AI Bypassed for Drone Swarms
A Russia-based developer group bypassed geographic blocks to use Anthropic's Claude Code to write software for an autonomous kamikaze drone swarm designed for lethal engagement.

In mid-May 2026, a drone swarm project codenamed "DronDoc" or "Serafim" was initiated to develop software for an autonomous FPV kamikaze drone swarm. To build this system, the developers bypassed geographic blocks by routing their network traffic through commercial virtual private servers to access Anthropic's Claude Code tool. The software engineered during this project included an onboard small language model designed to govern drone flight behaviors, alongside a terminal guidance system for detonation commands. Additionally, the developers trained a computer-vision classifier on scraped Ukrainian combat footage, establishing a specific "person" class to enable autonomous lethal engagement. During software-in-the-loop simulations, the developers repeatedly utilized frontline areas in Ukraine's Donetsk region as simulated test sites. In response to these activities, Anthropic identified and banned nine developer accounts associated with the project.
These activities and details were first reported by Anthropic on September 10, 2026, in its fourth Threat Intelligence Report, titled "Detecting and countering misuse of AI: September 2026." Anthropic attributed the project to a Russia-based team tracked as GTG-27005. The company assessed with moderate confidence that the actors involved were a small team of freelance developers with ties to a regional Russian university and a federal research center. According to Anthropic, the developers themselves claimed to have received funding from several Russian state entities, including Russia's Advanced Research Foundation, the National Technology Initiative, and the Russian Ministry of Defence. However, these specific attributions regarding state funding, university ties, and the exact identity of the group remain disputed.
This development is significant because it demonstrates how developers can leverage commercial artificial intelligence tools to construct lethal guidance systems, despite safety safeguards. The software created with Claude Code successfully integrated a small language model on the drone's hardware to manage flight behaviors, while the computer-vision classifier established a functional pathway for autonomous lethal targeting. According to confirmed findings, the project reached Technology Readiness Level 3 to 4. However, the system was never field-deployed, and Anthropic's intervention to ban the associated accounts successfully disrupted the developers' access to their platform.
In response to these findings, defense analysts have noted that if the developers' claims regarding state funding from the Russian Ministry of Defence and other entities are true, the distinction between "freelance" and "state-sponsored" actors becomes functionally negligible. This perspective contrasts with Anthropic's official categorization of the group as "likely freelance" and "not a Russian state entity."
Several critical elements of the operation remain unknown. Anthropic stated that it was unable to independently verify whether the developers actually received any funding from the Russian Ministry of Defence, the Advanced Research Foundation, or the National Technology Initiative. Furthermore, the exact names of the regional university and the federal research center associated with the Russian Academy of Sciences remain undisclosed. It also remains unknown if physical drone frames were ever fully assembled, or if the software was successfully flashed onto physical, flight-ready swarms beyond static hardware-in-the-loop test stands.
Sources
- fonearena.comAnthropic September 2026 Threat Report: AI Misuse Across Cyber Operations, Surveillance and Weapons
- CybernewsRussian developers used Claude to build kamikaze drones that can choose their own targets
- Cyber KendraAnthropic Threat Report Says AI Now Rebuilds Malware
- CA Akhilesh KumarAnthropic's September 2026 Threat Report: Hackers, Spies and Propagandists Tried to Weaponise Claude, and Were Caught
- remioClaude Drone Swarm Case Exposes the Limits of Anthropic’s AI Safeguards
- AnthropicCountering misuse of AI: September 2026
Verified claims
Stills

Written by The Quiet Search. Method: /about.