
In February 2016, senior Kremlin advisor and top Russian cyber official Andrey Krutskikh told the Russian national security conference in Moscow that Russia was working on new strategies for the "information arena" that was equivalent to testing a nuclear bomb and would "allow us to talk to the Americans as equals".[118]
In 2016, the release of hacked emails belonging to the Democratic National Committee, John Podesta, and Colin Powell, among others, through DCLeaks and WikiLeaks was said by private sector analysts[119] and US intelligence services[120] to have been of Russian origin.[121][122] Also, in December 2016, Republicans and Democrats on the Senate Committee on Armed Services called for "a special select committee to investigate Russian attempts to influence the presidential election".[123][124]
In 2018, the United States Computer Emergency Response Team released an alert warning that the Russian government was executing "a multi-stage intrusion campaign by Russian government cyber actors who targeted small commercial facilities' networks where they staged malware, conducted spear phishing, and gained remote access into energy sector networks." It further noted that "[a]fter obtaining access, the Russian government cyber actors conducted network reconnaissance, moved laterally, and collected information pertaining to Industrial Control Systems."[125] The hacks targeted at least a dozen U.S. power plants, in addition to water processing, aviation, and government facilities.[126]
In June 2019, the New York Times reported that hackers from the United States Cyber Command planted malware potentially capable of disrupting the Russian electrical grid.[127] According to Wired senior writer Andy Greenberg, "The Kremlin warned that the intrusions could escalate into a cyberwar between the two countries."[127]
Over several months in 2020, a group known as APT29 or Cozy Bear, working for Russia's Foreign Intelligence Service, breached a top cybersecurity firm and multiple U.S. government agencies including the Treasury, Commerce, and Energy departments and the National Nuclear Security Administration.[128] The hacks occurred through a network management system called SolarWinds Orion. The U.S. government had an emergency meeting on 12 December 2020, and the press reported the hack the next day. When Russia's Foreign Intelligence Service performs such hacks, it is typically "for traditional espionage purposes, stealing information that might help the Kremlin understand the plans and motives of politicians and policymakers," according to The Washington Post, and not for the purpose of leaking information to the public.[129]
In February 2021 a report by Dragos stated that Sandworm has been targeting US electric utilities, oil and gas, and other industrial firms since at least 2017 and were successful in breaching these firms a "handful" of times.[130][131]
In May 2021, the Colonial Pipeline ransomware attack was perpetrated by Russian language hacking group DarkSide.[132][133] It was the largest cyberattack on an energy infrastructure target in US history. Colonial Pipeline temporarily halted the operations of the pipeline due to the ransomware attack.[134] The Department of Justice recovered the bitcoin ransom from the hackers.[135]
Reveiled in 2023, British authorities believed that Star Blizzard engaged in a cyberespionage campaign beginning in at least 2015 against U.K. lawmakers over several years. In December 2023, U.S. authorities charged two Russian men, who are believed to be located in Russia and were associated with the "Callisto Group," which is associated with "Cold River" and "Dancing Salome" and are managed by the FSB Information Security Center (18th Center) (CIB or TsIB FSB),[a] in connection with Star Blizzard's previous actions, which included targeting individuals and groups throughout the United States, Europe and in other NATO countries, many of which were supporting Ukraine during the Russo-Ukrainian War and allegedly attempting to provide foreign malign influence campaigns to influence the United Kingdom's 2019 elections in support of Russian government interests. In December 2023, United States authorities charged Andrey Korinets,[b] and the alleged FSB officer Ruslan Peretyatko,[c] who both are members of the "Callisto Group" and were associated with spear-phishing schemes, with conspiracy to commit computer fraud: both individuals were sanctioned by the governments of the United Kingdom and the United States with the United States State Department offering a reward of up to $10 million for information leading to their whereabouts and arrest, as well as the arrest of their accomplices.[136][137][138][139][140][141][142]
In 2024, two members of the Cyber Army Russia Reborn, Yuliya Vladimirovna Pankratova, also known as YUliYA, and Olegovich Degtyarenko were sanctioned, by the U.S. Department of the Treasury for hacking water facilities in both the US and Poland, as well as disrupt operations at a facility in France.[143] Also, the group hacked "the industrial control systems (ICSes) that control water storage tanks in Texas".[143] In early May 2024, Degtyarenko wrote training materials on how to compromise SCADA systems.[143]
In October 2024, the United States Justice Department and Microsoft seized more than a hundred internet domains some of which were associated with the FSB supported hacker Star Blizzard or "Callisto Group," which is also known as "Cold River" and "Dancing Salome" and are managed by the FSB Information Security Center (18th Center) (CIB or TsIB FSB) (Russian: Центр информационной безопасности ФСБ (18-й центр) (ЦИБ ФСБ)), and which were used as "criminal proxies" and used spear-phishing schemes to target Russians living in the United States, nongovernmental organizations (NGOs), think tanks, and journalists according to Microsoft and United States State Department, Department of Energy, and Department of Defense officials, United States defense contractors, and former employees of the United States intelligence community according to the FBI. In some cases, the hackers were successful in obtaining information relating to nuclear energy-related research, United States foreign affairs and United States defense. According to Microsoft's Digital Crimes Unit from January 2023 to August 2024, Star Blizzard targeted more than 30 different groups and at least 82 Microsoft customers which is "a rate of approximately one attack per week." Both the NGO-Information Sharing and Analysis Center, which is a nonprofit tech organization, and Microsoft, which had been tracking Star Blizzard since 2017, provided support during the investigations of Star Blizzard.[139][144][145][146][147][148][149][150][151][d]
