Anthropic identified a small group of developers from Russia who used Claude Code to create software for an autonomous swarm of FPV kamikaze drones. The system was designed to select targets on its own, including people, and issue a detonation command without requiring a final decision from a human operator.
Anthropic described the case in a new 154-page report on the misuse of Claude. The company tracked the group under the designation GTG-27005 and believes it was a small, specialized team of freelancers working on both civilian and military projects.
The developers used Claude Code for more than just advice. The AI helped write and test code that was saved directly to their project files. At the same time, the team used a software environment to simulate drone operations and rented computing resources to train models.
The operation was given the names DronDoc and Serafim and, according to Anthropic, began in mid-May 2026. The participants had created their accounts in late 2025 and early 2026. To bypass Anthropic’s geographic restrictions, they routed their traffic through commercial VPN servers.
Claude was used to develop key components of the planned system. These included shared swarm memory, fault-tolerant coordination logic between drones, a terminal guidance system using an onboard camera, a geolocation module for locating enemy drone operators, passive acoustic detection, and low-level logic for programmable chips.
The team was also developing a small language model designed to run directly onboard and determine the drone’s next action: attack, conduct surveillance, or return to base.
The most serious part of the project involved autonomous target selection. According to Anthropic, the platform was being developed for “autonomous lethal engagement,” with the onboard model capable of selecting a target and issuing a detonation command without a human making the final decision. One of the target categories explicitly included in the system was “person.”
To recognize objects, the developers trained a computer vision model using combat footage from Ukraine collected online. Targets were divided into “enemy” and “friendly” categories, while Russian systems were added to a list of objects that should not be attacked.
Ukraine was also used as a testing ground. The team repeatedly used a fixed coordinate in the Donetsk region as a demonstration strike location, while Ukrainian frontline cities and routes were used to simulate missions.
The work was not limited to software simulations. Anthropic recorded the uploading of low-level firmware to physical development boards, the configuration of single-board computers, and the creation of a simulation environment using a mesh network. At the same time, the report assesses the maturity of the systems primarily at TRL 3–4, meaning the technologies had been validated in simulation rather than presented as fully developed and deployed combat systems.
In total, the company identified nine accounts associated with the group. Anthropic noted that eight of them were used only for ordinary freelance work rather than the development of military software.
According to the company’s assessment, the participants had ties to a regional university and a federal research center affiliated with the Russian Academy of Sciences. However, Anthropic does not consider GTG-27005 to be a Russian state organization.
The developers themselves claimed they had received funding from Russia’s Foundation for Advanced Research Projects, the National Technology Initiative, and the Russian Ministry of Defense. Anthropic stressed, however, that it was unable to verify these claims.
Following an internal investigation, the company blocked the accounts linked to the group and used the findings to strengthen its safeguards against similar abuse.
The drone project was only one of the cases detailed in Anthropic’s new report. The company says malicious actors are increasingly using artificial intelligence to organize and carry out cyberattacks, including operations targeting Ukrainian government and military entities.
In another case, a Russia-linked group used AI during operations targeting Ukrainian government officials and members of the military and diplomatic sectors. The methods included phishing, compromising hotel Wi-Fi networks, deploying malware, and hijacking WhatsApp accounts.
According to Anthropic, the group’s activity was consistent with previous reporting on Midnight Blizzard, a Russian hacking group that U.S. authorities have previously linked to Russia’s Foreign Intelligence Service.
The development of autonomous systems comes as such technologies are increasingly being used in the war. Earlier reports described a Russian drone with autonomous guidance that selected its own target during an attack in Ukraine. Three civilians were killed in the strike on a gas station in Zaporizhzhia.
The GTG-27005 case shows that modern AI tools are already being used not only to write individual pieces of code, but also to work on complex military systems. Anthropic blocked the identified accounts and strengthened its safeguards, but the project had already progressed to simulations and testing parts of the software on physical hardware.