Anthropic says a freelance Russian group exploited its Claude AI model for a range of activities related to the war in Ukraine: spreading propaganda, conducting espionage, acquiring military or dual-use equipment, and developing autonomous drone swarms.
DronDoc / Serafim: the autonomous swarm software
According to Anthropic, the attackers used Claude to develop parts of an autonomous combat drone-swarm software known as “DronDoc” or “Serafim.” They relied on Claude Code to build capabilities such as swarm coordination and computer-vision–based target recognition. Anthropic’s report indicates these capabilities allowed drones to select targets — including people — and strike them without human intervention.
Developers trained the system on combat footage from Ukraine and selected Ukrainian locations for simulated missions. The software was also deployed onto drone hardware, although Anthropic did not state whether those devices were later used in field tests.
The group bypassed geographic restrictions with VPNs to access Claude services, circumventing Western restrictions that have limited Russian access to many technologies and services since the invasion of Ukraine.
Espionage and more than 20 targets
Anthropic found the group used Claude for espionage-related tasks, including data theft and preparing phishing or other malicious attacks. This activity targeted more than 20 organizations, among them Ukrainian and European governmental, military, intelligence, and defense entities.
Propaganda and other abuses
The attackers also used Claude for propaganda purposes, producing pro‑Russian content aimed at audiences in the Central African Republic. These uses underline how language models can be misused for influence operations and political manipulation.
Anthropic’s response and attribution
After identifying the activity as an attempt to develop weapons, Anthropic suspended accounts linked to the group and incorporated lessons learned into its security protocols. The company says it gathered enough information to classify the perpetrators as non-state-affiliated hackers, but it did not disclose the specific organization or institution the actors belonged to.
Anthropic also identified separate operations it attributes to Moscow-backed actors; those campaigns involved espionage and other malicious actions.
While Anthropic’s interventions disrupted some of the group’s activity, publicly disclosed information indicates Claude materially contributed to the attackers’ progress in developing the autonomous drone-swarm capability.
Why this matters
The case highlights that advanced language models and developer tools pose risks beyond generating text: they can directly facilitate the creation of military systems, including autonomous weaponry. It also stresses the responsibility of service providers to prevent misuse and the need for international coordination and regulation to address such threats.