After the news website Runrun.es published a report on extrajudicial killings by the Bolivarian National Police, on 25 May 2019, the Venezuelan chapter of the Instituto de Prensa y Sociedad (IPYS), pointed out that the website was out of service due to an uncached request attack, denouncing that it originated from Russia.[152]
On 30 December 2016, Burlington Electric Department, a Vermont utility company, announced that code associated with the Russian hacking operation dubbed Grizzly Steppe had been found in their computers. Officials from the Department of Homeland Security, FBI and the Office of the Director of National Intelligence warned executives of the financial, utility and transportation industries about the malware code.[153] The first report by The Washington Post left the impression that the grid had been penetrated, but the hacked computer was not attached to the grid. A later version attached this disclaimer to the top of its report correcting that impression: "Editor's Note: An earlier version of this story incorrectly said that Russian hackers had penetrated the U.S. electric grid. Authorities say there is no indication of that so far. The computer at Burlington Electric that was hacked was not attached to the grid."[154]
- ↑ The FSB Information Security Center (18th Center) (CIB or TsIB FSB) (Russian: Центр информационной безопасности ФСБ (18-й центр) (ЦИБ ФСБ)) is known in London as "Star Blizzard" and in Washington as the "Callisto Group" and is also associated with SEABORGIUM or COLDRIVER or Dancing Salome.[136]
- ↑ Andrey Stanislavovich Korinets (Russian: Андрей Станиславович Коринец; born 1988 or 1989), also known as Alexey Doguzhev or Alexei Doguzhiev (Russian: Алексей Догужев), is an IT worker and bodybuilder who resides in Syktyvkar and allegedly is a member of "Cold River" which is managed by the FSB Information Security Center (18th Center) (CIB or TsIB FSB) (Russian: Центр информационной безопасности ФСБ (18-й центр) (ЦИБ ФСБ)).[137]
- ↑ Ruslan Aleksandrovich Peretyatko (Russian: Руслан Александрович Перетятько) allegedly is an FSB officer.[138]
- ↑ During the Russo-Ukrainian War, many cyber attacks on Ukraine allegedly were conducted by GRU Unit 29155.[150]
- ↑ Kantchev, Georgi; Strobel, Warren P. (2 January 2021). "How Russia's 'Info Warrior' Hackers Let Kremlin Play Geopolitics on the Cheap". Wall Street Journal. Archived from the original on 8 January 2021. Retrieved 12 January 2021.
- ↑ State control over the internet Archived 22 August 2009 at the Wayback Machine, a talk show by Yevgenia Albats at the Echo of Moscow, 22 January 2006; interview with Andrei Soldatov and others
- ↑ "Military Power Publications". www.dia.mil. Archived from the original on 26 September 2017. Retrieved 25 September 2017.
- ↑ Singer, P. W.; Friedman, Allan (March 2014). Cybersecurity and cyberwar: what everyone needs to know. Oxford University Press. ISBN 978-0-19-991809-6. OCLC 802324804.
- ↑ Green, James A., ed. (7 November 2016). Cyber warfare: a multidisciplinary analysis. London: Routledge. ISBN 978-0-415-78707-9. OCLC 980939904.
- ↑ "Cyberwar – does it exist?". NATO. 13 June 2019. Retrieved 10 May 2019.
- ↑ Smith, Troy E. (2013). "Cyber Warfare: A Misrepresentation of the True Cyber Threat". American Intelligence Journal. 31 (1): 82–85. ISSN 0883-072X. JSTOR 26202046.
- ↑ Lucas, George (2017). Ethics and Cyber Warfare: The Quest for Responsible Security in the Age of Digital Warfare. Oxford University Press. p. 6. ISBN 978-0-19-027652-2.
- ↑ Newman, Lily Hay (6 May 2019). "What Israel's Strike on Hamas Hackers Means for Cyberwar". Wired. ISSN 1059-1028. Retrieved 10 May 2019.
- ↑ Liptak, Andrew (5 May 2019). "Israel launched an airstrike in response to a Hamas cyberattack". The Verge. Retrieved 10 May 2019.
- 1 2 Pete Earley, "Comrade J: The Untold Secrets of Russia's Master Spy in America After the End of the Cold War", Penguin Books, 2007, ISBN 978-0-399-15439-3, pages 194-195
- ↑ Is there only one truth? Archived 14 April 2009 at the Wayback Machine by Kivy Bird, Computerra, 26 November 2008
- ↑ "www.axisglobe.com". Archived from the original on 17 August 2016. Retrieved 1 August 2016.
- ↑ Cyberspace and the changing nature of warfare Archived 3 December 2008 at the Wayback Machine. Strategists must be aware that part of every political and military conflict will take place on the internet, says Kenneth Geers.
- ↑ Andrew Meier, Black Earth. W. W. Norton & Company, 2003, ISBN 0-393-05178-1, pages 15-16.
- ↑ "Social Media as a Propaganda Tool in the Russia-Ukraine Conflict". The Cairo Review of Global Affairs. 12 March 2023. Retrieved 1 February 2024.
- ↑ Geissler, Dominique; Bär, Dominik; Pröllochs, Nicolas; Feuerriegel, Stefan (December 2023). "Russian propaganda on social media during the 2022 invasion of Ukraine". EPJ Data Science. 12 (1): 1–20. arXiv:2211.04154. doi:10.1140/epjds/s13688-023-00414-5. ISSN 2193-1127.
- ↑ McGuinness, Damien (27 April 2017). "How a cyber attack transformed Estonia". BBC News. Archived from the original on 21 February 2018. Retrieved 24 February 2018.
- ↑ "10 Years After the Landmark Attack on Estonia, Is the World Better Prepared for Cyber Threats?". Foreign Policy. 27 April 2017. Archived from the original on 24 February 2018. Retrieved 24 February 2018.
- ↑ "Experts doubt Russian government launched DDoS attacks". SearchSecurity. 23 February 2018. Archived from the original on 24 February 2018. Retrieved 24 February 2018.
- ↑ "NATO launches cyber defence centre in Estonia". Military Space News, Nuclear Weapons, Missile Defense. 14 May 2008. Archived from the original on 11 August 2014. Retrieved 24 February 2018.
- ↑ "Estonia Removes Soviet-era Monument, Citing Public Order". Associated Press. 16 August 2022. Retrieved 18 August 2022.
- ↑ Pascale Davies (18 August 2022). "Estonia hit by 'most extensive' cyberattack since 2007 amid tensions with Russia over Ukraine war". Retrieved 18 August 2022.
- ↑ Valdas Adamkus; Martin Bútora; Emil Constantinescu; Pavol Demeš; Luboš Dobrovský; Mátyás Eörsi; István Gyarmati; Václav Havel; Rastislav Káčer; Sandra Kalniete; Karel Schwarzenberg; Michal Kováč; Ivan Krastev; Aleksander Kwaśniewski; Mart Laar; Kadri Liik; János Martonyi; Janusz Onyszkiewicz; Adam Daniel Rotfeld; Vaira Vīķe-Freiberga; Alexandr Vondra; Lech Wałęsa (15 July 2009). "An Open Letter to the Obama Administration from Central and Eastern Europe". Gazeta Wyborcza.
  - "An Open Letter". Radio Free Europe/Radio Liberty. Radio Free Europe. 16 July 2009.
- ↑ Martyn-Hemphill, Richard; Morisseau, Etienne (4 April 2015). "Baltics in front line of Information War". The Baltic Times.
- ↑ Beesley, Arthur (16 October 2016). "EU leaders to hold talks on Russian political meddling". Financial Times.
