Safety2 min read

Russian Coders Used Claude AI to Build Attack Drones

By , Senior AI ConsultantPublished

Anthropic's new safety report found a freelance Russian team used its Claude AI to help build self-targeting kamikaze drones, while a separate Russia-linked hacking group used AI to auto-rewrite malware until it beat security software, a shift that raises the bar for any company's cyber defenses.

Anthropic just published its fourth report on how people misuse its Claude AI chatbot, and the most striking case involves a small freelance team in Russia that used Claude to help build software for a swarm of attack drones. These drones were designed to fly toward a target, choose it themselves, and crash into it to detonate, with no person making the final call to strike.

The team tested code on real drone hardware and trained a computer vision system using combat footage from Ukraine, sorting equipment into enemy and friendly categories. They kept aiming their tests at one location in Ukraine's Donetsk region, and got around Anthropic's country restrictions using VPNs. Anthropic believes this was a small group of specialists, possibly linked to a university and a research center, not an official state weapons program.

That last detail matters more than it might seem. A handful of freelance developers, using a commercial chatbot anyone can sign up for, got close to building an autonomous targeting system. A few years ago, that kind of capability required a defense contractor and a dedicated engineering team. Now it requires a laptop, some drone parts, and enough persistence to dodge a company's safety filters.

The report's second major finding is arguably more relevant to any business reading this. A hacking group whose methods match Midnight Blizzard, a unit the US government has tied to Russian intelligence, used AI to test its own malware against security software and rewrite the code automatically every time it got flagged. It repeated that cycle until the malware stopped getting caught. That is a genuine shift. Security software has always relied on a simple trade: attackers write a tool, defenders spot it and block it, attackers rewrite it, and the cycle repeats slowly enough that defenders usually stay ahead. AI collapses that cycle from days into minutes, and it does not care whether the target is a Ukrainian ministry or a private company with weaker defenses.

The same group also hijacked hotel guest WiFi to plant malware on travelers' devices and took over WhatsApp accounts belonging to former Ukrainian officials. Neither trick requires a nation-state budget. Business travelers connecting to hotel WiFi, and executives who run company business over WhatsApp, are exactly the kind of targets this method is built for.

Anthropic banned the accounts involved and says it shared its findings with authorities and other AI companies. That is the right response, but it only works after the damage has started. For any company that depends on email, messaging apps, or public WiFi, which is to say nearly every company, the lesson is not about drones. It is that AI has already changed the speed of cyberattacks, and the defenses most businesses run today were built for the slower version of that fight.


STAY INFORMED

Get AI intelligence like this delivered to your inbox.

Free forever · Unsubscribe anytime


You May Also Find Valuable