GTG-87001 is Anthropic’s designation for an alleged northern Yemen-based weapons-development cell. The cell was reportedly associated with three parallel guided-weapons programs and use of Claude Code for guidance, navigation, and control engineering, including flight-control and position-estimation development, parameter tuning, firmware builds, and simulation. Reported projects included a guided rocket, a multistage ballistic-missile concept, and the R2000 missile set. The activity reportedly divided coding, research, and code-review work among separate model sessions and attempted to conceal the weapons purpose of individual requests. Anthropic reportedly blocked many requests and found no evidence that GTG-87001 fielded an operational weapon. Publicly available information does not independently substantiate the attribution, the cell’s real-world weapons activity, or its intent.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A small cell reportedly based in northern Yemen that used Claude Code in parallelized, specialized AI workflows to develop guidance, navigation, control, simulation, and firmware components for guided-rocket and ballistic-missile programs.
A northern Yemen-based cell attempting AI-assisted development of guided rocket, ballistic-missile, and multi-variant missile capabilities. It used multiple Claude Code instances as specialized engineering roles for code generation, research, review, firmware builds, control tuning, and flight simulation. Anthropic reported no evidence that the group successfully fielded an operational weapon.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.