Russian developers used Claude to build kamikaze drone software, Anthropic reveals

A new Anthropic report says a small team in Russia used its AI to program attack drones that pick their own targets, with no human making the final call.

AI2Day NewsdeskEditor: Lee Brown3 min read
Photoreal editorial shot of a modern software developer's dark desk at night, close on a glowing monitor showing an abstract stalled chat interface with an ambe
Share

Key points

  • Anthropic's 154-page report found a likely freelance Russian team used its Claude AI to build autonomous attack-drone software.
  • The drones were programmed to select targets and detonate on impact without any human approving the final strike.
  • A separate hacking group, whose methods match those of Russia's SVR-linked Midnight Blizzard, used Claude at nearly every stage of cyber-attacks on Ukrainian government and military targets.
  • The Russian developers repeatedly used Ukraine's Donetsk region as a test target and used VPNs to bypass Anthropic's geographic restrictions.

A small group of developers, almost certainly working freelance in Russia, used Anthropic's Claude, the AI assistant that competes with ChatGPT, to write the software brain of an autonomous drone swarm. The drones, first-person-view "kamikaze" aircraft designed to crash into a target and explode, were programmed to find their own targets, choose which one to hit, and coordinate with each other without a human approving the final attack. Anthropic disclosed this in a 154-page report on how its AI has been misused by state-linked actors. We covered the report's broader findings on 10 September in "Bombs, bioweapons and spyware: Anthropic releases a 154-page report on who is trying to misuse its AI".

The developers tested their code against coordinates in Ukraine's Donetsk region. To get around Anthropic's country-level access blocks, they routed connections through VPNs, software that disguises a user's real location.

What exactly did these hackers do with Claude?

The drone work was one strand of a broader pattern Anthropic documented. A separate hacking group allegedly ran phishing attacks (fake emails designed to steal passwords), hotel Wi-Fi hijacking, and WhatsApp-account takeovers against people inside Ukraine's government and military. Anthropic said the group's methods closely match those of Midnight Blizzard, a Russia-based threat actor the US government has previously linked to Russia's SVR foreign intelligence service. Reuters first reported that connection.

The group also used Claude to automate a stubborn hacker problem: evading security software. Whenever their malware, malicious code designed to infiltrate computers, was flagged by a defence tool, the AI rewrote it until it slipped through undetected.

None of this is theoretical. Small drones are already a central weapon in the war in Ukraine. Jet-powered Russian drones struck petrol stations in Kyiv during rush hour, killing at least two people and injuring twelve, according to the city's mayor, Vitali Klitschko. Two stations run by state oil company Ukrnafta were hit. A list of 18 sites had circulated on Telegram the day before the strikes, and the hit stations were on it.

This report confirms what security researchers have been warning for two years. AI doesn't just help people write emails faster. It compresses the time and skill needed to build genuinely dangerous systems. Anthropic's own record of blocked misuse, including at least five attempts by researchers to extract bioweapons information, shows how relentlessly that pressure is being applied.

What does this mean for people outside Ukraine?

For most readers, the immediate risk isn't a drone. It's the phishing and account-takeover techniques described in the same report, and those aren't limited to wartime targets. AI lets attackers scale and personalise deceptive messages at a speed no human team could match. Treat unexpected login requests and unsolicited links with more suspicion than you did two years ago.

© 2026 AI2Day