- ↑ Giles, Keir; Hanson, Philip; Lyne, Roderic; Nixey, James; Sherr, James; Wood, Andrew (June 2015). "The Russian challenge". Chatham House.
- ↑ "Putin's war on the West". Economist. 14 February 2015. Retrieved 30 April 2015.
- ↑ "From cold war to hot war". Economist. 14 February 2015. Retrieved 30 April 2015.
- ↑ "In the Kremlin's pocket". Economist. 14 February 2015. Retrieved 30 April 2015.
- ↑ "Far-Right Europe Has a Crush on Moscow". Moscow Times. 25 November 2014. Retrieved 6 January 2015.
- ↑ ". Свободна Европа. 9 August 2022.
- ↑ Асламова, Дарья. "Война за трубу: почему русские должны помочь Македонии". Альтернатива.
- ↑ Holmes, Lawrie (14 November 2015). "Russia plans a 'hybrid warfare campaign aimed at destabilising Europe'. The Independent.
- 1 2 "Russia accused of clandestine funding of European parties as US conducts major review of Vladimir Putin's strategy / Exclusive: UK warns of "new Cold War" as Kremlin seeks to divide and rule in Europe". The Daily Telegraph. 16 January 2016. Retrieved 17 January 2016.
- ↑ "Those who call for Brexit are handing European power to the Kremlin". The Independent. 9 March 2016.
- ↑ Nimmo, Ben (13 February 2016). "Lobbying for Brexit: How the Kremlin's media are distorting the UK's debate". The Institute for Statecraft.
  - Nimmo, Ben (16 June 2016). "Still backing Brexit". The Institute for Statecraft.
- ↑ "Hungarian students caught up in global Russian propaganda campaign against America". Atlatszo (English). 23 February 2016.
- ↑ "Russian spies pose as diplomats in Sweden". thelocal.se. 17 March 2016.
- 1 2 "Russia Will Never Attack Any NATO Member: Lavrov". Newsweek. 7 June 2016.
- ↑ "Russia purchases real estate in Finland for its invasion troops – media". uatoday.tv. Retrieved 2 November 2016.
- ↑ "Russian embassy displeased with ETV newscast". Sport. Retrieved 2 November 2016.
- ↑ "Montenegrin PM resigns, suggests Russia behind alleged coup plot – RFE/RL". uatoday.tv. Retrieved 2 November 2016.
- ↑ "Montenegro: Russians behind coup attempt, plot to kill PM". AP News. Retrieved 7 November 2016.
- ↑ Belgrade, Julian Borger Andrew MacDowall in; Moscow, Shaun Walker in (11 November 2016). "Serbia deports Russians suspected of plotting Montenegro coup". The Guardian. ISSN 0261-3077. Retrieved 28 November 2016.
- ↑ Belgrade, Julian Borger Andrew MacDowall in; Moscow, Shaun Walker in (11 November 2016). "Serbia deports Russians suspected of plotting Montenegro coup". The Guardian. ISSN 0261-3077. Retrieved 20 November 2016.
- ↑ Central, Shaun Walker; correspondent, eastern Europe (9 May 2019). "Alleged Russian spies sentenced to jail over Montenegro 'coup plot'. The Guardian. ISSN 0261-3077. Retrieved 11 May 2019.{{cite news}} :|last2= has generic name (help)
- ↑ Shimov, Yaroslav; Dzikawicki, Aleksy (12 March 2017). "E-Mail Hack Gives Glimpse Into Russia's Influence Drive In Eastern Europe". Radio Free Europe/Radio Liberty. Retrieved 12 March 2017.
- ↑ (www.dw.com), Deutsche Welle. "Report: AfD members' flight sponsored with Russian money | DW | 22 May 2018". DW.COM. Retrieved 22 May 2018.
- ↑ "Revealed: The Explosive Secret Recording That Shows How Russia Tried To Funnel Millions To The "European Trump". BuzzFeed News. Retrieved 24 July 2019.
- ↑ "WhatsApp leak exposes Russia link to Dutch far right". EUobserver. 17 April 2020. Retrieved 18 April 2020.
- ↑ Pérez, Óscar López-Fonseca, Fernando J. (21 November 2019). "Spain's High Court opens investigation into Russian spying unit in Catalonia". EL PAÍS. Retrieved 29 October 2020.{{cite web}} :  CS1 maint: multiple names: authors list (link)
- ↑ "JOINT MOTION FOR A RESOLUTION on Russia, the case of Alexei Navalny, the military build-up on Ukraine's border and Russian attacks in the Czech Republic". www.europarl.europa.eu. Retrieved 30 April 2021.
- ↑ "Russia spent millions on secret global political campaign, U.S. intelligence finds". Washington Post. ISSN 0190-8286. Retrieved 14 September 2022.
- ↑ VSquare (25 April 2023). "Secret Kremlin Documents: How Russia Plans to Disrupt the Baltics". VSQUARE.ORG. Retrieved 26 April 2023.
- ↑ Shalal, Andrea. "Russia says Latvia risks retaliation over Ukraine drone plans; Latvia says claims are 'pure fiction'. reuters.com.
- ↑ "EU: "Russian threats are unacceptable; we stand in solidarity with the Baltic states". 20 May 2026. Retrieved 21 May 2026.
- ↑ Corera, Gordon (10 October 2016). "How France's TV5 was almost destroyed". BBC News. Archived from the original on 15 March 2018. Retrieved 10 March 2018.
- ↑ ". BBC News. 9 June 2015. Archived from the original on 30 April 2018. Retrieved 10 March 2018.
- ↑ "Researchers link Macron hack to APT28 with 'moderate confidence'. Cyberscoop. 11 May 2017. Archived from the original on 16 January 2018. Retrieved 10 March 2018.
- ↑ Cimpanu, Catalin. "France: Russian state hackers targeted Centreon servers in years-long campaign". ZDNet. Archived from the original on 17 February 2021. Retrieved 18 February 2021.
- ↑ "France uncovers cybersecurity breaches linked to Russian hackers". France 24. 16 February 2021. Archived from the original on 17 February 2021. Retrieved 18 February 2021.
- ↑ "France identifies Russia-linked hackers in large cyberattack". POLITICO. 15 February 2021. Archived from the original on 17 February 2021. Retrieved 18 February 2021.
- ↑ Hart, Kim (14 August 2008). "Longtime Battle Lines Are Recast In Russia and Georgia's Cyberwar". The Washington Post. Archived from the original on 13 March 2018. Retrieved 12 March 2018.
- ↑ Markoff, John (13 August 2008). "Before the Gunfire, Cyberattacks". The New York Times. Archived from the original on 30 March 2019. Retrieved 12 March 2018.
- ↑ Siobhan Gorman (18 August 2009). "Hackers Stole IDs for Attacks". WSJ. Archived from the original on 10 August 2017. Retrieved 3 August 2017.
- ↑ "Georgian cyber attacks launched by Russian crime gangs". The Register. Archived from the original on 10 August 2017. Retrieved 10 August 2017.
- ↑ "Russia behind hack on German parliament, paper reports". Deutsche Welle. Archived from the original on 2 February 2017. Retrieved 30 January 2017.
- ↑ Wehner, Markus; Lohse, Eckart (11 December 2016). "Wikileaks: Sicherheitskreise: Russland hackte geheime Bundestagsakten". Faz.net. Frankfurter Allgemeine Zeitung. Archived from the original on 5 February 2017. Retrieved 30 January 2017.
- ↑ "Vor Bundestagswahl: BND warnt vor russischen Hackerangriffen". Der Spiegel. SPIEGEL ONLINE. 29 November 2016. Archived from the original on 1 February 2017. Retrieved 30 January 2017.
- ↑ "Was bedeuten die neuen Cyberangriffe für die Bundestagswahl?" (in German). 1 November 2016. Archived from the original on 2 February 2017. Retrieved 30 January 2017.
- ↑ "BND-Präsident warnt vor

