Russia repurposes Claude for autonomous drone targeting and scalable influence ops

Anthropic says Russian-linked actors used Claude to prototype edge AI for autonomous target selection and to scale cyber and disinformation operations—trends with direct implications for NATO and European elections.

Share
Illustrative military quadcopter drone with onboard computing module, overlaid with code and social-media interface graphics.
Illustrative military quadcopter drone with onboard computing module, overlaid with code and social-media interface graphics.

Key facts

  • Anthropic says Russian-linked GTG-27005 used Claude to help build a compact model for single-board computers enabling target selection (including “person”) and autonomous detonation commands without human-in-the-loop
  • Anthropic reports the group also used Claude to develop drone-to-drone communications software to improve targeting; it was not fielded but involved hardware-in-the-loop testing
  • Anthropic says Claude was used in cyber/data-theft and disinformation operations, including building fake personas and news sites, streamlining phishing-to-exfiltration workflows, and document forgery

3 minute read

Anthropic’s latest threat-disruption disclosure asserts that Kremlin-backed actors have attempted to weaponise its Claude model across three mutually reinforcing mission sets: autonomous drone targeting, cyber intrusion tradecraft, and influence operations. The most operationally salient claim concerns a Russian “freelance” cluster tracked as GTG-27005, which allegedly used Claude to develop a compact AI model intended to run on single-board computers—implying a focus on low-cost, distributed edge autonomy. Anthropic says the design goal was a drone capable of selecting targets, including a “person” target class, and issuing detonation commands without a human in the loop. The same cluster reportedly used Claude to write software enabling autonomous drones to communicate with one another to improve targeting. Anthropic states the capability had not yet been deployed to the field but that the group conducted “real hardware-in-loop testing” during the activity it observed.

Beyond kinetic autonomy, Anthropic describes Claude being used to industrialise cyber and influence workflows: target research, vulnerability identification, malware development to bypass security controls, operational security to avoid detection, and end-to-end content production. The company reports observing the creation of networks of fake social media profiles and entire news sites, echoing established Russian tactics such as fabricated journalist personas and local-language outlets used to launder narratives about NATO activity, including in the Baltic region. The key change, per Anthropic, is scale and believability—AI streamlining infrastructure acquisition, phishing, persistence through command-and-control, and data exfiltration, while also improving the plausibility of synthetic “reporters” and documents. Anthropic also notes document forgery activity attributed to Russian-linked groups, including forged materials purporting to be from Central African Republic security institutions.

For European defence and homeland-security stakeholders, the implication is less about a single “killer drone” breakthrough than the convergence of cheap autonomy with cognitive warfare. If small, edge-deployable models can be rapidly iterated with AI assistance, European forces should expect faster adversary adaptation in FPV/drone swarms, counter-UAS deception, and target-recognition tuning for contested environments. In parallel, the described influence toolchains map directly onto European vulnerabilities: election interference, mobilisation against NATO posture, and the erosion of trust in military movements and procurement decisions. The report also highlights a policy asymmetry risk: even where frontier labs detect and disrupt abuse, hostile actors can recycle techniques across models and platforms, pushing Europe toward a posture that treats AI-enabled manipulation and autonomy as a persistent, scalable feature of Russian operations rather than episodic incidents.

Source: Defense One