
Anthropic Disrupts Midnight Blizzard's Claude-Assisted Reverse-Engineering of Ukrainian Drone SDK
Anthropic's report details Midnight Blizzard's Claude use for drone SDK analysis and rapid implant modification, exposing how frontier models compress adversary OODA loops. Evidence shows cost inversion favoring attackers with access to commercial AI. This pattern aligns with broader state adoption of LLMs for supply-chain targeting.
Anthropic observed the group, linked to Russia's SVR, pivot from initial mailbox access to full extraction of product architecture, hardware BOM, supplier data, and unannounced firmware details. The operators then queried Claude to map AI vision components and test implant evasion against security products, redeploying modified artifacts within hours of detection. Technical logs show repeated queries on military drone control firmware.
Anthropic: Midnight Blizzard will publish at least two additional Claude-assisted zero-days against security tooling within 120 days.
Sources (2)
- [1]Anthropic Threat Intelligence Report(https://therecord.media/anthropic-russia-hackers-claude)
- [2]Microsoft Storm-2945 Analysis(https://www.microsoft.com/security/blog/2025/midnight-blizzard-storm-2945)