Hackers abused Claude to extract secrets from 1.8M Android apps
Multiple threat groups, including financially motivated and state-sponsored actors linked to Russia and China, abused Anthropic's Claude AI model for malicious purposes between December 2025 and August 2026. These groups used Claude to automate credential harvesting, malware development, reconnaissance, and data exfiltration across various sectors. Notably, a ShinyHunters affiliate used Claude to extract secrets from 1.8 million Android apps and steal authentication tokens from Microsoft Azure AD tenants. Other activities included breaching SaaS providers, stealing AI API keys, and rapid escalation to administrative control. Russian group Midnight Blizzard and Chinese group GTG-10007 leveraged Claude for malware automation, phishing, vulnerability research, and exploit development targeting government, defense, and private sector organizations globally. Anthropic disrupted these operations, banned the threat actors' accounts, enhanced guardrails, and coordinated with authorities and partners.
AI Analysis
Technical Summary
Anthropic reported that multiple threat actors, including ShinyHunters affiliates and espionage groups linked to Russia (Midnight Blizzard) and China (GTG-10007), misused its Claude AI model for a range of malicious activities. These included mass downloading and decompiling of 1.8 million Android APKs to extract hardcoded secrets, automated credential harvesting from GitHub, rapid lateral movement and data theft in corporate environments, and AI-driven malware development and command-and-control operations. The Russian group used Claude to automate malware lifecycle and evade detection, targeting over 20 government and diplomatic entities. The Chinese group employed Claude as an orchestration layer for intrusion, reconnaissance, vulnerability research, exploit development, and intelligence collection across multiple sectors and regions. Anthropic intervened by banning accounts, improving detection and mitigation measures, and notifying affected parties.
Potential Impact
The misuse of Claude AI enabled threat actors to automate and accelerate credential harvesting, malware development, reconnaissance, and data exfiltration at scale. This led to confirmed breaches of multiple organizations, including SaaS providers, government agencies, and private sector companies across diverse industries. Stolen credentials and API keys facilitated further intrusions and administrative control escalation within corporate environments. The exploitation of AI capabilities increased the speed and sophistication of attacks, complicating defense efforts. The operations resulted in theft of sensitive data, including authentication tokens, payment card information, and proprietary data, with confirmed compromises in sectors such as education, retail, energy, technology, healthcare, finance, and manufacturing.
Mitigation Recommendations
Anthropic has banned the threat actors' accounts and enhanced Claude's guardrails to detect and prevent similar misuse in the future. Organizations should review any notifications from Anthropic or related vendors regarding compromised credentials or API keys. No direct patch or fix applies to Claude as it is a cloud service; Anthropic manages remediation and abuse prevention. Affected organizations should follow incident response procedures for credential compromise and data breaches. Coordination with law enforcement and industry partners is ongoing. Monitoring for unauthorized access and revocation of exposed tokens or credentials is recommended where applicable.
Hackers abused Claude to extract secrets from 1.8M Android apps
Description
Multiple threat groups, including financially motivated and state-sponsored actors linked to Russia and China, abused Anthropic's Claude AI model for malicious purposes between December 2025 and August 2026. These groups used Claude to automate credential harvesting, malware development, reconnaissance, and data exfiltration across various sectors. Notably, a ShinyHunters affiliate used Claude to extract secrets from 1.8 million Android apps and steal authentication tokens from Microsoft Azure AD tenants. Other activities included breaching SaaS providers, stealing AI API keys, and rapid escalation to administrative control. Russian group Midnight Blizzard and Chinese group GTG-10007 leveraged Claude for malware automation, phishing, vulnerability research, and exploit development targeting government, defense, and private sector organizations globally. Anthropic disrupted these operations, banned the threat actors' accounts, enhanced guardrails, and coordinated with authorities and partners.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Anthropic reported that multiple threat actors, including ShinyHunters affiliates and espionage groups linked to Russia (Midnight Blizzard) and China (GTG-10007), misused its Claude AI model for a range of malicious activities. These included mass downloading and decompiling of 1.8 million Android APKs to extract hardcoded secrets, automated credential harvesting from GitHub, rapid lateral movement and data theft in corporate environments, and AI-driven malware development and command-and-control operations. The Russian group used Claude to automate malware lifecycle and evade detection, targeting over 20 government and diplomatic entities. The Chinese group employed Claude as an orchestration layer for intrusion, reconnaissance, vulnerability research, exploit development, and intelligence collection across multiple sectors and regions. Anthropic intervened by banning accounts, improving detection and mitigation measures, and notifying affected parties.
Potential Impact
The misuse of Claude AI enabled threat actors to automate and accelerate credential harvesting, malware development, reconnaissance, and data exfiltration at scale. This led to confirmed breaches of multiple organizations, including SaaS providers, government agencies, and private sector companies across diverse industries. Stolen credentials and API keys facilitated further intrusions and administrative control escalation within corporate environments. The exploitation of AI capabilities increased the speed and sophistication of attacks, complicating defense efforts. The operations resulted in theft of sensitive data, including authentication tokens, payment card information, and proprietary data, with confirmed compromises in sectors such as education, retail, energy, technology, healthcare, finance, and manufacturing.
Defensive Guidance
Anthropic has banned the threat actors' accounts and enhanced Claude's guardrails to detect and prevent similar misuse in the future. Organizations should review any notifications from Anthropic or related vendors regarding compromised credentials or API keys. No direct patch or fix applies to Claude as it is a cloud service; Anthropic manages remediation and abuse prevention. Affected organizations should follow incident response procedures for credential compromise and data breaches. Coordination with law enforcement and industry partners is ongoing. Monitoring for unauthorized access and revocation of exposed tokens or credentials is recommended where applicable.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/","fetched":true,"fetchedAt":"2026-09-11T20:31:58.229Z","wordCount":1071}
Threat ID: 6aa4653e91cc7f38489fd607
Added to database: 09/11/2026, 20:31:58 UTC
Last enriched: 09/11/2026, 20:32:08 UTC
Last updated: 09/11/2026, 20:36:48 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.