Russian developers used Claude to build kamikaze drones that can choose their own targets
Anthropic revealed the findings in its 154-page report on how Claude AI is being misused by threat actors.

Image by wutianzeri | Shutterstock
- Anthropic says Russia-based developers used Claude Code to build software for autonomous kamikaze drones.
- The system could select targets, including people, and detonate without human approval, according to Anthropic.
- The team trained target-recognition tools on scraped Ukrainian combat footage and used Ukrainian front-line areas in tests.
- Anthropic banned nine accounts and said it could not verify claimed Russian government funding.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Anthropic found that “likely freelance” Russia-based developers used Claude AI to build the core software for an autonomous swarm of kamikaze drones capable of selecting targets – including people – without human oversight.
In its 154-page report on how bad actors misuse Claude AI, Anthropic described how its technology had been utilized by Russia-linked actors.
The company said it observed a small team of Russia-based threat actors, tracked as GTG-27005, using Claude Code to write and test code and save it directly into their own project files. Alongside Claude Code, they used simulation software to test the system and rented computing power to train the models.
The operation, dubbed “DronDoc” or “Serafim”, began in mid-May 2026. The actors, who created their accounts between late 2025 and early 2026, bypassed Anthropic’s geographic blocks by routing traffic through commercial virtual private servers.
Claude helped them develop shared swarm memory and a fault-tolerant coordination system so that drones can operate together. They then built an onboard small language model to govern whether drones should attack, observe, or return to base.
Anthropic said the targeting system could select its own targets and issue the command to detonate without a human in the loop. According to the company, it was designed “for autonomous lethal engagement”, and its target classes explicitly included “person.”
The actors trained a computer-vision classifier on scraped Ukrainian combat footage, labeling targets “enemy” or “friendly” and allow-listing Russian systems.
The freelance team also repeatedly used a location in Ukraine’s Donetsk region as a demonstration strike point and Ukrainian front-line cities and corridors as the mission geography.
Anthropic believes the actors “were a small, specialized freelance team doing a mix of civilian and military work”, not a Russian state entity. The company identified nine accounts in total and linked the actors to a regional university and a federal research center associated with the Russian Academy of Sciences. Those accounts have since been banned.
The actors also claimed to have received funding from Russia’s Advanced Research Foundation, National Technology Initiative, and Ministry of Defence. Anthropic said it could not verify those claims.
Anthropic noted that attackers are increasingly using AI to orchestrate cyberattacks against Ukrainian government representatives and military targets. One Russia-linked group was observed using AI to target Ukrainian officials through phishing, compromised hotel WiFi networks, malware, and WhatsApp account hijacking.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Anthropic said its attribution was consistent with previous reports linking the attacker to Russia’s Midnight Blizzard hacking group.
The Russian Embassy in Washington did not respond to Reuters’ request for comment on Anthropic’s allegations.