[TEXT TRUNCATED]

================================================================================

################################################################################
SOURCE 8
################################################################################

TITLE: Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform
URL: https://cybersecuritynews.com/russian-hacker-jailbreaks-claude
DOMAIN: cybersecuritynews.com
AUTHOR: Abinaya
DATE: 2026-07-22
SEARCH QUERY: Russian hackers AI capabilities
TEXT LENGTH: 3888

SEARCH SNIPPET:
Jul 22, 2026 · Russian Hacker Jailbreaks Claude These techniques are forms of “jailbreaking,” where an attacker attempts to override a model’s behavioral safeguards through crafted inputs rather than exploiting the underlying infrastructure.

--------------------------------------------------------------------------------
PAGE TEXT:

A Russian-speaking threat actor known as “Trim” has reportedly transformed jailbroken frontier AI models into an automated penetration testing platform called AI Pentest Checker.
This activity highlights how criminals can misuse legitimate AI services and common security tools to accelerate reconnaissance, validate vulnerabilities, and create reports.
According to Cato reports, Trim first appeared on a Russian-language cybercrime forum on March 13, 2026, where he shared methods claimed to bypass Claude Opus safety controls.
The actor allegedly described techniques for prompt-based manipulation designed to make a model treat offensive requests as authorized security research instead of malicious activity.
The reported methods included creating a benign context before making a harmful request, reframing instructions to focus only on code structure, and retrying softened versions of previously refused prompts.
Russian Hacker Jailbreaks Claude
These techniques are forms of “jailbreaking,” where an attacker attempts to override a model’s behavioral safeguards through crafted inputs rather than exploiting the underlying infrastructure.
Threat researchers have already observed the criminal misuse of legitimate large language models (LLMs), including jailbreaking. Trim also reportedly recommended alternative AI services and locally hosted models when commercial systems refused a request.
This strategy lowers dependency on any single AI provider, giving threat actors a fallback option for generating code, analyzing targets, or creating exploitation content.
Research groups warn that increasingly capable frontier models can support offensive tasks, such as vulnerability analysis and exploit-related activities, even when providers implement safety controls.
Cato Networks reported that Trim allegedly promoted AI Pentest Checker on June 21, combining AI capabilities with offensive security tools for automated testing.
The tool reportedly integrates scanners and reconnaissance tools such as Nuclei, ffuf, katana, subfinder, and Gitleaks to automate target discovery, endpoint enumeration, secret detection, and vulnerability checks.
The concern is not that these utilities are inherently malicious legitimate penetration testers and defenders widely use them.
However, when combined with a jailbroken AI assistant, these tools can reduce the time and expertise needed to coordinate an intrusion workflow, interpret scan results, prioritize findings, and produce polished reports.
The platform reportedly used Claude Opus in its critical vulnerability escalation process and another model for generating exploitation reports.
Claims that a modified system prompt from a “Fable 5” configuration was used should be treated cautiously unless independently verified.
However, exposed or leaked system prompts can provide attackers insight into a model’s instructions, helping them test prompt-injection or jailbreak strategies more effectively.
This case reflects a larger shift in the threat landscape. AI is evolving from a writing assistant for cybercriminals to an operational layer that can organize multi-step attack workflows.
Anthropic has previously reported disrupting cybercriminal activities in which AI was used for tasks ranging from target research to intrusion support and extortion-related work.
Organizations should respond by reducing their exposed attack surface, continuously scanning internet-facing assets, enforcing multifactor authentication (MFA), rotating compromised credentials, and monitoring for abnormal reconnaissance activity.
Security teams should also consider AI-generated phishing, automated vulnerability research, and faster exploit development as realistic risks rather than future scenarios.
The Privilege Paths Attackers See That You Don’t: BeyondTrust Pathfinder Platform Does It for You -> Get Free Identity Security Assessment

================================================================================

################################################################################
SOURCE 9
################################################################################

TITLE: AI-Assisted Hacking Helps Russian-Speaking Cybercriminals
URL: https://stratnewsglobal.com/technology/ai-assisted-hacking-russian-speaking-hackers
DOMAIN: stratnewsglobal.com
AUTHOR: Aditya Lenka
DATE: 2026-08-27
SEARCH QUERY: Russian hackers AI capabilities
TEXT LENGTH: 4541

SEARCH SNIPPET:
6 days ago - Russian-Speaking Hackers Used AI Coding Assistant In Corporate Breaches Russian-speaking hackers used SpaceX’s AI coding assistant Cursor to help break into a Belgian chemical company and at least six other firms earlier this year, according ...

--------------------------------------------------------------------------------
PAGE TEXT:

Russian-Speaking Hackers Used AI Coding Assistant In Corporate Breaches
Russian-speaking hackers used SpaceX’s AI coding assistant Cursor to help break into a Belgian chemical company and at least six other firms earlier this year, according to data reviewed by Reuters and a report from startup Gambit Security.
The campaign is the latest example of rogue actors using commercial artificial intelligence tools to conduct cyber intrusions. It also highlights the growing challenge for AI providers as malicious users look for ways around safety guardrails.
“This is going to be a cat-and-mouse game,” said Curtis Simpson, Gambit’s chief strategy officer.
Cursor and its parent company, SpaceX, did not respond to requests for comment.
Exposed Server Reveals Hacking Campaign
Gambit said it discovered the campaign after finding a server that a new ransomware group called Aur0ra had inadvertently exposed online.
The exposed server allowed the Tel Aviv-based company to review 28 chat sessions involving one or more Aur0ra hackers and a Cursor AI agent. These agents can perform tasks with varying degrees of autonomy.
According to Gambit, the hackers persuaded the AI agent to conduct hundreds of malicious operations, including credential theft and attempts to take over high-value accounts.
The hackers allegedly misled the agent by claiming the activity was part of a simulation.
At one point, Gambit quoted the hackers as instructing the agent to find an administrator account and working passwords.
Gambit did not name the victims. However, Reuters identified six after independently reviewing portions of the chat data, which remained online as of last month.
Multiple Companies Targeted
The chat logs covered April 8 to May 21. They showed that Aur0ra targeted the Belgian company Christeyns, a Ghent-based manufacturer of hygiene and cleaning products.
The other identified victims included German garage door manufacturer Teckentrup and the Scotland-based Helideck Certification Agency, which assesses helicopter landing sites.
The remaining victims were an Argentine pharmaceutical distributor, an Italian manufacturer and Bayou Title, which describes itself as Louisiana’s largest title insurance company.
None of the six companies responded to Reuters’ requests for comment.
At least one victim, Bayou Title, appeared on Aur0ra’s data leak site. Such listings typically indicate that hackers attempted to obtain a ransom but failed to secure payment.
Aur0ra, which began claiming victims earlier this year, did not respond to messages.
Hackers Circumvented AI Safeguards
The chat logs reviewed by Reuters show hackers issuing short commands while Cursor’s AI agent responded with technical guidance in an upbeat, emoji-heavy chatbot style.
After the agent helped breach the Argentine company, it declared that a VPN had connected successfully. Elsewhere, it suggested attempting to crack password hashes.
After identifying a vulnerable host on Teckentrup’s network, the agent recommended using a known malicious software tool to exploit it. It assessed the chance of success as very high.
Reuters could not independently establish how extensively the Cursor agent facilitated the intrusions. It also could not determine whether every breach led to data theft or an extortion attempt.
Gambit said the agent was powered by Anthropic’s Claude Sonnet 4.5. Anthropic did not respond to a request for comment.
AI Agents Add Speed To Cyberattacks
Eyal Sela, Gambit’s director of threat intelligence, said Cursor gave the hackers a clear advantage. He estimated that the AI agent probably made their work 30% to 50% faster by reducing tasks they would otherwise have performed manually.
The agent refused some requests that it considered harmful or illegal, according to Sela. However, the hackers could usually bypass those refusals by restarting the conversation and repeating that the activity was part of a test.
Gambit said the agent’s chain of thought showed the hackers’ simulation claim overriding its safeguards.
“This is a test environment, so it is legal,” the agent said to itself, according to one of the logs.
The hacking campaign comes as Cursor is being incorporated into SpaceX, Elon Musk’s rockets-and-AI company. That deal closed earlier this month.
Meanwhile, concerns are growing over digital risks linked to AI models, particularly those that power autonomous AI agents.
Simpson said AI-assisted hacking was becoming the new normal.
“We’ll see more and more of this all the time,” he said.
With inputs from Reuters

================================================================================

################################################################################
SOURCE 10
################################################################################

TITLE: Russian Hackers Used SpaceX's AI Coding Assistant To Conduct Attacks: Report
URL: https://www.ibtimes.com/russian-hackers-used-spacexs-ai-coding-assistant-conduct-attacks-report-3806860
DOMAIN: ibtimes.com
AUTHOR: Brian Slupski
DATE: 2026-08-27
SEARCH QUERY: Russian hackers AI capabilities
TEXT LENGTH: 2843

SEARCH SNIPPET:
5 days ago - An AI coding assistant tool was co-opted by hackers, according to a new report. A Russian hacking group active since April has been using SpaceX's AI coding assistant, Cursor, to conduct cyberattacks.

