We do not install firmware or provide advice on Kanadka / Overlord / 1001.
If your goal is to maintain a stable connection, reduce drone losses, extend UAV operating range, or work with Autel / DJI / Vampire platforms, see our Wood Station antenna systems.
Go to the catalog →
Get equipment advice →
Anonymization of DJI Series 3, 4, and 5 Drones
Remote ID: A Threat in Modern Warfare
Aviation regulators around the world, including the FAA and EASA, first developed the concept of Remote Identification. The EU and the United States subsequently adopted it.
In April 2019, the European Union Aviation Safety Agency (EASA) introduced drone identification requirements that included Direct Remote ID (Direct Remote Identification) across the European Union.
On December 16, 2019, the FAA published a Notice of Proposed Rulemaking (NPRM) on Remote ID—a formal proposal of remote drone identification rules for public comment. On January 15, 2021, Remote ID was published in the United States as an official FAA regulation.
Thus, beginning in early 2019, Europe and the United States established a regulatory framework governing UAV identification systems.
What did this mean in practice?
All manufacturers of commercial UAVs were required to ensure that every drone began broadcasting a Remote ID message as soon as it was powered on, and that this broadcast could not be disabled. Users (pilots) were required to register UAVs weighing more than 250 grams. Some EU countries also charge an annual fee and require pilots to complete mandatory training before they may operate a UAV. In Finland, for example, this costs €100 per year.
From a technical perspective, the Remote ID messages transmitted by a UAV are used for:
-
identifying UAVs in the airspace;
-
monitoring flights in restricted areas;
-
improving situational awareness for air traffic controllers and law-enforcement agencies;
-
subsequent incident analysis.
What information does a Remote ID message contain?
DJI and Autel identification messages may contain the drone's unique identifier (ID), current GPS coordinates, flight altitude, speed, direction of travel (heading), flight status, takeoff point (Home Point) coordinates, the operator/controller coordinates, UAV type and model, timestamps, and system-status flags.
Depending on the UAV model and operating mode, some of this information may not be transmitted. In most cases, however, all of it is broadcast. In practice, as soon as the drone is switched on, it begins broadcasting a data packet that reveals the takeoff location, the operator's position, and other information.
On Autel drones, this can be disabled using military firmware such as Overlord. Autel is relatively straightforward in this respect. With DJI, the situation is much more complicated: the feature cannot simply be turned off in the settings. Using a drone “out of the box” in a war zone is extremely risky and puts lives at risk.
If a DJI drone broadcasts so much information, how can that information be received and used to display the drone's location on a map?
Back in 2017, long before mandatory standards were introduced, DJI implemented its own proprietary identification system. DJI AeroScope was presented in 2017 as an enterprise and government solution. AeroScope is not an ASTM or EN standard; it is part of DJI's closed ecosystem and is designed around the company's proprietary communication protocols. Essentially, DJI developed both the drones and a system capable of identifying only its own drones in the air. This is useful, for example, at airports or stadiums during large public events.
DJI AeroScope is a passive radio-monitoring system designed to receive, demodulate, and decode the service radio messages that DJI drones broadcast as part of the standard communication protocol between the unmanned aircraft and its remote controller.
AeroScope does not establish a connection with the drone, transmit control commands, or interfere with the control link. The system operates exclusively in receive-only (RX-only) mode. It passively receives and decodes service radio messages that the drone itself broadcasts using DJI's proprietary communication protocol.
Solutions are now available that can receive and parse Remote ID messages, displaying all the information transmitted by a UAV—and this is not limited to DJI drones.
Brief Summary
Once powered on, any DJI drone begins broadcasting a large amount of information that the enemy can obtain using relatively simple equipment. Remote ID transmission cannot be disabled in the settings. This is where the term “anonymization” comes into play.
What is DJI drone anonymization?
DJI drone anonymization is a set of measures intended to remove, restrict, or substitute the data transmitted by a DJI drone in its Remote ID packet so that the takeoff point, operator/controller location, and aircraft position on the map cannot be identified.
What solutions are currently available?
These solutions can broadly be divided into several categories. Each emerged at a particular point in time and was adapted to specific drone models because DJI continuously improves and modifies its aircraft.
