By Open Chronicle with agencies
Russian linked actors have used Anthropic’s Claude artificial intelligence system in cyber espionage campaigns, influence operations and the development of software for autonomous military drones, according to a new threat intelligence report from the U.S. AI company.
The findings, published by Anthropic on September 10, provide a detailed picture of how advanced AI tools are increasingly being incorporated into intelligence gathering, cyber operations and weapons development. Anthropic said its threat intelligence team identified and disrupted the malicious activity and used the investigations to strengthen safeguards designed to detect similar abuse.
The cases range from automated cyber operations targeting Ukrainian government institutions and military technology suppliers to Russian influence activities abroad and a project intended to develop a largely autonomous swarm of first person view kamikaze drones.
Anthropic stressed that the incidents involve actors abusing Claude in violation of its policies. They do not indicate that the company knowingly supported the operations.
AI enters the cyber espionage pipeline
One of the most significant cases described by Anthropic involved a sophisticated threat actor using Claude across multiple intelligence and cyber operations.
Ukraine was a central focus. According to Anthropic, the actor scanned email and remote access systems across more than two dozen Ukrainian government organisations, with government officials, military personnel and diplomatic staff among the recurring targets.
Military drone technology was another major area of interest.
Anthropic said the attackers exported mailboxes belonging to at least two drone component manufacturers, targeted a military drone company and obtained a proprietary software development kit associated with a drone vision system.
The attackers subsequently spent several days analysing that system, reconstructing elements of its architecture, hardware components, suppliers and information about an unreleased product. Firmware connected to military drone control and artificial intelligence vision systems appeared to be particularly valuable to the operation.
Targets outside Ukraine included government organisations in other regions connected with maritime shipping and tracking.
Claude used as more than an assistant
The report suggests that AI was not simply being used to answer technical questions.
The operators built workflows in which AI agents could perform different parts of an intelligence operation simultaneously.
Anthropic said the campaign employed what it described as “agent swarms.” A lead AI agent could divide reconnaissance and post intrusion work among multiple subagents operating in parallel.
Campaign information could also persist between sessions. Target lists, stolen credentials, instructions and the status of individual operations were stored so that activity could resume later without rebuilding the entire operational context.
Separate workflows were used for intrusion operations, reconnaissance against foreign governments, malware development, examination of security products for potential vulnerabilities and maintenance of intelligence collection infrastructure.
The development illustrates an important shift in AI enabled cyber operations. Advanced models can increasingly become part of the operational infrastructure itself rather than functioning only as advisory tools.
Pro Russian influence operations in Africa and Moldova
Anthropic also reported detecting Russian linked influence activity involving Claude.
According to the material provided to Open Chronicle, investigators working alongside the All Eyes On Wagner project identified an account operated by a Russian speaking individual in Bangui, Central African Republic, connected with Radio Lengo Songo.
The station has previously been associated with Russian influence activities in the country and the Wagner network.
The operator allegedly used AI to help prepare pro Russian material while coordinating content associated with Russian state media and local influence networks. The content promoted narratives favourable to Russia and the Central African government while criticising France and domestic opposition figures.
The operation was designed to appear locally produced, according to the investigation.
Anthropic also identified AI assisted political content production connected with Moldova. A former regional official from the Russian state run Sputnik media network allegedly used Claude to adapt news reports, polling information and opposition material into content supporting pro Kremlin narratives.
These cases illustrate how generative AI can reduce the time and personnel required to produce large quantities of politically targeted material.
Russia linked developers pursued autonomous kamikaze drone swarm
Perhaps the most consequential military finding concerned a separate Russia based project to develop an autonomous FPV drone swarm.
Anthropic identified the operation as GTG 27005 and said the developers referred to their project as “DronDoc” or “Serafim.” The company assessed the actors as likely freelance Russia based developers.
According to Anthropic, Claude Code was used to write and test substantial portions of the software.
The proposed system included shared memory between drones, fault tolerant coordination, terminal guidance, geolocation capabilities, passive acoustic detection and software operating on the drones’ programmable hardware.
Most significantly, Anthropic said the developers were designing the platform for autonomous lethal engagement.
The onboard system was intended to identify potential targets, including a human target category, and make engagement decisions without requiring a human operator to remain directly in the decision loop.
Combat footage used to train targeting system
The developers also trained a computer vision classifier using footage from the war in Ukraine.
According to Anthropic, the system separated targets into opposing and friendly categories while Russian military systems were placed on an allow list.
A fixed coordinate in Ukraine’s Donetsk region was repeatedly used as a demonstration strike point, while frontline cities and operational corridors appeared in the mission environment.
The project went beyond theoretical conversations with an AI chatbot.
Anthropic observed software being loaded onto physical development boards, single board computers being configured and simulations being connected through mesh networking. The company nevertheless assessed the systems at relatively early technology readiness levels, generally around TRL 3 to 4, meaning they had been validated primarily through simulation and experimental development rather than demonstrated as an operational combat swarm.
That distinction is important. Anthropic’s findings demonstrate an attempt to build autonomous weapons technology with AI assistance, but they do not establish that the developers successfully deployed an operational autonomous drone swarm on the battlefield.
Claude unavailable officially in Russia
The actors also had to circumvent Anthropic’s geographic restrictions.
Claude is not officially available in Russia. Anthropic said the drone developers bypassed those controls by routing their traffic through commercial virtual private servers. Their accounts were created between late 2025 and early 2026, with the drone project beginning in mid May 2026.
Anthropic said accounts associated with the malicious operations were banned and additional monitoring measures were introduced.
The company has also deployed new classifiers intended to identify and block requests associated with explosives and weapons development.
AI capabilities are moving into military territory
The report arrives alongside new research from Anthropic examining how capable frontier AI systems have become in intelligence and conventional weapons related tasks.
The company’s Frontier Red Team found that, for some military and intelligence tasks, advanced models can now perform work that historically required highly trained specialists. Anthropic specifically tested areas such as locating targets from fragmented intelligence and assisting with engineering problems related to drone weapons.
That does not mean an AI system can independently build an advanced military capability from beginning to end. Human operators, physical hardware, training data, engineering expertise and testing infrastructure remain important.
But the Russian linked cases demonstrate how AI can potentially compress parts of the development cycle.
Code generation, intelligence collection, malware development, image classification, simulation, documentation and troubleshooting can increasingly be assisted by the same general purpose model.
A new dimension of AI security
The broader significance extends beyond Russia.
Anthropic’s September report documents attempted misuse of Claude by actors from several countries and across multiple weapons and intelligence related projects. The company said the patterns observed on its own platform are relevant to the wider challenge facing frontier AI developers.
The Russian cases nevertheless provide a particularly striking example of how several previously separate domains are beginning to converge.
Cyber espionage can obtain information about drone technology. Generative AI can help analyse that information. Computer vision can contribute to target recognition. AI coding systems can accelerate development of autonomous control software. The same class of technology can also support influence operations aimed at shaping political narratives abroad.
For governments, defence companies and AI developers, that convergence creates a rapidly evolving security challenge.
The question is no longer simply whether artificial intelligence can generate propaganda or help hackers write malicious code. The emerging issue is how much of an intelligence, cyber or weapons development operation can be connected and accelerated through increasingly autonomous AI systems.
Anthropic’s findings suggest that some actors are already attempting to find out.