WENAWorld Events, News & Analysis
Sat, 12 Sept, 2026

Anthropic says Russian developers used Claude to build attack drone software

A 154-page report describes a small freelance team programming an autonomous swarm to select its own targets, using VPNs to get around geographic blocks. The same report details hacking against Ukrainian government targets.

A small multirotor drone in flight
File photo: a small multirotor drone. Photograph by Ryan Decker via Wikimedia Commons (CC BY-SA 3.0)

A small team of likely freelance developers in Russia used the AI system Claude to build software for an autonomous swarm of first-person-view attack drones, according to Anthropic, the company that makes it.

The software covered terminal guidance, target selection and coordination between multiple aircraft. Anthropic said the swarm was programmed to pick its own targets and crash into them to detonate, without a human making the final call.

What the report describes

The findings appear in a 154-page report describing how bad actors used Claude for state-sponsored surveillance and propaganda operations.

In their programming, the freelance team repeatedly selected a location in Ukraine's Donetsk region as the target, and used VPNs to circumvent Anthropic's geographic blocks.

The detail about VPNs is the operationally significant one. Geographic restriction is among the blunter controls an AI provider has, and it fails against anyone willing to route their traffic elsewhere — which is to say, against most people who intend to misuse a service.

Small drones have become a central weapon in the war in Ukraine.

The autonomy question

The element that distinguishes this from ordinary drone software is the removal of the human from the final decision — the swarm, as Anthropic describes it, was programmed to choose its own target and strike it with nobody authorising that particular strike.

What the report describes is not a deployed system. It is software developed with the assistance of a commercial AI model by a small team the company assesses to be freelance — which is a different proposition from a state programme, and in some respects a more troubling one, because the barrier to entry is lower.

The cyber findings

Anthropic also found that cybercriminals and state-backed hackers are increasingly using AI to orchestrate and execute large portions of cyber-attacks, including attacks on officials in Ukraine.

One hacking group allegedly ran phishing, hotel wifi hijacking and WhatsApp-takeover operations against targets in the Ukrainian government, military and diplomatic sectors, using AI at nearly every stage.

The group's tradecraft was consistent with the Russia-based threat actor Midnight Blizzard, which the US government has previously linked to Russia's SVR foreign intelligence service, Reuters reported. The Russian embassy in Washington did not immediately respond to a request for comment.

Malware that rewrites itself

The most technically notable item in the cyber section is a feedback loop. The group allegedly used AI to build a system that automatically detected when its malware was flagged by security defences, and then rewrote the code until it evaded detection.

That inverts the usual economics of defensive security. Signature-based detection assumes the attacker must do work to produce each new variant; automating the rewrite removes that cost, and turns evasion into something that runs continuously without supervision.

The context in Kyiv

The report was published as petrol stations in Kyiv were struck by jet-powered drones in a wave of targeted Russian attacks, with the bombardment of the capital entering a more intense phase.

At least two people were killed and 12 injured in strikes on two petrol stations on Friday morning, according to the city's mayor, Vitali Klitschko. The rush-hour strikes followed a similar attack on a petrol station on Thursday.

The proximity of the two stories is coincidental in the sense that the report covers a period rather than a day. It is not coincidental in the sense that both concern the same technology being used for the same purpose.

What a company can and cannot do

Anthropic's position in this is unusual: it is reporting misuse of its own product, in detail, in public. The company both operates the controls that were circumvented and is the source of the account of how they were circumvented.

That produces a genuinely useful record — nobody else has this visibility — and a limit. The measures described as having failed are the company's own, and the report is the company's account of them.

The findings on drone software and on hacking against Ukrainian targets are part of a wider report that also covers other categories of misuse.

More from Technology

All Technology →