Anonymization is based on one simple principle: if we cannot disable the transmission of the aircraft, controller, or Home Point coordinates, we can substitute the initial coordinates on which all subsequent positioning data is based. For example, the drone may set a Home Point with zero coordinates. It continues broadcasting the same information, but with an offset. AeroScope can no longer determine the aircraft's actual position. However, if AeroScope detects such a drone, it is still possible to say with confidence that the aircraft is within the coverage area of the AeroScope antennas, which may range from 1 to 25 km depending on the system configuration.
How is the coordinate offset produced, and what does Home Point have to do with it?
Home Point is the location to which the drone returns if it loses its connection to the remote controller, provided this behavior is enabled in the settings. There is an important detail: after a DJI drone is powered on, if it has not obtained coordinates and has not marked a Home Point on the map, its flight altitude and range are restricted. Depending on the model, the limit is between 30 and 50 meters. In other words, the drone must receive at least some coordinates before it can fly normally. Under heavy GPS jamming, the aircraft may be unable to obtain any coordinates at all. Does that mean it cannot fly farther than 50 meters? Yes—if it is a drone operating with factory settings.
The first widely used solution that addressed several problems at once was known as “Kanadka.” It allowed the drone to set a Home Point and remove the 50-meter range restriction, shifted the coordinates used as AeroScope's reference point, and enabled FCC mode.
FCC and CE are standards that limit maximum transmission power, measured in dBm. FCC is the US standard and permits greater transmission power than CE, the European standard. It also permits operation on the 5.8 GHz band. In most EU countries, UAV operation on 5.8 GHz is prohibited, and only 2.4 GHz may be used.
Does this mean a DJI drone also needs a Home Point to determine which permitted frequency bands the controller-to-drone link will use, as well as its data-transmission power? Yes.
“Kanadka” is a solution that, during the drone's initial startup, feeds the aircraft the coordinates we want it to use instead of coordinates received from actual satellites. Many variants exist today, including Kanadka, Mohnolka, Avstraliika, Bolotka, and others. They are also implemented in different ways: using chips, ribbon cables, Arduino boards, and so on. There are many “manufacturers,” if they can be called that, and each keeps the exact operating principle of its solution secret. A Kanadka can be thought of as a small circuit board. Installing it requires physically disassembling the drone and connecting the board to the GPS module.
Disadvantages of “Kanadka-type” and similar solutions:
-
physical intervention is required, and the drone must be disassembled;
-
installation is generally performed only in specialized workshops;
-
some workshops do it free of charge, while others charge between $50 and $150 per aircraft;
-
there is always a waiting list, and the drones must be shipped or taken to the workshop.
These, however, are merely practical inconveniences related to organizing the work. There is one drawback that almost everyone remains silent about: the architecture of every solution commonly described as a “Kanadka” neither disables the drone's GPS module nor allows the GPS antenna to be removed from the aircraft.
The drone's GPS remains active at all times. This is the principal problem that began to surface in 2026. It is causing the loss of Kanadka-equipped aircraft for reasons that operators do not even consider as possible causes. For now, this has primarily been occurring in rear areas, where operators do not expect it at all. Can a drone equipped with a Kanadka still receive real coordinates from real satellites? Yes, under certain conditions—specifically, if the GPS signal is sufficiently strong. The signal received from actual GPS satellites is typically around −130 to −120 dBm, essentially at the noise-floor level. A powerful spoofing signal (substituting false GPS coordinates), however, may exceed 0 dBm depending on the distance between the UAV and the spoofing source. Given the characteristics of navigation-system frequency bands, the effective distance may be tens of kilometers.
This raises a second question: can GPS be disabled on the drone?
Yes. This can be done using the so-called 1001 firmware. The name dates back to the release of updated stock firmware numbered 1000 for Mavic Series 3 aircraft. No better name was devised, so the modified firmware was called 1001. This firmware allows the operator to send a command from the UAV controller that disables the GPS module. The display then shows zero satellites in white, meaning the drone does not treat the condition as an error. We will not discuss the exact method used, but the fact remains: the GPS module is genuinely disabled and can be re-enabled just as quickly by the operator.