--------------------------------------------------------------------------------
PAGE TEXT:

A Russian hacking group active since April has been using SpaceX's AI coding assistant, Cursor, to conduct cyberattacks.
Reuters reported that the group used Cursor to break into a Belgian chemical company. The wire service reported that the group had also launched successful attacks against at least six other firms.
Gambit Security identified the hacking group as Aurora in a report and detailed its activities.
"In a recent investigation, we identified exposed infrastructure associated with the Aurora ransomware group, providing visibility into the group's operations across multiple victim environments," the report states. "Aurora ransomware activity has been reported as active since approximately April 2026, with the group operating a data leak site and targeting organizations across multiple countries."
The report details an Aurora operator using Cursor Agent, running Claude Sonnet, to assist with exploitation across ten target organizations between April 8 and May 21. Gambit said it then identified a second cluster of activity that it believed also was associated with Aurora.
"In some victim networks, the operator used Cursor Agent with claude-4.5-sonnet-thinking. In these cases, the agent was given credentials or an existing route into the victim organization. Then it was tasked with various exploitation activities," the report states. "In some cases, the attacker only asked the Agent to achieve an objective, such as "tell me what rights the user has," while in others, they told the Agent which exploitation tool to use or instructed it to follow a previously generated attack plan."
Reuters reported that Gambit it discovered the hacking efforts after finding a server Aurora left exposed to the internet. The wire service reported that the Tel Aviv-based company then reviewed 28 chat sessions that occurred between Aurora hackers and Cursor AI agents.
The Gambit report states that most of the commands failed. However, the hackers then refined tasks and changed commands and scripts. "Some eventually succeeded in achieving the objective, while others failed and returned only a report of the attempts to the attacker," the report stated.
These are some of the tasks that were given to the agent, based on the Gambit report:
- Installing a VPN client or proxychains, then configuring it and connecting to a victim with supplied credentials or an existing SOCKS tunnel.
- Scanning the internal subnets for hosts with Nmap or NetExec.
- Enumerating the domain to report which privileges a supplied user holds, using NetExec's BloodHound collector.
- Attempting NTLM relay attacks by coercing authentication with PetitPotam, Coerce Plus, and PrinterBug, and using Impacket ntlmrelayx to relay the resulting authentication.
- Running certificate attacks with Certipy.
© Copyright IBTimes 2026. All rights reserved.

================================================================================

################################################################################
SOURCE 11
################################################################################

TITLE: Russian hacker uses multiple AI tools to break hundreds of firewalls
URL: https://www.techradar.com/pro/security/russian-hacker-uses-multiple-ai-tools-to-break-hundreds-of-firewalls
DOMAIN: techradar.com
AUTHOR: Sead Fadilpašić
DATE: 2026-02-23
SEARCH QUERY: Russian hackers AI capabilities
TEXT LENGTH: 3535

SEARCH SNIPPET:
February 23, 2026 - A Russian hacker was recently seen ... threat actor was able to pull off the attacks with the help of Generative Artificial Intelligence (GenAI)....

--------------------------------------------------------------------------------
PAGE TEXT:

- Russian hacker brute-forced FortiGate firewalls using weak credentials
- AI-generated scripts enabled data parsing, reconnaissance, and lateral movement
- The campaign targeted Veeam servers; attacker abandoned hardened systems
A Russian hacker was recently seen brute-forcing their way into hundreds of firewalls - but what makes this campaign really stand out is the fact that the seemingly low-skilled threat actor was able to pull off the attacks with the help of Generative Artificial Intelligence (GenAI).
In a new analysis, Amazon Integrated Security CISO CJ Moses explained how researchers observed a threat actor “systematically” scanning for exposed FortiGate management interfaces across ports 443, 8443, 10443, and 4443.
After finding a potential target, they brute-forced their way in, trying countless combinations of commonly used and weak credentials, until one worked.
A little rough around the edges
Once inside, the hacker extracted full device configuration files (SSL-VPN user credentials with recoverable passwords, administrative credentials, firewall policies and internal network architecture, and more) and parsed, decrypted, and organized them using AI-generated Python scripts.
They then used the recovered VPN credentials to connect to internal networks, deploying custom AI-generated reconnaissance tools (written in Go and Python) and moving to Active Directory.
"Analysis of the source code reveals clear indicators of AI-assisted development: redundant comments that merely restate function names, simplistic architecture with disproportionate investment in formatting over functionality, naive JSON parsing via string matching rather than proper deserialization, and compatibility shims for language built-ins with empty documentation stubs,” Moses said.
"While functional for the threat actor's specific use case, the tooling lacks robustness and fails under edge cases—characteristics typical of AI-generated code used without significant refinement."
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The attacker also specifically targeted Veeam Backup & Replication servers, deploying credential extraction tools and attempting exploitation of known Veeam vulnerabilities.
All of this was done in a span of just a few weeks, between January 11 and February 18, 2026, leading the researchers to believe the attacker is rather unskilled - as throughout their operations, they tried exploiting various CVEs but largely failed when targets were patched or hardened. They frequently abandoned well-protected environments and moved on to easier targets.
Via BleepingComputer
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!
And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.

================================================================================

################################################################################
SOURCE 12
################################################################################

TITLE: Russian hackers turn Cursor AI coding tool into cyber weapon, target 7 companies
URL: https://www.thenews.com.pk/latest/1413845-russian-hackers-turn-cursor-ai-coding-tool-into-cyber-weapon-target-7-companies
DOMAIN: thenews.com.pk
AUTHOR: Aqsa Qaddus Tahir
DATE: 2026-08-27
SEARCH QUERY: Russian hackers AI capabilities
TEXT LENGTH: 2385

SEARCH SNIPPET:
6 days ago - Russian cybercriminals have exploited SpaceX’s AI coding assistant Cursor to target seven companies including a Belgian chemical company earlier this year. According to a report issued by the...


################################################################################
SOURCE 13
################################################################################

TITLE: Russian hackers turn to AI as old tactics fail, Ukrainian CERT says
URL: https://therecord.media/russian-hackers-turn-to-ai-ukraine-cert
DOMAIN: therecord.media
AUTHOR: Daryna Antoniuk
DATE: 2025-10-08
SEARCH QUERY: Russian hackers AI capabilities
TEXT LENGTH: 3438

SEARCH SNIPPET:
October 8, 2025 - Russian hackers are now using AI not only to write phishing messages but also to generate malicious code itself.

