Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Webinar: Which Google Workspace security controls actually matter?

    September 20, 2026

    Malicious npm packages evade install-script defenses at runtime

    September 20, 2026

    Researchers escape OpenAI Codex sandbox to run commands on host

    September 20, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Hackers abused Claude to extract secrets from 1.8M Android apps
    News

    Hackers abused Claude to extract secrets from 1.8M Android apps

    adminBy adminSeptember 11, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Robot

    Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes.

    The AI company says that between December 2025 and August 2026, it recorded various forms of artificial intelligence misuse, including for cyber and influence operations,  surveillance, scams, development of biological and conventional weapons, and model distillation.

    Over the eight-month period, Anthropic disrupted several activities linked to the ShinyHunters collective, infamous for massive data theft attacks that typically begin with social engineering and account compromise.

    An alleged French-speaking member of the group that used the handle ‘frkoo’ distributed a credential-harvesting pipeline across ten AWS EC2 workers that downloaded from multiple stores and then scanned for secrets in 1.8 million Android APKs.

    “This pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog,” Anthropic explains.

    “Verified findings were routed in real time to a Telegram group organized into over 100 source types.”

    The same actor used a separate automated process to collect GitHub organization email addresses and used them to obtain GitHub Personal Access Tokens (PATs).

    The two pipelines provided initial-access credentials that ‘frkoo’ used “for the bulk of the confirmed breaches” associated with the hacker.

    Anthropic says that ‘frkoo’ also set up a carding shop at policenationale[.]cc that impersonated the French national police to sell stolen payment-card records, full cardholder information, and an interactive map of victim addresses.

    Suspected ShinyHunters members also stole AI API keys and used them for breaching other organizations or for reconnaissance activity.

    In one case, they breached a software-as-a-service provider and stole data belonging to around 200 downstream customers.

    Fast-paced attacks

    With the help of Claude AI, it took a suspected ShinyHunters threat actor about 34 hours to extract authentication data and get more than 2,100 sets of Azure AD authentication tokens linked to over 40 separate corporate Microsoft tenants. According to Anthropic, “AI agents performed nearly all of the work.”

    Additional harmful activity involving Claude and attributed to ShinyHunters affiliates includes breaching a technology provider and stealing 1TB of data, compromising an airline, and accessing systems of an energy company.

    ShinyHunters moved quickly after obtaining initial access. In the case of an enterprise software firm, the hackers went to bulk data theft in just a few hours.

    In another instance, the AI company says that the attacker moved from a single stolen developer token to full administrative control in less than three hours.

    Russian and Chinese hackers

    Anthropic’s report also highlights activity attributed to the Russian espionage group “Midnight Blizzard,” which used Claude to automate malware development, research, infrastructure acquisition, phishing, persistence, command-and-control (C2) operations, and data exfiltration.

    The threat actor also set up a feedback loop that rebuilt malware whenever security products detected it.

    Anthropic observed Midnight Blizzard targeting over 20 government, defense, diplomatic, intelligence, and foreign-policy entities.

    The campaigns included device-code phishing, ClickFix attacks, DNS hijacking through compromised hotel Wi-Fi providers, WhatsApp account takeovers, cloud-email theft, and Windows, Android, and iOS malware, with Claude being used throughout all attack stages.

    Midnight Blizzard automated its operations through AI-driven workflows built around Claude Code skills, with the human operator primarily modifying those skills when they needed refinement.

    Anthropic also describes an espionage operation attributed to a Chinese-speaking group tracked as GTG-10007, where Claude was used “as the engineering and orchestration layer of a coordinated offensive program involving a variety of tasks,” such as:

    • intrusion attempts against production systems
    • reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia
    • a standing vulnerability-research and exploit development effort against major endpoint-security products
    • malware development
    • building an intelligence-collection platform

    The GTG-10007 espionage group operated autonomous vulnerability-research workflows while the human operators were away, which uncovered multiple previously unknown vulnerabilities in a major security product.

    Additionally, the automated effort also delivered “working exploits for several families of network and security appliances.” The actor then leveraged the exploit code against several government organizations around the globe.

    The group’s operations targeted around 50 organizations across government, education, retail, energy, technology, healthcare, finance, and manufacturing, with confirmed compromises at an education-technology company, a retailer, and a Southeast Asian government agency.

    The AI company notes that it disrupted the actors’ use of Claude for harmful activities and banned the threat actors’ account.

    Furthermore, Anthropic adjusted its guardrails based on the observed malicious use, added measures to detect future misuse faster, and contacted the authorities, industry partners, and victims.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCIS Benchmarks September 2026 Update
    Next Article Florida confirms DMV database breached via stolen police account
    admin
    • Website

    Related Posts

    News

    Webinar: Which Google Workspace security controls actually matter?

    September 20, 2026
    News

    Malicious npm packages evade install-script defenses at runtime

    September 20, 2026
    News

    Researchers escape OpenAI Codex sandbox to run commands on host

    September 20, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Our Picks

    Webinar: Which Google Workspace security controls actually matter?

    September 20, 2026

    Malicious npm packages evade install-script defenses at runtime

    September 20, 2026

    Researchers escape OpenAI Codex sandbox to run commands on host

    September 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.