A Russia-based threat actor used Anthropic’s Claude AI to help build an autonomous swarm of kamikaze drones capable of selecting targets and triggering detonation without human approval.
The operation is one of several cases detailed in a new threat intelligence report from Anthropic, which found its AI models being used for weapons development, military procurement and espionage targeting defence organisations and technology.
The disclosures are the latest developments in a fast-evolving story about the role that general-purpose Large Language Models are playing in national security. Sometimes that role may be in aid of new defence tech; but in some cases, it’s the opposite: adversaries looking to weaponise AI for nefarious ends.
Anthropic said the small team of Russia-based developers, likely freelancers, used Claude Code to write and test software for a swarm of first-person-view (FPV) attack drones. The project, known as DronDoc or Serafim, included software to coordinate the swarm, provide terminal guidance, locate enemy drone operators, and control the drones’ onboard systems.
Significantly, the system was being designed to operate autonomously. According to Anthropic, its onboard model could choose targets, including a “person” category, and issue detonation commands without a human in the loop.
The developers were not simply asking Claude for theoretical advice. Anthropic said it found evidence that code was loaded onto development boards and tested on real hardware, although the systems remained early-stage and were validated in simulation rather than deployed operationally.
The team also trained a computer vision system using Ukrainian combat footage scraped from the internet, dividing equipment into “enemy” and “friendly” categories and allow-listing Russian systems. A location in Donetsk Oblast was repeatedly used as a demonstration strike point, while frontline Ukrainian cities and corridors featured in the project’s mission geography.
Anthropic said it believed the developers were a small, specialist freelance team rather than a Russian state entity. The company added that the group had links to a regional university and a federal research centre associated with the Russian Academy of Sciences. The developers claimed to have received funding from Russia’s Advanced Research Foundation, National Technology Initiative and its Ministry of Defence, but Anthropic said it could not verify those claims.
The case sits alongside another Russia-linked operation uncovered by Anthropic, in which AI was used much closer to the war in Ukraine.
An espionage group tracked by Anthropic as GTG-20006 used Claude across attacks on military and intelligence targets in Ukrainian and European governments, as well as diplomatic organisations and defence companies. Anthropic said its attribution aligned with public reporting on Midnight Blizzard, which focuses on malware delivery and credential theft, while the group’s tradecraft and targeting matched Russian state-linked espionage.
Ukraine’s drone industry was a recurring target, according to the report. The group stole mailboxes belonging to at least two drone component manufacturers, targeted a military drone maker, and obtained the complete proprietary software development kit for a drone vision system. It then spent several days reverse-engineering the technology, recovering information including its architecture, hardware bill of materials, suppliers and details of an unannounced product.
Claude was used throughout the espionage operation, from reconnaissance and phishing to credential theft, lateral movement, and the processing of hundreds of gigabytes of stolen data. Anthropic also observed the group using AI to monitor whether its malware had been detected, and then to modify and rebuild compromised tools to evade security products.
Russia was not alone. Anthropic said it had disrupted six cases involving Claude and conventional weapons programmes across China, Russia and Yemen. Four of the cases involved actors using the model to develop weapons software directly.
In China, one actor assessed to be a defence and military-industrial researcher used Claude to develop an electronic warfare and air-defence suppression suite.
The software analysed radar systems, surface-to-air missile sites and command posts before ranking targets and calculating how jamming assets should be assigned. During development, the scenario was changed to 12 targets in Taiwan, including air bases, a command bunker and Patriot and Tien Kung air-defence batteries. Anthropic said the actor had links to Chinese research institutions including the PLA Academy of Military Sciences.
A separate China-based actor used Claude to work on an anti-torpedo fire-control system and produce a technical proposal of more than 200 pages. Anthropic assessed that the actor was associated with a Chinese defence manufacturer seeking to develop a weapons specification and acquisition proposal for the People’s Liberation Army Navy.
In northern Yemen, meanwhile, a weapons engineering cell used Claude Code while working on a guided rocket, a ballistic missile with a stated range of more than 2,000km and a missile programme that included a hypersonic glide vehicle variant. The group test-fired a guided rocket and, after the test apparently failed, returned to Claude within hours to help diagnose what had gone wrong.
Anthropic said the six cases are not representative of typical use of its models and that it banned the accounts involved. But the company said its own evaluations show AI models making steady progress on simulated tactical intelligence and conventional weapons development tasks.
The cases offer an unusually detailed look at how general-purpose AI tools are already finding their way into adversaries’ military engineering and intelligence work.
In some cases, they are helping established threat actors move faster; in others, they appear to be allowing much smaller teams to take on work that would previously have required considerably more specialist engineering expertise.












