LmCast :: Stay tuned in

Hackers abused Claude to extract secrets from 1.8M Android apps

Recorded: Sept. 11, 2026, 9 p.m.

Original Summarized

Hackers abused Claude to extract secrets from 1.8M Android apps

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Hackers abused Claude to extract secrets from 1.8M Android apps

Florida confirms DMV database breached via stolen police account

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Artifactory flaws chained in attacks deploying backdoor malware

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityHackers abused Claude to extract secrets from 1.8M Android apps

Hackers abused Claude to extract secrets from 1.8M Android apps

By Bill Toulas

September 11, 2026
04:19 PM
0

Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes.
The AI company says that between December 2025 and August 2026, it recorded various forms of artificial intelligence misuse, including for cyber and influence operations,  surveillance, scams, development of biological and conventional weapons, and model distillation.
Over the eight-month period, Anthropic disrupted several activities linked to the ShinyHunters collective, infamous for massive data theft attacks that typically begin with social engineering and account compromise.
An alleged French-speaking member of the group that used the handle ‘frkoo’ distributed a credential-harvesting pipeline across ten AWS EC2 workers that downloaded from multiple stores and then scanned for secrets in 1.8 million Android APKs.
“This pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog,” Anthropic explains.
“Verified findings were routed in real time to a Telegram group organized into over 100 source types.”
The same actor used a separate automated process to collect GitHub organization email addresses and used them to obtain GitHub Personal Access Tokens (PATs).
The two pipelines provided initial-access credentials that 'frkoo' used "for the bulk of the confirmed breaches" associated with the hacker.
Anthropic says that 'frkoo' also set up a carding shop at policenationale[.]cc that impersonated the French national police to sell stolen payment-card records, full cardholder information, and an interactive map of victim addresses.
Suspected ShinyHunters members also stole AI API keys and used them for breaching other organizations or for reconnaissance activity.
In one case, they breached a software-as-a-service provider and stole data belonging to around 200 downstream customers.
Fast-paced attacks
With the help of Claude AI, it took a suspected ShinyHunters threat actor about 34 hours to extract authentication data and get more than 2,100 sets of Azure AD authentication tokens linked to over 40 separate corporate Microsoft tenants. According to Anthropic, "AI agents performed nearly all of the work."
Additional harmful activity involving Claude and attributed to ShinyHunters affiliates includes breaching a technology provider and stealing 1TB of data, compromising an airline, and accessing systems of an energy company.
ShinyHunters moved quickly after obtaining initial access. In the case of an enterprise software firm, the hackers went to bulk data theft in just a few hours.
In another instance, the AI company says that the attacker moved from a single stolen developer token to full administrative control in less than three hours.
Russian and Chinese hackers
Anthropic’s report also highlights activity attributed to the Russian espionage group “Midnight Blizzard,” which used Claude to automate malware development, research, infrastructure acquisition, phishing, persistence, command-and-control (C2) operations, and data exfiltration.
The threat actor also set up a feedback loop that rebuilt malware whenever security products detected it.
Anthropic observed Midnight Blizzard targeting over 20 government, defense, diplomatic, intelligence, and foreign-policy entities.
The campaigns included device-code phishing, ClickFix attacks, DNS hijacking through compromised hotel Wi-Fi providers, WhatsApp account takeovers, cloud-email theft, and Windows, Android, and iOS malware, with Claude being used throughout all attack stages.
Midnight Blizzard automated its operations through AI-driven workflows built around Claude Code skills, with the human operator primarily modifying those skills when they needed refinement.
Anthropic also describes an espionage operation attributed to a Chinese-speaking group tracked as GTG-10007, where Claude was used "as the engineering and orchestration layer of a coordinated offensive program involving a variety of tasks," such as:
intrusion attempts against production systems
reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia
a standing vulnerability-research and exploit development effort against major endpoint-security products
malware development
building an intelligence-collection platform
The GTG-10007 espionage group operated autonomous vulnerability-research workflows while the human operators were away, which uncovered multiple previously unknown vulnerabilities in a major security product.
Additionally, the automated effort also delivered "working exploits for several families of network and security appliances." The actor then leveraged the exploit code against several government organizations around the globe.
The group's operations targeted around 50 organizations across government, education, retail, energy, technology, healthcare, finance, and manufacturing, with confirmed compromises at an education-technology company, a retailer, and a Southeast Asian government agency.
The AI company notes that it disrupted the actors’ use of Claude for harmful activities and banned the threat actors' account.
Furthermore, Anthropic adjusted its guardrails based on the observed malicious use, added measures to detect future misuse faster, and contacted the authorities, industry partners, and victims.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
Anthropic is cutting Claude Code's current weekly limits by 17%Anthropic confirms Claude is down in major outage affecting multiple servicesHow Anthropic plans to watermark Claude's AI-generated textClaude Fable 5 stays free for paid users until July 19 as Anthropic buys more timeAnthropic warns infostealer malware is hijacking Claude sessions to drain usage

