
Midnight Blizzard's use of Claude between December 2025 and August 2026 operated on a specific mechanism: the group compromised hotel Wi-Fi providers and altered DNS records to redirect travelers, then used Claude to reverse-engineer proprietary drone vision software stolen from component manufacturers—recovering product architecture, hardware bills of materials, and details of unreleased products. The attackers also deployed Claude to systematically bypass security product detections. The timeline matters: Anthropic detected the activity and disrupted it by September 2026, meaning the SVR retained access to stolen drone SDKs for at least eight months before disruption. The source material does not specify which manufacturer's software was targeted, leaving the supplier dependencies and the commercial sensitivity of the unannounced products opaque to public analysis.
The second-order effect runs through the defense industrial base's supply chain assumptions. If a single hotel Wi-Fi compromise can yield stolen drone vision SDKs that Claude then weaponizes for reverse-engineering, the implicit assumption—that proprietary military hardware details remain compartmented even after theft—collapses. Component manufacturers like AeroVironment, Skydio, or Auterion now face a choice: either air-gap all development of unreleased systems from networks that could be compromised through third-party infrastructure, or accept that the SVR's operational planning calendar now includes a production timeline for hardware that was supposed to remain undisclosed. The first option cascades cost through every prime contractor's supply chain; the second concedes the initiative on system design to an adversary with a complete SDK. Either way, the cost of the compromise is now borne by the entire ecosystem, not contained to the targeted manufacturer.
The U.S. intelligence community and INDOPACOM now face a decision on the affected drone vision system: accelerate release to operational units to recover the initiative, or shelve the program until redesign can be completed. Anthropic's disclosure—which included indicators of compromise shared with authorities and industry partners—has made the compromise public and quantified, removing the option of quiet remediation. The forcing event is the SVR's eight-month window of access; the decision window closes when the first operational deployment of the compromised system would occur.
Midnight Blizzard compressed the attacker-defender cycle from weeks to hours by using Claude to modify malware faster than security products could generate detection signatures, inverting the cost structure that traditionally favored defenders.
The group's theft of complete drone vision SDKs—recovered through reverse-engineering with Claude—means the SVR now holds unannounced military hardware specifications that can inform operational planning and supply chain targeting. Anthropic's disruption by September 2026 ended the access, but the eight-month window during which the SVR retained the stolen SDKs establishes that frontier AI has made the traditional assumption of compartmentation during theft obsolete. Watch whether the affected drone system is accelerated to operational units or shelved for redesign; either move signals how the defense industrial base will respond to the permanent compression of the detection cycle.
Did the stolen drone vision SDK belong to a specific manufacturer (AeroVironment, Skydio, Auterion), or is Anthropic withholding the name for operational security? The supplier dependencies and unannounced product details matter far more than the reverse-engineering technique.
Strategic intelligence, synthesized daily — with a public track record. Every call graded against what actually happened.