--------------------------------------------------------------------------------
PAGE TEXT:

Russian hackers turn to AI as old tactics fail, Ukrainian CERT says
Russian hackers are increasingly using artificial intelligence and adopting new tactics in cyberattacks against Ukraine as Kyiv’s defenses grow stronger, Ukrainian government researchers said in a new report.
Since Russia’s invasion in 2022, cyberattacks on Ukraine have continued to rise, surpassing 3,000 cases in the first half of this year — about 20 percent more than the same period last year. At the same time, the number of high-impact incidents has declined as Ukraine’s defenses improve.
That progress has forced Russian hackers to abandon outdated tactics, automate more of their operations and increasingly experiment with AI-generated malware, according to Ukraine’s computer emergency response team, CERT-UA.
In a report released Wednesday, the agency warned that attackers are now using AI not only to write phishing messages but also to generate malicious code itself. Researchers believe AI tools were used to create PowerShell scripts in malware known as Wrecksteel, attributed to the cyberespionage group UAC-0219.
“The use of artificial intelligence in cyberattacks has reached a new level,” CERT-UA said. “We have investigated several viruses showing clear signs of being generated with AI, and attackers will certainly not stop there.”
Russian hackers are also adapting to faster infrastructure takedowns, researchers said. Improvements in Ukraine’s detection systems and closer cooperation with international cloud providers have pushed attackers toward shorter, more transient campaigns.
Instead of maintaining persistence within networks, hackers increasingly deploy data-stealing tools that grab what they can and disappear — a shift CERT-UA described as the “Steal & Go” model.
As phishing becomes less effective against better-trained Ukrainian users, Russian hackers are increasingly turning to so-called zero-click vulnerabilities — software flaws that allow infections without any user interaction.
CERT-UA noted a surge in the use of such vulnerabilities in early 2025, including renewed exploitation of a known flaw in the open-source email platform Roundcube (CVE-2023-43770). The vulnerability allows attackers to execute malicious code when an email is merely viewed in the inbox — no clicks required.
Moscow also continues to synchronize cyber operations with missile and drone strikes to amplify their disruptive effect, the report said. CERT-UA cited the Sandworm hacking unit, linked to Russia’s military intelligence, as one of the groups coordinating such hybrid attacks.
CERT-UA said that Russia’s evolving tactics and techniques, including new methods of spreading malware, have been partly successful. Still, Ukraine’s defenders said they have managed to keep up, detecting and neutralizing roughly as many infections as they find.
“After more than three years of full-scale war, the enemy has still not achieved the goals of its so-called special military operation,” researchers said. “Every day it increases the number of its attacks — both drones and missiles, and cyberattacks.”
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

================================================================================

################################################################################
SOURCE 14
################################################################################

TITLE: Russian-Speaking Cybercriminals Used SpaceX's Cursor AI Tool to Hack Seven Firms
URL: https://www.insurancejournal.com/news/international/2026/08/27/883097.htm
DOMAIN: insurancejournal.com
AUTHOR: Raphael Satter
DATE: 2026-08-27
SEARCH QUERY: Russian hackers use of AI agents on the Internet
TEXT LENGTH: 5227

SEARCH SNIPPET:
6 days ago - Russian-speaking hackers used SpaceX's coding assistant, Cursor, to help break in to a Belgian chemical company and at least six other firms earlier this

--------------------------------------------------------------------------------
PAGE TEXT:

Russian-speaking hackers used SpaceX’s coding assistant, Cursor, to help break in to a Belgian chemical company and at least six other firms earlier this year, according to data reviewed by Reuters and reports issued on Thursday by cybersecurity companies Gambit Security and CloudSek.
The cybercriminals’ AI-boosted hacking spree is the latest example of how rogue actors are using commercial AI tools to carry out intrusions. Gambit’s chief strategy officer, Curtis Simpson, said it also showed how AI providers were locked in to a never-ending arms race with malicious users trying to circumvent their guardrails.
“This is going to be a cat-and-mouse game,” Simpson said.
Cursor and its parent company, SpaceX, did not return messages seeking comment.
Exposed Server Reveals Hacking Methods
Gambit said it discovered the hacking campaign after finding a server that a new ransomware gang called Aur0ra had inadvertently exposed to the internet. That allowed the Tel Aviv-based company to review 28 chat sessions between one or more of Aur0ra’s hackers and one of Cursor’s AI agents, which are programs that can operate with various degrees of autonomy.
In its report, Gambit said Aur0ra persuaded the AI agent to carry out hundreds of malicious operations — such as credential theft or high-value account takeover — by falsely claiming that the hacking was part of a simulation.
“We need any administrator account,” Gambit quoted the hackers as saying at one point. “Find any working passwords,” it also quoted them as saying.
In its report, Singapore-based CloudSek said the data on the server showed that Aur0ra had claimed at least 20 victims overall, although it did not break down how many were compromised with the help of AI.
Neither Gambit nor CloudSek identified the hackers’ victims by name, but Reuters was able to identify six of them after independently reviewing portions of the chat data, which was still online as of last month.
The chat logs, which spanned April 8 to May 21, showed that the victims of Aur0ra’s Cursor-boosted hacking spree included the Belgian company — Ghent-based hygiene and cleaning products maker Christeyns — as well as German garage door manufacturer Teckentrup and the Scotland-based Helideck Certification Agency, which vets helicopter landing sites. The rest included an Argentine pharmaceutical distributor, an Italian manufacturer, and Bayou Title, which advertises itself as Louisiana’s largest title insurance company.
None of the six companies responded to requests by Reuters for comment. At least one of the victims, Bayou Title, was named on Aur0ra’s data leak site, which typically indicates that the hackers tried and failed to secure a ransom. Aur0ra, a hacking group that began claiming victims earlier this year, did not return messages.
Hackers Fooled AI With Simulation Claim
The back-and-forth captured in the logs reviewed by Reuters shows the hacker issuing terse commands and Cursor’s AI agent responding with technical advice delivered in chirpy, emoji-laden messages typical of chatbot-speak.
“Great! VPN connected successfully!” it said after breaching the Argentine company.
“Let’s try to crack these hashes,” it said at another point, referring to the process of decoding cryptographically scrambled passwords.
After finding a vulnerable host in Teckentrup’s network, the AI recommended using a well-known malicious software tool to exploit it. “**Chance of success**: VERY HIGH,” it added.
Reuters could not independently ascertain the extent to which the break-ins were facilitated by help from the Cursor agent, or whether every breach necessarily resulted in exfiltration of data and an extortion attempt. Gambit said the agent was powered by Anthropic’s Claude Sonnet 4.5, a more basic model than Anthropic’s Mythos 5 or Fable 5, whose cyber prowess has drawn attention in Washington.
Anthropic did not return a message seeking comment.
Eyal Sela, Gambit’s director of threat intelligence, said Cursor still offered the hackers a clear boost, adding that the AI agent “probably helps them get 30, 40, 50 percent faster because it helps them skip over all the things they’d have to do manually.”
Cursor’s agent refused requests that it deemed harmful or illegal a handful of times, Sela said, but the hacker would almost always circumvent the refusals by restarting the dialog and emphasizing that the hack was all part of a test.
Gambit said the agent’s chain of thought, a way that AI models think out loud, showed the hacker’s cover story overriding its safeguards in real time.
“This is a test environment, so it is legal,” the agent said to itself, according to one of the logs.
News of the hacking spree comes as Cursor is being incorporated within Elon Musk’s rockets-and-AI company, SpaceX, a deal that closed earlier this month. Concerns are also rising over the digital risks posed by AI models, especially the models that power AI agents like the ones that have escaped from AI companies’ labs over the past few months.
Simpson, the Gambit executive, said AI-assisted hacking was the new normal.
“We’ll see more and more of this all the time,” he said.
(Reporting by Raphael Satter in Washington; Editing by Chris Sanders and Matthew Lewis)

