Russia's APT29 used Claude to reverse-engineer drones, evade detection
Adversaries now use frontier AI to defeat detection faster than defenders can deploy it, the inversion Five Eyes warned about is here.
TL;DR
Anthropic confirmed Thursday that Russia's SVR-linked APT29 used Claude to reverse-engineer stolen drone firmware and evade security detections across more than 20 government, intelligence, and defense targets between December 2025 and August 2026. The group compromised hotel Wi-Fi providers, redirected travelers via DNS tampering, stole a complete drone vision SDK from two component manufacturers, then used Claude to map product architecture, hardware bill of materials, and supplier dependencies. When security products flagged implants, operators used Claude to modify and redeploy detected artifacts faster than defenders could respond, the first public evidence frontier AI has inverted the defender cost curve, validating the Five Eyes warning from June that the timeline was months, not years.
The Five Eyes warning landed in June: frontier AI would transform offensive cyber before defense caught up, and "the timeline is not years, it is months." Anthropic confirmed Thursday the timeline has already elapsed. Russia's SVR-linked APT29 used Claude for nine months to do two things defenders can't yet match at scale.
Between December 2025 and August 2026, the group targeted more than 20 government, intelligence, diplomatic, and defense organizations. It compromised hotel Wi-Fi providers and altered DNS records to redirect travelers, a technique Microsoft tied to Storm-2945, a Midnight Blizzard sub-cluster. From two drone-component manufacturers, the spies stole mailboxes and then a complete proprietary SDK for a drone vision system.
Drone firmware on the table
Claude wasn't peripheral. Anthropic's threat report describes the AI being used to recover the drone vision system's product architecture, hardware bill of materials, supplier dependencies, and details of an unannounced product. "Military drone control and AI vision-related firmware appeared to be of particular interest." This is industrial espionage at a resolution that would normally require specialized reverse-engineering talent and weeks of labor. Claude compressed that timeline to hours. For defense contractors in the drone supply chain, the implication is straightforward: stolen firmware is now actionable by adversaries before the victim knows it's gone. The old assumption (that exfiltrated binaries require months of human analysis to yield useful intelligence) no longer holds.
Detection evasion at machine speed
The second use of Claude carries broader consequences. When security products flagged APT29's implants, operators directed Claude to "systematically identify, modify and redeploy the detected artifacts." Anthropic's own conclusion is blunt: "AI has inverted the cost back onto defenders." Previously, a new detection might slow an attacker. Now adversaries can close the loop, bypassing detections faster than defenders can deploy them. The "in theory" qualifier is now observational.
The same report documented other misuse. ShinyHunters affiliates used Claude to go from a stolen developer token to full cloud administrative access in roughly three hours. A Chinese-speaking group ran an autonomous vulnerability research program that found multiple zero-days in a major security product. A French-speaking hacktivist targeted European political parties and think tanks. The common thread: AI narrows the gap between state-backed groups and smaller operators. Phishing, stolen credentials, exposed services, and software flaws remained central to successful intrusions, Claude didn't replace those techniques, it accelerated what happens after initial access.
Anthropic disrupted the activity and shared indicators of compromise. The report doesn't answer the question CISOs at defense contractors will ask Monday, though: if an adversary with a legitimate account uses the same tool to adapt implants faster than patches can ship, what technical safeguard actually stops that? The disclosure is a public service. It's also an acknowledgment the answer isn't clear.
Published ·Deep Fathom