Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Anthropic blocks possible attempt to use AI to make biological weapons

    September 11, 2026

    Can LLMs Engineer Their Own Agent Harness? ByteDance Seed’s HarnessDev Says Only 34 of 64 Changes Generalize

    September 11, 2026

    Hackers abused Claude to extract secrets from 1.8M Android apps

    September 11, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Anthropic blocks possible attempt to use AI to make biological weapons
    • Can LLMs Engineer Their Own Agent Harness? ByteDance Seed’s HarnessDev Says Only 34 of 64 Changes Generalize
    • Hackers abused Claude to extract secrets from 1.8M Android apps
    • Circle’s $400M Tazapay deal targets USDC payouts
    • Scientists just made quantum computer operations 1,000 times faster
    • Running costs of Covid vaccine damage scheme double the amount paid to victims
    • Court Rules Against Trump Order to Keep Costly Michigan Coal Plant Running
    • Milwaukee audit logs show no evidence of election fraud, experts say
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 11
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers abused Claude to extract secrets from 1.8M Android apps

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 11, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes.

    The AI company says that between December 2025 and August 2026, it recorded various forms of artificial intelligence misuse, including for cyber and influence operations,  surveillance, scams, development of biological and conventional weapons, and model distillation.

    Over the eight-month period, Anthropic disrupted several activities linked to the ShinyHunters collective, infamous for massive data theft attacks that typically begin with social engineering and account compromise.

    An alleged French-speaking member of the group that used the handle ‘frkoo’ distributed a credential-harvesting pipeline across ten AWS EC2 workers that downloaded from multiple stores and then scanned for secrets in 1.8 million Android APKs.

    “This pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog,” Anthropic explains.

    “Verified findings were routed in real time to a Telegram group organized into over 100 source types.”

    The same actor used a separate automated process to collect GitHub organization email addresses and used them to obtain GitHub Personal Access Tokens (PATs).

    The two pipelines provided initial-access credentials that ‘frkoo’ used “for the bulk of the confirmed breaches” associated with the hacker.

    Anthropic says that ‘frkoo’ also set up a carding shop at policenationale[.]cc that impersonated the French national police to sell stolen payment-card records, full cardholder information, and an interactive map of victim addresses.

    Suspected ShinyHunters members also stole AI API keys and used them for breaching other organizations or for reconnaissance activity.

    In one case, they breached a software-as-a-service provider and stole data belonging to around 200 downstream customers.

    Fast-paced attacks

    With the help of Claude AI, it took a suspected ShinyHunters threat actor about 34 hours to extract authentication data and get more than 2,100 sets of Azure AD authentication tokens linked to over 40 separate corporate Microsoft tenants. According to Anthropic, “AI agents performed nearly all of the work.”

    Additional harmful activity involving Claude and attributed to ShinyHunters affiliates includes breaching a technology provider and stealing 1TB of data, compromising an airline, and accessing systems of an energy company.

    ShinyHunters moved quickly after obtaining initial access. In the case of an enterprise software firm, the hackers went to bulk data theft in just a few hours.

    In another instance, the AI company says that the attacker moved from a single stolen developer token to full administrative control in less than three hours.

    Russian and Chinese hackers

    Anthropic’s report also highlights activity attributed to the Russian espionage group “Midnight Blizzard,” which used Claude to automate malware development, research, infrastructure acquisition, phishing, persistence, command-and-control (C2) operations, and data exfiltration.

    The threat actor also set up a feedback loop that rebuilt malware whenever security products detected it.

    Anthropic observed Midnight Blizzard targeting over 20 government, defense, diplomatic, intelligence, and foreign-policy entities.

    The campaigns included device-code phishing, ClickFix attacks, DNS hijacking through compromised hotel Wi-Fi providers, WhatsApp account takeovers, cloud-email theft, and Windows, Android, and iOS malware, with Claude being used throughout all attack stages.

    Midnight Blizzard automated its operations through AI-driven workflows built around Claude Code skills, with the human operator primarily modifying those skills when they needed refinement.

    Anthropic also describes an espionage operation attributed to a Chinese-speaking group tracked as GTG-10007, where Claude was used “as the engineering and orchestration layer of a coordinated offensive program involving a variety of tasks,” such as:

    • intrusion attempts against production systems
    • reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia
    • a standing vulnerability-research and exploit development effort against major endpoint-security products
    • malware development
    • building an intelligence-collection platform

    The GTG-10007 espionage group operated autonomous vulnerability-research workflows while the human operators were away, which uncovered multiple previously unknown vulnerabilities in a major security product.

    Additionally, the automated effort also delivered “working exploits for several families of network and security appliances.” The actor then leveraged the exploit code against several government organizations around the globe.

    The group’s operations targeted around 50 organizations across government, education, retail, energy, technology, healthcare, finance, and manufacturing, with confirmed compromises at an education-technology company, a retailer, and a Southeast Asian government agency.

    The AI company notes that it disrupted the actors’ use of Claude for harmful activities and banned the threat actors’ account.

    Furthermore, Anthropic adjusted its guardrails based on the observed malicious use, added measures to detect future misuse faster, and contacted the authorities, industry partners, and victims.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    1.8M abused Android apps Claude extract hackers Secrets
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Anthropic Adds Plugin Evals to Claude Code: 6 Grader Types, a No-Plugin Baseline, and a CI Gate for Skills

    Phishing Research Challenges Conventional Security Awareness Testing

    Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

    Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

    Historical art can hide scientific secrets

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Anthropic blocks possible attempt to use AI to make biological weapons

    September 11, 2026

    Can LLMs Engineer Their Own Agent Harness? ByteDance Seed’s HarnessDev Says Only 34 of 64 Changes Generalize

    September 11, 2026

    Hackers abused Claude to extract secrets from 1.8M Android apps

    September 11, 2026

    Circle’s $400M Tazapay deal targets USDC payouts

    September 11, 2026
    Latest Posts

    After 3 reverse stock splits and a $13.5M loss, this real estate firm bet $8M on crypto it may not be allowed to withdraw

    August 3, 2026

    There Are 2 Eclipses This August. Here’s How to See Them

    August 3, 2026

    Europe’s ETS revision is an opportunity to strengthen maritime competitiveness – POLITICO

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Anthropic blocks possible attempt to use AI to make biological weapons

    September 11, 2026

    Can LLMs Engineer Their Own Agent Harness? ByteDance Seed’s HarnessDev Says Only 34 of 64 Changes Generalize

    September 11, 2026

    Hackers abused Claude to extract secrets from 1.8M Android apps

    September 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.