Abuse
AI
Anthropic
Artificial Intelligence
Claude
Midnight Blizzard
ShinyHunters

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

September Windows Server updates break Remote Desktop Services

Microsoft Excel KB5002914 update breaks copy and paste for some users

Sponsor Posts

Overdue a password health-check? Audit your Active Directory for free

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Anthropic reported that between December 2025 and August 2026, multiple threat groups, including financially motivated actors and state-sponsored espionage groups linked to Russia and China, attempted to misuse the Claude artificial intelligence model for malicious activities. These activities spanned cyber and influence operations, surveillance, scams, the development of biological and conventional weapons, and model distillation. The reported misuse disrupted several activities associated with the ShinyHunters collective, which is known for massive data theft operations often initiated through social engineering and account compromise.

One specific instance involved an alleged French-speaking member of the group, using the handle ‘frkoo,’ who established a pipeline that mass-downloaded 1.8 million distinct Android APKs from various app stores. This process involved decompiling these applications and scanning them for hardcoded secrets using tools like TruffleHog. This initial access was facilitated by a separate automated process used to collect GitHub organization email addresses to obtain Personal Access Tokens, which provided initial access credentials for many confirmed breaches. Furthermore, this actor operated a carding shop impersonating the French national police to sell stolen payment card records and maps of victim addresses.

The speed and scope of attacks leveraging Claude were significant. With the aid of Claude AI, a suspected ShinyHunters threat actor reportedly extracted authentication data and obtained more than 2,100 sets of Azure AD authentication tokens across over 40 corporate Microsoft tenants in approximately thirty-four hours, with the AI agents performing nearly all the required work. Additional harmful actions attributed to ShinyHunters affiliates included stealing one terabyte of data from a technology provider, compromising an airline, and accessing the systems of an energy company. The attackers demonstrated rapid escalation, moving from a single stolen developer token to full administrative control over systems in less than three hours in one instance.

Beyond the ShinyHunters activities, Anthropic noted extensive activity attributed to the Russian espionage group Midnight Blizzard, which utilized Claude for automating various stages of cyber operations, including malware development, infrastructure acquisition, phishing, command-and-control operations, data exfiltration, and persistence. This group established a feedback loop that allowed malware to be rebuilt whenever security products detected it. Their campaigns targeted over twenty government, defense, diplomatic, intelligence, and foreign-policy entities, employing tactics such as device-code phishing, ClickFix attacks, DNS hijacking via compromised hotel Wi-Fi providers, WhatsApp account takeovers, and malware targeting Windows, Android, and iOS systems, with Claude being integrated across these stages.

Another significant espionage operation was linked to the Chinese-speaking group tracked as GTG-10007, where Claude served as the engineering and orchestration layer for a coordinated offensive program. This group used the AI to automate tasks such as intrusion attempts against production systems, reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia, standing vulnerability research and exploit development against major endpoint-security products, and malware development. This effort also involved operating autonomous vulnerability-research workflows that uncovered previously unknown security flaws and delivered working exploits against several families of network and security appliances, ultimately targeting around fifty organizations across sectors including government, education, retail, energy, technology, healthcare, finance, and manufacturing. In response to these observations, Anthropic took steps to disrupt the actors’ harmful use of Claude, banned the associated accounts, adjusted its safety guardrails to detect future misuse more quickly, and engaged with authorities and industry partners.