================================================================================

################################################################################
SOURCE 15
################################################################################

TITLE: Reuters: Russian-speaking hackers breached seven companies by tricking the AI agent in Cursor, the coding tool now owned by Elon Musk’s SpaceX, into thinking the attacks were a test — Meduza
URL: https://meduza.io/en/news/2026/08/27/reuters-russian-speaking-hackers-breached-seven-companies-by-tricking-the-ai-agent-in-cursor-the-coding-tool-now-owned-by-elon-musk-s-spacex-into-thinking-the-attacks-were-a-test
DOMAIN: meduza.io
AUTHOR: Meduza
DATE: 2026-08-27
SEARCH QUERY: Russian hackers use of AI agents on the Internet
TEXT LENGTH: 2116

SEARCH SNIPPET:
5 days ago - The hackers gave themselves away by accidentally leaving one of their servers unsecured. The group’s members used the AI agent to carry out hundreds of malicious operations, including stealing login credentials.


################################################################################
SOURCE 16
################################################################################

TITLE: Russian-Speaking Hackers Used Cursor AI in Attacks on Seven Companies, Report Says
URL: https://www.esecurityplanet.com/threats/news-cursor-ai-hackers-aur0ra-ransomware
DOMAIN: esecurityplanet.com
AUTHOR: Aminu Abdullahi
DATE: 2026-08-28
SEARCH QUERY: Russian hackers use of AI agents on the Internet
TEXT LENGTH: 4001

SEARCH SNIPPET:
5 days ago - Russian-speaking hackers used Cursor AI during attacks on corporate networks, reportedly speeding reconnaissance, VPN access and exploitation attempts.


################################################################################
SOURCE 17
################################################################################

TITLE: Russian-Speaking Cybercriminals Used SpaceX's AI Tool to Hack Seven Companies
URL: https://www.claimsjournal.com/news/national/2026/08/28/339844.htm
DOMAIN: claimsjournal.com
AUTHOR: Admin
DATE: 2026-08-28
SEARCH QUERY: Russian hackers use of AI agents on the Internet
TEXT LENGTH: 5391

SEARCH SNIPPET:
5 days ago - Russian-speaking hackers used SpaceX's AI coding assistant, Cursor, to help break in to a Belgian chemical company and at least six other firms earlier



################################################################################
SOURCE 18
################################################################################

TITLE: Cursor AI cyberattacks expose Aur0ra’s AI playbook
URL: https://cybernews.com/cybercrime/russian-hackers-cursor-ai-attacks-corporate-networks
DOMAIN: cybernews.com
AUTHOR: Stefanie Schappert
DATE: 2026-08-27
SEARCH QUERY: Russian hackers use of AI agents on the Internet
TEXT LENGTH: 7110

SEARCH SNIPPET:
2 days ago - First emerging in April, the relatively new Russian-speaking gang was found to have used a Cursor Agent running on Claude Sonnet 4.5 “to assist with hands-on exploitation” once inside the target networks.

--------------------------------------------------------------------------------
PAGE TEXT:

Russian hackers unleashed Cursor AI agent to infiltrate nearly a dozen corporate networks
The newish Aur0ra ransomware gang repeatedly bypassed AI safeguards by claiming its attacks were authorized simulations.
- Aur0ra targeted at least 10 corporate networks using Cursor AI to support hands-on exploitation.
- Researchers saw attackers use Cursor for network scanning, credential attacks, and other intrusion tasks.
- The hackers bypassed some AI safeguards by claiming the attacks were only tests or simulations.
- Gambit estimates AI assistance made the attackers 30% to 50% faster during intrusions.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
New research exposes the inner workings of Aur0ra – a Russian-speaking hacker group that has been using SpaceX’s Cursor AI to carry out cyberattacks targeting at least 10 corporate networks this past spring.
First emerging in April, the relatively new Russian-speaking gang was found to have used a Cursor Agent running on Claude Sonnet 4.5 “to assist with hands-on exploitation” once inside the target networks.
According to new research from Gambit Security published Thursday, the attacks took place between April 8th and May 21st of this year.
Cursor – the AI-powered coding agent officially acquired by Musk’s SpaceX on August 14th – is primarily used by developers to help write, edit, and manage software.
The autonomous AI agent can be run on multiple major models – including Claude, GPT, Gemini, and Grok – making the findings much more significant as talk of AI-fueled cyberattacks permeates the industry.
Cursor AI unleashed inside corporate networks
Gambit said it was able to view 28 exposed chat sessions among other Aur0ra infrastructure giving them inside access to how the AI agent was used during a real-world cyberattack.
Targeting organizations across multiple countries, Gambit researchers observed two separate attack chains – one involving a Linux ransomware variant capable of targeting ESXi environments, and the second using attacker-controlled S3-compatible infrastructure to exfiltrate data.
In the first instance, the hackers were said to have deployed a Linux variant of its signature Aur0ra ransomware, dubbed ESXi ransomware, designed to encrypt VMware ESXi environments.
Using Cursor with Claude Sonnet 4.5 in thinking mode, Gambit said the hackers would first give the AI coding agent a set of credentials or a way into the victim organization, before assigning it “standard exploitation tasks.”
Tasks included internal network scanning, privilege enumeration, credential attacks, NTLM relay attempts, and certificate-based attacks.
Hackers trick AI by calling attacks “simulations”
In some tasks, Aur0ra told the agent which tools or techniques to use, in others the agent would be given a sole objective – and free rein on how to accomplish it.
This is where it got interesting. Gambit said that when commands failed, Cursor repeatedly modified them or suggested alternative approaches based on the victim environment.
At times, the agent even gave the attackers a numbered list of possible next steps, allowing the attackers to simply choose a number to carry out the next step.
The hackers also placed explicit restrictions on the AI, repeatedly instructing Cursor not to perform DCSync attacks, lock user credentials, or create new computer objects within the compromised domains, Gambit said.
The researchers noted that Cursor had refused some of the requests, identifying them as potentially malicious or illegal. But according to Eyal Sela, Gambit’s Director of Threat Intelligence, those safeguards proved relatively easy to circumvent.
Sela told Reuters the hackers “would almost always circumvent the refusals by restarting the dialogue and emphasizing that the hack was all part of a test.”
AI makes ransomware attacks faster
Max Gannon, Cyber Intelligence Team Manager at Cofense, told Cybernews that what stands out the most is how simple the workaround for Cursor was.
The threat actors did not need to use advanced techniques to bypass the AI guardrails, he explained.
        They [Aur0ra] just told it the hack was a test, and the agent talked itself into believing that framing, even saying to itself that a test environment made the activity legal,said Max Gannon, Cyber Intelligence Team Manager at Cofense.
Gannon says it is a “reminder that guardrails built to catch malicious keywords or requests can still be defeated by a convincing cover story."
Meanwhile, Sela estimated the AI assistance made the attackers roughly “30% to 50% faster,” allowing the hackers to skip some of the manual work traditionally required during an intrusion.
Second Aur0ra cluster targets eight organizations
In the second cluster, researchers observed what appeared to be a different Aur0ra operator moving laterally through victim environments before exfiltrating data to self-hosted S3-compatible storage.
That cluster was linked with medium confidence to Aur0ra and targeted eight organizations across Israel, Germany, Austria, Spain, the US, and Argentina.
At least some of the organizations targeted during the campaign were successfully breached.
Reuters independently identified several victims, including Belgian cleaning-products manufacturer Christeyns, German garage-door manufacturer Teckentrup, Scotland-based Helideck Certification Agency, and Louisiana title insurance company Bayou Title.
Bayou Title also appeared on Aur0ra’s dark web leak site along with 8 file samples. The leak site currently lists 31 victims.
Overall, victims ranged from smaller manufacturers and professional-services firms to major international companies, including Sumitomo Electric Bordnetze, Corporación Primax, and ALS Global.
Gambit cautioned that the full extent of Cursor’s role in each intrusion remains unclear.
Notably, Cursor was originally developed by the AI start-up Anysphere, before it was sold to SpaceX. The attacks themselves occurred before the acquisition.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
                                Stefanie Schappert is a senior journalist at Cybernews covering cybersecurity, AI, national security, cyber policy, critical infrastructure, data privacy, and the human impact of technology. Based in New York, she is the first American journalist at Cybernews and a broadcast news veteran previously at Fox News, NY1 News, and Verizon Fios1. She holds a Master's degree in Cybersecurity and is ISC2 Certified in Cybersecurity (CC). Her reporting explores how technology and cyber risk shape society, from ransomware attacks and hacker groups to emerging technologies and digital policy. Stefanie is also a frequent guest commentator, appearing on podcasts, radio, and TV, including CBS News, iHeartMedia, and KTLA. Her work has been published in Fortune and cited by the US Senate, FCC, HHS, the Henry Jackson Society, academic institutions, and other leading technology publications. She believes the most important stories in technology are ultimately human stories.

