A Russia-based development team got Claude-generated code onto live development hardware while a separate operation used AI to steal and reverse-engineer proprietary drone-vision technology, according to Anthropic‘s latest threat report.
- Anthropic disrupts Russian developers using Claude Code to engineer targeting algorithms for autonomous FPV kamikaze drone swarms.
- Threat actors achieve Technology Readiness Level 3 to 4, validating software across physical microcontrollers and network simulation meshes.
- A separate state-linked espionage campaign compromises over 20 defense targets, reverse-engineering proprietary drone vision software development kits.
The first group used Claude Code to build software for an autonomous FPV drone swarm. Its onboard model could select targets, including a “person” target class, and issue detonation commands without a human in the loop, Anthropic said. The second operation targeted more than 20 organizations and stole a complete software development kit for a drone vision system before reverse-engineering its architecture, hardware bill of materials, and suppliers.
Neither case establishes that a Claude-built autonomous drone was fielded in Ukraine. Anthropic assessed the swarm-related systems at Technology Readiness Level 3–4, validated in simulation, although the developers did conduct hardware-in-the-loop testing.
Claude Reached Live Development Hardware
Anthropic identified the first operation as GTG-27005 and said it involved likely freelance Russia-based threat actors building a full-stack autonomous FPV kamikaze drone swarm. The developers called the project DronDoc or Serafim.
Claude Code was used to build the swarm’s core software, including shared swarm memory, fault-tolerant coordination logic, an onboard small language model, terminal guidance, geolocation, and low-level logic for programmable chips. Anthropic said the system was designed for autonomous lethal engagement.
Have a development worth tracking?
Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.
→ Submit a Press ReleaseThe onboard model could select targets and issue detonation commands without a human in the loop. The developers trained a computer-vision classifier on scraped Ukrainian combat footage, splitting targets into “enemy” and “friendly” and allow-listing Russian systems.
The work reached physical development hardware. Anthropic said the developers flashed low-level firmware onto live development boards, provisioned single-board computers, and connected their simulation environment through a mesh network. They repeatedly used a fixed coordinate in Donetsk Oblast as a demonstration strike point.
That was not proof of battlefield deployment.
Anthropic’s report rates the systems associated with the operation at TRL 3–4, meaning they were validated in simulation. The table includes the Serafim family of heterogeneous autonomous swarm systems, along with several other drone and control systems at the same maturity level.
The developers created their accounts between late 2025 and early 2026 and began the operation in mid-May 2026. Anthropic said they bypassed its geographic access controls by routing traffic through commercial virtual private servers.
Anthropic assessed the group as a small, specialized freelance team doing civilian and military work, not a Russian state entity. It identified nine associated accounts, eight of which were used only for ordinary freelance work. The company said the actors had ties to a regional university with a federal research center associated with the Russian Academy of Sciences.
The actors claimed to have received funding from Russia’s Advanced Research Foundation, National Technology Initiative, and Ministry of Defense. Anthropic said it could not verify those claims.
The company banned the associated accounts and incorporated its findings into its safeguards.
Hackers Stole a Drone-Vision SDK
The second operation, GTG-20006, involved a separate actor. Anthropic said its activity was consistent with public reporting linking the actor to Midnight Blizzard, while the operator’s tradecraft and targeting were consistent with Russian state-nexus espionage.
The actor targeted more than 20 organizations, including government, defense, and intelligence bodies, embassies, diplomatic missions, think tanks, and defense-industrial companies. The targets were concentrated in Ukraine and Europe, with activity extending into the Middle East and Asia.
Ukraine and military drone technology providers and supply chains were a recurring theme.
The actor bulk-exported the mailboxes of at least two drone component manufacturers, targeted a military drone maker, and stole a complete proprietary software development kit for a drone vision system, Anthropic said. The attackers then spent several days reverse-engineering the system, recovering its product architecture, hardware bill of materials, supplier dependencies, and details of an unannounced product.
AI was embedded across the operation. Anthropic said the actor used AI-driven workflows for reconnaissance, infrastructure acquisition, phishing, persistence, command and control, and data exfiltration.
The actor also used AI after access was gained. When monitoring agents detected that malware had been flagged by security products, they could identify the problem, modify the malware, and rebuild it until the toolkit was again undetected, Anthropic said.
Anthropic disrupted both operations. In the drone case, the company said nine associated accounts were identified, with eight used only for ordinary freelance work.
Activate Terminal Layer
Structural analysis of the systems, pressures, and stakeholders behind this story.





