Russians, Chinese and Yemenis: Anthropic reveals how its AI is misused in warfare

Russians, Chinese and Yemenis: Anthropic reveals how its AI is misused in warfare

Ondřej Barták
Ondřej Barták
Entrepreneur and Programmer
14. 9. 2026
6 minutes reading · 4 views
Listen to the article
Audio version of the article
Russians, Chinese and Yemenis: Anthropic reveals how its AI is misused in warfare

American company Anthropic has published an extensive report on how people misuse its Claude model. Eight months of monitoring uncovered cases ranging from fraudulent dating sites to the surveillance of dissidents. However, the most serious section concerns weapons. In the chapter on conventional weapons, the company describes six cases from Russia, China, and Yemen. In four of them, people used artificial intelligence directly to develop software for weapons systems. The most advanced was the case designated GTG-27005, in which the model itself was supposed to select a target and issue the command to detonate.

Russia: a drone swarm that was supposed to select its own targets

According to Anthropic, the project, which its creators called DronDoc or Serafim, was developed by a small team of developers from Russia, probably independent freelance programmers. It was therefore not the Russian state, although the developers themselves claimed that their work was funded by Russia's Advanced Research Foundation, the National Technology Initiative program, and the Ministry of Defense. Anthropic adds that it was unable to verify these claims.

The goal was a complete system for a swarm of FPV kamikaze drones, small aircraft that a pilot controls from a camera's point of view and that dive toward a target while carrying an explosive charge. Claude Code helped them write and test the software. This included a program that enabled the drones to communicate and coordinate with one another. It also helped with guidance during the final phase of flight, locating enemy drone operators, and controlling onboard systems.

The turning point came when the work shifted from ordinary programming assistance to autonomous decision-making. The onboard model was supposed to be small enough to fit on a single-board computer while also being capable enough to select a target on its own. One of the categories was a person. The system was supposed to issue the detonation command without human involvement. And it did not remain merely code on a screen. Investigators observed that the group was uploading software to actual development boards, preparing single-board computers, and connecting the individual components. However, the system remained at an early stage and was tested mainly in simulation, so according to Anthropic, it never reached the battlefield.

Training on footage from Ukraine

Part of the work involved training computer vision. The team used footage of fighting in Ukraine downloaded from the internet and divided military equipment into friend and foe categories, classifying Russian systems as permitted objects. Investigators noticed one more thing. Specific coordinates in the Donetsk region repeatedly appeared in the project as a sample attack location, while front-line cities and corridors in Ukraine served as areas for planned missions.

Anthropic ultimately found nine accounts linked to this group. Eight of them were used only for ordinary contract work unrelated to weapons software. The investigation also indicated ties to a regional university and a federal research center affiliated with the Russian Academy of Sciences.

China: jammers and a list of targets in Taiwan

The second set of cases leads to China. One user, whom Anthropic assesses to be a researcher in the defense and military industry, used the Claude model to build a suite of tools for electronic warfare and the suppression of air defenses.

The software analyzed radars, surface-to-air missile positions, and command posts, then ranked the targets by priority and calculated how to allocate jammers among them. During the work, the scenario shifted to twelve targets in Taiwan, including air bases, a command bunker, and Patriot and Tien Kung system batteries. According to Anthropic, this user had ties to Chinese research institutions, including the People's Liberation Army Academy of Military Sciences.

Another user from China worked on an anti-torpedo fire-control system and had the model generate a technical design of more than two hundred pages. Anthropic links the user to a Chinese defense company that wanted to prepare a weapon specification and a bid for a Chinese navy tender.

Yemen: a missile failed, and then came the query

The report's third focus is northern Yemen. A local group of weapons engineers used Claude Code while working on a cruise missile, a ballistic missile with a stated range of more than two thousand kilometers, and a missile program that was also supposed to include a version with a hypersonic glide vehicle. The group launched a test cruise missile, the test apparently failed, and within several hours the engineers returned to the Claude model to ask for help identifying the cause.

Technology theft from drone manufacturers

Espionage forms a separate chapter. A group that Anthropic tracks as GTG-20006 and links to activity described by other companies as Midnight Blizzard attacked military and intelligence targets in Ukrainian and European government agencies, diplomatic missions, and defense companies. In total, more than twenty organizations appeared in its plans and operations.

Ukraine's drone industry was repeatedly targeted. The attackers exported entire mailboxes belonging to at least two manufacturers of drone components, targeted a military drone manufacturer, and stole a complete software development kit for a machine-vision system for unmanned aircraft. They then spent several days analyzing it, obtaining the product architecture, a list of the hardware used, a supplier list, and information about a product that had not yet been unveiled.

They also reached victims indirectly. They compromised at least three providers of hotel wi-fi networks and redirected guests' traffic to their own servers, from which they sent malware to their phones and laptops. They prioritized people connected to Ukraine, including officials and drone manufacturers. They took over the WhatsApp accounts of at least two former senior Ukrainian officials and quietly downloaded their conversations.

Claude handled almost the entire course of the attacks, from preparing and sending fraudulent emails through stealing login credentials to processing hundreds of gigabytes of stolen data. When security software detected their malware, the attackers kept modifying and rebuilding it until it became completely undetectable.

Anthropic's response

Anthropic blocked all the accounts described, incorporated the findings into its safeguards, and shared the information with authorities and industry partners. The company emphasizes that the selected cases do not represent typical model use, but rather the most serious activity encountered by its team. The company also states that its models are gradually improving in tests involving tactical intelligence tasks and conventional weapons development. In response to this report, Anthropic CEO Dario Amodei called for slowing the development of advanced models.

The Russian developers did not work exclusively with the Claude model. They had their own project files, simulation environment, and rented computing power for training models. Claude represented only one part of a larger whole. Although the company can block accounts on its own platform, doing so will not stop the work itself.

The American response has so far remained muted. Shortly after the second Trump administration took office, Attorney General Pam Bondi disbanded the FBI team focused on foreign influence operations, and Secretary of State Marco Rubio shut down a similar unit at his department two months later.

Sources: anthropic.com, theguardian.com and businessinsider.com

Advertisement

Content created with help from UpTier.

SEO and GEO on autopilot. UpTier’s multi-agent systems write and optimize content for search engines and AI answers.

Discover UpTier ↗

Did you enjoy this article?
Discover more interesting posts on our blog
Back to blog

Related posts

Anthropic Blocked Possible Attempts to Develop Biological Weapons Using Its ModelsAnthropic Blocked Possible Attempts to Develop Biological Weapons Using Its Models
Anthropic uncovered five cases in which scientists used Claude to plan research that could potentially be used for biological weapons. The company intervened, although it could not determine their true intentions.
5 min read
15. 9. 2026
Pentagon Admits Using Musk’s Grok for Strikes on IranPentagon Admits Using Musk’s Grok for Strikes on Iran
What happens when artificial intelligence gains direct influence over where missiles land? We are now finding out in real time in Iran. The Trump administration used Elon Musk’s Grok AI to help target strikes.
4 min read
18. 6. 2026
US Used Claude to Identify More Than 1,000 Targets in Iran AttackUS Used Claude to Identify More Than 1,000 Targets in Iran Attack
When the US and Israel launched a massive military operation against Iran in early March, the world watched in astonishment as the numbers emerged. Nearly 900 strikes in the first 12 hours. More than 1,000 targets hit
5 min read
10. 3. 2026
Přihlaste se k odběru našeho newsletteru
Zůstaňte informováni o nejnovějších příspěvcích, exkluzivních nabídkách, a aktualizacích.
CodedTrip

Operated by CodedTrip LLC, USA.

YouTube
TikTok