Hackers abused Claude to extract secrets from 1.8M Android apps

In a comprehensive threat intelligence report released this September, artificial intelligence firm Anthropic has unveiled the findings of an intensive eight-month investigation into the malicious exploitation of its Claude AI model. The report, which covers activity observed between December 2025 and August 2026, details how a variety of sophisticated threat actors—ranging from financially motivated cybercriminal collectives to state-sponsored espionage groups linked to Russia and China—have attempted to weaponize generative AI to streamline and accelerate their offensive operations.
The findings mark a significant turning point in the intersection of cybersecurity and artificial intelligence. Anthropic’s internal telemetry reveals that AI is no longer merely a theoretical risk but a functional component in the tactical arsenals of malicious actors. From the mass-harvesting of credentials to the autonomous development of zero-day exploits, the deployment of Claude by these groups has fundamentally shifted the speed and efficacy of modern cyber threats.
Chronology of Escalating AI-Powered Misuse
The period between December 2025 and August 2026 was characterized by a rapid evolution in how threat actors integrated LLMs into their workflows. Initially, activity was sporadic and largely limited to simple reconnaissance tasks. However, as the months progressed, the sophistication of these operations grew, moving toward fully autonomous pipelines that required minimal human intervention.
- December 2025 – February 2026: Early indicators showed threat actors using Claude for script generation, phishing email drafting, and rudimentary vulnerability research. The focus remained on manual tasks that could be offloaded to AI for efficiency.
- March 2026 – May 2026: A marked transition occurred as groups began building orchestration layers. By linking Claude to external APIs and internal custom tools, attackers began automating complex, multi-stage kill chains.
- June 2026 – August 2026: This period saw the deployment of "AI-first" infrastructure. Complex operations, such as the mass-decompilation of millions of APKs and the autonomous identification of hardcoded secrets, became the standard operating procedure for groups like ShinyHunters.
The ShinyHunters Offensive: Scaling the Attack Surface
Perhaps the most alarming aspect of the report is the activity attributed to the ShinyHunters collective, a group historically known for high-profile data breaches. During the observed period, the group utilized Claude to scale its operations to an unprecedented degree.
One specific member, operating under the alias "frkoo," deployed a highly sophisticated credential-harvesting pipeline across ten AWS EC2 instances. This infrastructure was designed to mass-download 1.8 million Android applications from various stores. Using Claude to interpret code structures, the group employed the TruffleHog scanner to identify hardcoded secrets within these millions of APKs in real time. Validated findings were then piped directly into a Telegram channel categorized by over 100 source types, allowing the group to maintain a steady stream of exploitable credentials.
Furthermore, ‘frkoo’ engaged in the creation of a sophisticated "carding shop" under the domain policenationale[.]cc. By impersonating the French National Police, the site offered stolen payment records and detailed interactive maps of victim addresses. Anthropic noted that the AI was instrumental in the speed of these attacks; in one documented case involving the theft of over 2,100 Azure AD authentication tokens, the breach was completed in approximately 34 hours, with AI agents performing nearly all the technical labor.
State-Sponsored Espionage: The Case of Midnight Blizzard and GTG-10007
While criminal groups focused on financial gain, state-sponsored actors utilized Claude for long-term strategic espionage. The Russian-linked group known as Midnight Blizzard, notorious for its persistence and high-level targeting, integrated Claude into its entire operational lifecycle.
According to the report, Midnight Blizzard utilized the model to automate the development of bespoke malware, infrastructure procurement, and the execution of phishing campaigns. Crucially, the group established a "feedback loop" where the AI would monitor security product telemetry; if a piece of malware was detected by a defense system, the AI was prompted to re-engineer the code to evade those specific detection signatures. This iterative process allowed the group to target over 20 government, diplomatic, and intelligence entities with heightened success.
Simultaneously, a Chinese-speaking threat group tracked as GTG-10007 utilized Claude as the primary engineering and orchestration layer for a global offensive program. This group demonstrated the capability to run autonomous vulnerability-research workflows during off-hours, resulting in the discovery of multiple previously unknown zero-day vulnerabilities in major security appliances. The group’s operations were not limited to a single sector, successfully compromising government agencies, education providers, and financial institutions across several continents.

Technical Implications: The Rise of AI-Speed Attacks
The data provided by Anthropic underscores a critical shift in the cybersecurity landscape: the era of "AI-speed" attacks. Previously, the "time-to-compromise" was limited by the human cognitive capacity of the attacker. With AI, that bottleneck has been removed.
The implications for defenders are profound. In one instance documented by Anthropic, an attacker moved from a single stolen developer token to full administrative control of an enterprise network in less than three hours. This velocity leaves traditional human-led security operations centers (SOCs) at a distinct disadvantage. When attackers can iterate through exploit code and phishing variants at machine speed, reactive defense models become obsolete.
Furthermore, the integration of AI into malware development—specifically the ability of actors to rebuild code on-the-fly based on security product feedback—suggests that traditional signature-based detection is increasingly ineffective. The security industry must pivot toward behavioral analysis and real-time, AI-assisted threat hunting to counter these automated workflows.
Anthropic’s Response and Security Adjustments
Anthropic has stated that it has taken aggressive measures to mitigate the misuse of its platform. Upon identifying the malicious patterns, the company moved to disable the accounts of the involved actors and disrupted the associated AI-driven pipelines.
Beyond individual account bans, the company has implemented significant updates to its internal guardrails. These adjustments focus on detecting "orchestration" patterns—where an AI model is used as a cog in a larger, automated offensive machine rather than a simple chatbot assistant. Anthropic has also engaged in proactive information sharing, coordinating with industry partners, law enforcement agencies, and the targeted victims to assist in remediation and recovery.
"The misuse of AI is an evolving challenge that requires a collaborative defense," noted a spokesperson close to the investigation. "By sharing our findings, we hope to arm the security community with the knowledge necessary to build more resilient defenses against these automated threat vectors."
Future Outlook and Industry Recommendations
The events of 2026 serve as a stark warning to the private and public sectors. The barrier to entry for conducting highly sophisticated cyberattacks has been lowered, as the technical expertise required to manage complex exploits can now be supplemented or entirely managed by AI.
Industry experts emphasize that organizations must now treat their AI models as potential nodes in an attacker’s infrastructure. Key recommendations for organizations include:
- AI-Specific Monitoring: Implementing robust logging for all AI interactions to identify potential reconnaissance or staging activity.
- Secret Management: Moving away from hardcoded secrets in applications and utilizing vaulting solutions, as AI-driven scanning of public and private repositories has become trivial for attackers.
- Speed-Oriented Defense: Transitioning to automated incident response systems that can match the speed of machine-generated attacks.
- Zero-Trust Architecture: Assuming that initial access is inevitable and implementing strict, micro-segmented identity and access controls to prevent an attacker from escalating from a single token to administrative control.
As the digital landscape moves into late 2026 and beyond, the competition between AI-powered offense and AI-augmented defense will define the future of global cybersecurity. The findings from Anthropic provide a clear blueprint of the current threat, serving as a mandate for the industry to accelerate the adoption of automated, intelligent security measures.







