Anthropic says threat actors used Claude in campaigns targeting Android apps and organizations
Anthropic says it disrupted several threat actors that allegedly used its Claude AI services to support credential theft, espionage, malware development, and other cybercrime between December 2025 and...
Anthropic says it disrupted several threat actors that allegedly used its Claude AI services to support credential theft, espionage, malware development, and other cybercrime between December 2025 and August 2026.
In a report on malicious AI use, the company described activity it linked to members or affiliates of the ShinyHunters cybercrime ecosystem. One French-speaking actor, identified by the handle “frkoo,” allegedly operated an automated pipeline across 10 AWS EC2 instances. The system downloaded roughly 1.8 million Android application packages from app-store sources, decompiled them, and searched for embedded credentials and other secrets using TruffleHog.
According to Anthropic, validated results were sent to a Telegram group sorted into more than 100 source categories. The same actor reportedly ran another process to gather GitHub organization email addresses and attempt to obtain GitHub personal access tokens. Anthropic said the collected credentials were used as initial access in many of the breaches it associated with the actor.
AI-assisted intrusion activity
The company said Claude was also used to accelerate post-compromise work. In one incident attributed to a suspected ShinyHunters operator, AI-assisted workflows allegedly extracted authentication material and obtained more than 2,100 Azure AD tokens spanning over 40 Microsoft tenants within about 34 hours.
Anthropic further reported that attackers moved rapidly from initial access to large-scale data theft in several cases, including an incident in which a stolen developer token was allegedly escalated to administrative access in less than three hours.
Espionage groups also cited
The report also discusses activity attributed to Midnight Blizzard, a Russian-linked espionage group, and a Chinese-speaking cluster Anthropic tracks as GTG-10007. The alleged uses included reconnaissance, phishing, infrastructure setup, malware development, command-and-control operations, vulnerability research, and data exfiltration.
- Midnight Blizzard reportedly targeted government, defense, diplomatic, intelligence, and foreign-policy entities.
- GTG-10007 allegedly used automated workflows to identify vulnerabilities and develop exploits affecting network and security products.
Anthropic said it banned accounts tied to the reported activity, updated its safeguards and detection systems, and notified relevant authorities, industry partners, and potential victims. The company’s findings are based on its own investigation and attribution assessments.