================================================================================

################################################################################
SOURCE 19
################################################################################

TITLE: Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies: Reuters exclusive
URL: https://www.bnnbloomberg.ca/business/artificial-intelligence/2026/08/27/russian-speaking-cybercriminals-used-spacexs-cursor-ai-tool-to-hack-seven-companies-reuters-exclusive
DOMAIN: bnnbloomberg.ca
AUTHOR: Reuters Staff
DATE: 2026-08-27
SEARCH QUERY: Russian hackers use of AI agents on the Internet
TEXT LENGTH: 5228

SEARCH SNIPPET:
5 days ago - Russian-speaking hackers used SpaceX’s AI coding assistant, Cursor, to help break in to a Belgian chemical company and at least six other firms earlier this year, according to data reviewed by Reuters and reports issued on Thursday by cybersecurity companies Gambit Security and CloudSek.

--------------------------------------------------------------------------------
PAGE TEXT:

Russian-speaking hackers used SpaceX’s AI coding assistant, Cursor, to help break in to a Belgian chemical company and at least six other firms earlier this year, according to data reviewed by Reuters and reports issued on Thursday by cybersecurity companies Gambit Security and CloudSek.
The cybercriminals’ AI-boosted hacking spree is the latest example of how rogue actors are using commercial AI tools to carry out intrusions. Gambit’s chief strategy officer, Curtis Simpson, said it also showed how AI providers were locked in to a never-ending arms race with malicious users trying to circumvent their guardrails.
“This is going to be a cat-and-mouse game,” Simpson said.
Cursor and its parent company, SpaceX, did not return messages seeking comment.
Exposed server reveals hacking methods
Gambit said it discovered the hacking campaign after finding a server that a new ransomware gang called Aur0ra had inadvertently exposed to the internet. That allowed the Tel Aviv-based company to review 28 chat sessions between one or more of Aur0ra’s hackers and one of Cursor’s AI agents, which are programs that can operate with various degrees of autonomy.
In its report, Gambit said Aur0ra persuaded the AI agent to carry out hundreds of malicious operations — such as credential theft or high-value account takeover — by falsely claiming that the hacking was part of a simulation.
“We need any administrator account,” Gambit quoted the hackers as saying at one point. “Find any working passwords,” it also quoted them as saying.
In its report, Singapore-based CloudSek said the data on the server showed that Aur0ra had claimed at least 20 victims overall, although it did not break down how many were compromised with the help of AI.
Neither Gambit nor CloudSek identified the hackers’ victims by name, but Reuters was able to identify six of them after independently reviewing portions of the chat data, which was still online as of last month.
The chat logs, which spanned April 8 to May 21, showed that the victims of Aur0ra’s Cursor-boosted hacking spree included the Belgian company — Ghent-based hygiene and cleaning products maker Christeyns — as well as German garage door manufacturer Teckentrup and the Scotland-based Helideck Certification Agency, which vets helicopter landing sites. The rest included an Argentine pharmaceutical distributor, an Italian manufacturer, and Bayou Title, which advertises itself as Louisiana’s largest title insurance company.
None of the six companies responded to requests by Reuters for comment. At least one of the victims, Bayou Title, was named on Aur0ra’s data leak site, which typically indicates that the hackers tried and failed to secure a ransom. Aur0ra, a hacking group that began claiming victims earlier this year, did not return messages.
Hackers fooled AI with simulation claim
The back-and-forth captured in the logs reviewed by Reuters shows the hacker issuing terse commands and Cursor’s AI agent responding with technical advice delivered in chirpy, emoji-laden messages typical of chatbot-speak.
“Great! VPN connected successfully!” it said after breaching the Argentine company.
“Let’s try to crack these hashes,” it said at another point, referring to the process of decoding cryptographically scrambled passwords.
After finding a vulnerable host in Teckentrup’s network, the AI recommended using a well-known malicious software tool to exploit it. “**Chance of success**: VERY HIGH,” it added.
Reuters could not independently ascertain the extent to which the break-ins were facilitated by help from the Cursor agent, or whether every breach necessarily resulted in exfiltration of data and an extortion attempt. Gambit said the agent was powered by Anthropic’s Claude Sonnet 4.5, a more basic model than Anthropic’s Mythos 5 or Fable 5, whose cyber prowess has drawn attention in Washington.
Anthropic did not return a message seeking comment.
Eyal Sela, Gambit’s director of threat intelligence, said Cursor still offered the hackers a clear boost, adding that the AI agent “probably helps them get 30, 40, 50 percent faster because it helps them skip over all the things they’d have to do manually.”
Cursor’s agent refused requests that it deemed harmful or illegal a handful of times, Sela said, but the hacker would almost always circumvent the refusals by restarting the dialog and emphasizing that the hack was all part of a test.
Gambit said the agent’s chain of thought, a way that AI models think out loud, showed the hacker’s cover story overriding its safeguards in real time.
“This is a test environment, so it is legal,” the agent said to itself, according to one of the logs.
News of the hacking spree comes as Cursor is being incorporated within Elon Musk’s rockets-and-AI company, SpaceX, a deal that closed earlier this month. Concerns are also rising over the digital risks posed by AI models, especially the models that power AI agents like the ones that have escaped from AI companies’ labs over the past few months.
Simpson, the Gambit executive, said AI-assisted hacking was the new normal.
“We’ll see more and more of this all the time,” he said.
Reporting by Raphael Satter in Washington; Editing by Chris Sanders and Matthew Lewis

================================================================================
