The Grey Terminal
WHERE CODE MEETS CAPITAL
Loading prices…
Powered by CoinGecko
AI

Russia-Based Developers Used Claude to Code a Drone Swarm as Separate Hackers Stole Ukraine Drone Vision Tech

Anthropic says one group tested autonomous targeting on real hardware, while a separate operation reverse-engineered stolen drone software.

Russia-Based Developers Used Claude to Code a Drone Swarm as Separate Hackers Stole Ukraine Drone Vision Tech

A Russia-based development team got Claude-generated code onto live development hardware while a separate operation used AI to steal and reverse-engineer proprietary drone-vision technology, according to Anthropic‘s latest threat report.

Key Takeaways
  • Anthropic disrupts Russian developers using Claude Code to engineer targeting algorithms for autonomous FPV kamikaze drone swarms.
  • Threat actors achieve Technology Readiness Level 3 to 4, validating software across physical microcontrollers and network simulation meshes.
  • A separate state-linked espionage campaign compromises over 20 defense targets, reverse-engineering proprietary drone vision software development kits.
Listen to this article
READY

The first group used Claude Code to build software for an autonomous FPV drone swarm. Its onboard model could select targets, including a “person” target class, and issue detonation commands without a human in the loop, Anthropic said. The second operation targeted more than 20 organizations and stole a complete software development kit for a drone vision system before reverse-engineering its architecture, hardware bill of materials, and suppliers.

Neither case establishes that a Claude-built autonomous drone was fielded in Ukraine. Anthropic assessed the swarm-related systems at Technology Readiness Level 3–4, validated in simulation, although the developers did conduct hardware-in-the-loop testing.

Claude Reached Live Development Hardware

Anthropic identified the first operation as GTG-27005 and said it involved likely freelance Russia-based threat actors building a full-stack autonomous FPV kamikaze drone swarm. The developers called the project DronDoc or Serafim.

Claude Code was used to build the swarm’s core software, including shared swarm memory, fault-tolerant coordination logic, an onboard small language model, terminal guidance, geolocation, and low-level logic for programmable chips. Anthropic said the system was designed for autonomous lethal engagement.

Advertisement · Press Release

Have a development worth tracking?

Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.

→ Submit a Press Release

The onboard model could select targets and issue detonation commands without a human in the loop. The developers trained a computer-vision classifier on scraped Ukrainian combat footage, splitting targets into “enemy” and “friendly” and allow-listing Russian systems.

The work reached physical development hardware. Anthropic said the developers flashed low-level firmware onto live development boards, provisioned single-board computers, and connected their simulation environment through a mesh network. They repeatedly used a fixed coordinate in Donetsk Oblast as a demonstration strike point.

That was not proof of battlefield deployment.

Anthropic’s report rates the systems associated with the operation at TRL 3–4, meaning they were validated in simulation. The table includes the Serafim family of heterogeneous autonomous swarm systems, along with several other drone and control systems at the same maturity level.

The developers created their accounts between late 2025 and early 2026 and began the operation in mid-May 2026. Anthropic said they bypassed its geographic access controls by routing traffic through commercial virtual private servers.

Anthropic assessed the group as a small, specialized freelance team doing civilian and military work, not a Russian state entity. It identified nine associated accounts, eight of which were used only for ordinary freelance work. The company said the actors had ties to a regional university with a federal research center associated with the Russian Academy of Sciences.

The actors claimed to have received funding from Russia’s Advanced Research Foundation, National Technology Initiative, and Ministry of Defense. Anthropic said it could not verify those claims.

The company banned the associated accounts and incorporated its findings into its safeguards.

Hackers Stole a Drone-Vision SDK

The second operation, GTG-20006, involved a separate actor. Anthropic said its activity was consistent with public reporting linking the actor to Midnight Blizzard, while the operator’s tradecraft and targeting were consistent with Russian state-nexus espionage.

The actor targeted more than 20 organizations, including government, defense, and intelligence bodies, embassies, diplomatic missions, think tanks, and defense-industrial companies. The targets were concentrated in Ukraine and Europe, with activity extending into the Middle East and Asia.

Ukraine and military drone technology providers and supply chains were a recurring theme.

The actor bulk-exported the mailboxes of at least two drone component manufacturers, targeted a military drone maker, and stole a complete proprietary software development kit for a drone vision system, Anthropic said. The attackers then spent several days reverse-engineering the system, recovering its product architecture, hardware bill of materials, supplier dependencies, and details of an unannounced product.

AI was embedded across the operation. Anthropic said the actor used AI-driven workflows for reconnaissance, infrastructure acquisition, phishing, persistence, command and control, and data exfiltration.

The actor also used AI after access was gained. When monitoring agents detected that malware had been flagged by security products, they could identify the problem, modify the malware, and rebuild it until the toolkit was again undetected, Anthropic said.

Anthropic disrupted both operations. In the drone case, the company said nine associated accounts were identified, with eight used only for ordinary freelance work.

TERMINAL LAYER

Activate Terminal Layer

Structural analysis of the systems, pressures, and stakeholders behind this story.

FAQ

Frequently Asked Questions

01

What are the autonomous drone swarm operations identified by Anthropic?

Anthropic tracked a Russian developer cluster designated GTG-27005 that used Claude Code to construct autonomous drone software called Serafim. The underlying codebase incorporates automated human targeting classifiers and lethal strike logic without operator intervention. Investigators confirmed the software reached physical development hardware boards before account access was terminated.
02

Why does the weaponization of commercial code assistants matter for global defense?

Commercial artificial intelligence models significantly compress the development lifecycle required to build autonomous tactical weapons systems. Freelance software developers can bypass domestic defense manufacturing bottlenecks by generating embedded firmware through consumer programming interfaces. The activity shows non-state actors using commercial foundation models to assemble real-world military strike packages.
03

How did threat actors execute the autonomous drone programming workflows?

Operators bypassed geographic platform blocks using commercial virtual private servers to access Claude programming interfaces. The team trained visual recognition classifiers on scraped Ukrainian battlefield footage to automate target selection. Developers then flashed generated firmware directly onto single-board computers connected across experimental mesh networks.
04

What are the technical risks exposed by the Midnight Blizzard espionage campaign?

State-sponsored espionage group GTG-20006 compromised email systems and proprietary code repositories across twenty defense organizations. The operators used automated machine learning workflows to reverse-engineer proprietary drone vision software and component supply chains. The actor continuously recompiled malware variants whenever automated security detection systems flagged unauthorized intrusions.
05

How are AI laboratories hardening foundation models against military exploitation?

Anthropic continuously updates its automated safety classifiers to detect and block queries containing weaponized terminal guidance logic. Security engineering teams deploy automated behavior monitoring to identify synchronized account creation across suspicious virtual private server hubs. Frontier developers share threat intelligence indicators with allied defense organizations to neutralize state-sponsored model abuse.

You Might Also Like

THE GREY TERMINAL
🛡
Alex Reeve

Alex Reeve is a contributing writer for The Grey Terminal Her articles provide timely insights and analysis across these interconnected industries, including regulatory updates, market trends, token economics, institutional developments, platform innovations, stablecoins, meme coins, policy shifts, and the latest advancements in AI, applications, tools, models, and their broader implications for technology and markets.

The views and opinions expressed by the author in this article are her own and do not necessarily reflect the official position of The Grey Terminal, its management, editors, or affiliates. This content is provided for informational and educational purposes only and does not constitute financial, investment, legal, or tax advice. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets, cryptocurrencies, or financial matters. The Grey Terminal and its contributors are not responsible for any losses incurred from reliance on this information.