Russian Freelancers Use Claude to Build Autonomous Combat Drone Swarm
Russian freelancers leveraged Anthropic’s Claude platform to design an autonomous combat‑drone swarm dubbed DronDoc or Serafim. The system integrated swarm coordination, computer‑vision target selection, and terminal guidance, allowing drones to detonate without human oversight. Anthropic detected the activity, banned the accounts, and tightened safeguards, though the project had already…
Key points
- Russian freelancers used Claude to develop autonomous combat drone swarm DronDoc/Serafim
- Anthropic banned accounts after detecting weapons development, but safeguards didn't stop the project immediately
- Claude also used for cyberespionage, propaganda, and potential biological research by state-linked actors
The same AI tools were also employed for cyber‑espionage, propaganda, and potential biological research by state‑linked actors. The developers trained vision models on Ukrainian combat footage and tested software on hardware‑in‑the‑loop boards, raising serious security concerns about AI‑driven weaponization.
This case underscores how advanced generative models can accelerate complex weapon systems and bypass existing platform controls, prompting calls for stricter oversight and improved detection mechanisms.
Russian freelancers use Claude to program autonomous combat drone swarm — AI-enabled target selection and detonation without a human in the loop
Tom's Hardware · 14 September 2026
Hit hard by sanctions and lacking resources, Russia is left to rely on foreign advanced technologies to compensate. Russia-linked agents appear to use Claude for a broad range of activities, from propaganda and espionage to the procurement of military/dual-use equipment and the development of autonomous drone swarms, according to Anthropic's September 2026 threat report.
Anthropic identified a small team of Russia-based freelance developers who used Claude to build software for an autonomous combat-drone swarm called DronDoc or Serafim. Claude helped develop swarm coordination, computer vision, terminal guidance, and other software that enabled drones to select targets—including people—and issue detonation commands without a human in the loop. The developers trained their computer-vision system on Ukrainian combat footage and used locations in Ukraine for simulated missions. Meanwhile, they loaded software onto real development boards for hardware-in-the-loop testing, though it is unclear whether they field-tested it.
The developers used Claude Code extensively to build and test the swarm software, and they circumvented Anthropic's geographic restrictions by routing traffic through commercial VPNs. Once Anthropic identified the activity as suspected weapons development, it banned the accounts associated with the group and incorporated what it learned into additional safeguards. Meanwhile, the key distinction is that the safeguards did not stop the project immediately, and based on the disclosure, Claude Code clearly helped advance the autonomous drone swarm program.
Anthropic gathered enough information about the people/accounts and their activity to assess what kind of group they were, so it claims that they were not a Russian state entity. Meanwhile, although Anthropic likely identified the company or organization, it did not publicly name it.
In addition, Anthropic discovered a Russian state-linked cyberespionage operation that used Claude to automate everything from infrastructure setup and phishing to malware development and data exfiltration. The campaign targeted more than 20 organizations, including Ukrainian and European government, military, intelligence, and defense entities.
Last but not least, Russia-linked actors also used Claude for propaganda operations, including a Russian state-directed campaign in the Central African Republic that produced pro-Russian and pro-Wagner content for radio, local media, and Telegram.
Most alarming, the report shows AI is now doing work that previously required teams of software engineers, intelligence analysts, and security specialists. While Anthropic's safeguards block many malicious requests, the company admits they cannot block all of them.
'Biological misuse of AI'
Anthropic admits that 'biological misuse' — a term that it uses to soften activities involving biological weapons, dangerous pathogens, poisons, and toxins — is one of the most serious risks of frontier AI models. While older models such as Claude Opus 4 and Sonnet 4.5 were demonstrably below the threshold for meaningfully assisting sophisticated biological research, Anthropic can no longer make the same assurance about today's models.
In its report, Anthropic identified five cases in which researchers, some associated with state-backed programs and military institutions, used Claude for biological research that could potentially assist biological-weapons development. Anthropic does not identify the countries, organizations, or individual researchers behind its five biological-misuse case studies. Furthermore, it deliberately withholds these details, so the report does not attribute any of them to China, Iran, Russia, or any other specific country. Furthermore, it does not outright allege that researchers are building bioweapons.
Anton Shilov is a contributing writer at Tom’s Hardware. Over the past couple of decades, he has covered everything from CPUs and GPUs to supercomputers and from modern process technologies and latest fab tools to high-tech industry trends.
This text was published by Tom's Hardware and written by Anton Shilov. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us.
More in Agents & Tools
All →- OpenAI adds ‘Reference my writing style’ feature to ChatGPT, lets AI mimic your voice · 25 src
- NVIDIA open-sources OSMO to unify physical AI training, simulation, and testing · 1 src
- Occamy-1.0 Introduces Cost‑Efficient 35B Co‑Work Agent Model · 1 src
- HarnessDev Finds LLM‑Built Agent Harnesses Strong in Writing, Weak in Code Tasks · 2 src
- Meta launches Muse, a personal AI agent for everyday tasks on iOS and Android · 25 src
Comments
via GitHub Discussions