Disabling GPS is not the only advantage of the 1001 firmware. When the drone is powered on, a Home Point is set automatically; altitude and flight-range restrictions are removed (a feature particularly relevant to Series 3); and, if the controller link is lost, the aircraft automatically climbs to a preset altitude of 500 or 1,000 meters in an attempt to leave the electronic-warfare coverage area and increase the chance of restoring the control link. It also provides many other useful features that genuinely help reduce drone losses.
Where was this firmware installed?
Usually, it was installed in the same workshops that had previously fitted Kanadka devices. The timeline was roughly as follows. In Bakhmut in early summer 2023, the first Kanadka solutions for Series 3 appeared. For several months, developers were unable to produce a Kanadka for the Enterprise series—the Mavic 3T and 3E. A working version was eventually released closer to autumn. The 1001 firmware then appeared in November and became widely used in early 2024. A system of firmware “boxes” was organized, and under the banner of one of Ukraine's best-known charitable foundations, access began to be controlled: decisions were made about who would and would not be allowed to install the firmware on drones.
Later, 1001 firmware was released for the Mavic 3T and 3E. Demand for Kanadka devices fell sharply, and Kanadka installers effectively took a year off. On January 8, 2025, DJI unveiled the Matrice 4. Everyone became active again and began adapting Kanadka devices from the Mavic 3T for the Matrice 4. By May, Matrice 4 aircraft equipped with Kanadka devices were already being deployed. But alongside the Matrice, DJI released the Mavic 4 Pro—and that is where the problems began.
We will not go too deeply into the technical details. DJI Series 3 had numerous security vulnerabilities, which could be exploited to make firmware modifications possible in the first place. The process was fairly complex internally but simple for the end user, and it worked. DJI was presumably aware of this and had already started changing the embedded software in the Mavic 3 Pro—the final aircraft in the standard Series 3 lineup—which caused temporary complications.
Summary
For DJI Series 3, the relevant anonymization solutions were initially Kanadka-type devices and later the 1001 firmware. Once the firmware became available, Kanadka devices almost ceased to be used: the firmware offered more benefits, did not require the drone to be disassembled, and could be installed quickly and free of charge.
Today, however, the only DJI Series 3 aircraft still readily available on the market in quantity is the Mavic 3TA. Finding other new Series 3 drones in quantity is now almost impossible. It is also time to begin properly tracking the firmware installed on each aircraft, identifying responsible personnel, and preventing drones intended for the Armed Forces of Ukraine from being resold on OLX.
DJI Mavic 4 Pro and Matrice Series 4 and 5
What is wrong with these drones from an anonymization perspective?
The problem is that DJI is constantly changing and improving its products. For example, in Series 3, the GPS module could be moved from one drone to another without difficulty and everything would continue to work. In Series 4, that approach no longer works; reflashing is required.
Solutions developed for Series 3 are therefore unsuitable for Series 4. Even the Kanadka was not easily adapted from Series 3 to Series 4, and the resulting solution has shortcomings. A 1001-type firmware solution for Series 4 is extremely difficult to achieve; technically, it is almost impossible without DJI's assistance.
What solutions are available for DJI Series 4 and 5?
Matrice 4: a Kanadka-type solution, with issues that vary depending on the workshop. It is still too early to discuss firmware, although some options exist.
Mavic 4 Pro: a Kanadka-type solution, most likely also with issues, installed by only a limited number of workshops.
DJI Series 5: not used by the military; these are tiny, lightweight aircraft.
What do we mean by a “Kanadka with issues”? The answer is simple: the architecture of every Kanadka-type solution fails to disable the drone's GPS module completely. That is the fundamental flaw. With “properly” executed spoofing, the GPS module can be overwhelmed and the drone spoofed, resulting in a 99.9% probability of losing the aircraft within seconds. Moreover, the latest spoofing methods cause behavior that UAV operators do not recognize as spoofing because they are accustomed to entirely different symptoms and explanations for aircraft losses caused by spoofing.
Video: How a Kanadka-equipped drone behaves under spoofing.
Operators who have encountered the drone behavior shown in the video have lost the aircraft. As a rule, they attributed the loss to almost anything—motor failure, ESC failure, icing, software error, and so on—but not to spoofing.