|
    Theme
    Tech Verified Story

    Hackers abused Claude to extract secrets from 1.8 million Android apps

    Saba QamarSeptember 12, 2026 3 min read
    Text Size
    Hackers abused Claude to extract secrets from 1.8 million Android apps
    Tech CoverageAman-e-Pakistan Digital Desk
    Key Story Executive Summary
    Quick Read

    Anthropic said it recorded various forms of AI misuse between December 2025 and August 2026, including cyber and influence operations, surveillance, scams, weap…

    SSAN FRANCISCOHackers linked to financially motivated and state-sponsored groups from Russia and China have abused Anthropic’s Claude AI model for cyberattacks, surveillance, scams and other malicious activities,. Anthropic said it recorded various forms of AI misuse between December 2025 and August 2026, including cyber and influence operations, surveillance, scams, weapons development and model distillation.

    The company said it disrupted several activities linked to the Shiny. Hunters collective, which has been associated with major data theft campaigns. In one operation, an alleged French-speaking Shiny.

    Hunters member using the handle “frkoo” deployed a credential-harvesting pipeline across 10 Amazon Web Services EC2 workers. The system downloaded and analysed 1.8 million Android application packages (APKs) from multiple app stores and scanned them for hardcoded secrets using Truffle.

    Key Story Takeaway

    "Stay connected with Aman-e-Pakistan for ongoing live reporting and verified investigative updates."

    Hog., verified findings were sent in real time to a Telegram group organised into more than 100 source categories. The same actor used another automated process to collect email addresses linked to Git. Hub organisations and obtain Git.

    Hub Personal Access Tokens. These credentials were then used to gain initial access in several confirmed breaches. Anthropic said “frkoo” also established a carding operation impersonating French national police to sell stolen payment-card information and victim data.

    Suspected Shiny. Hunters members also stole AI API keys and used them to compromise other organisations or conduct reconnaissance. In one case, attackers breached a software-as-a-service provider and stole data belonging to around 200 downstream customers.

    AI-powered attacks accelerate. Anthropic said Claude helped one suspected Shiny. Hunters actor extract authentication data and obtain more than 2,100 Azure AD authentication tokens associated with over 40 corporate Microsoft tenants in about 34 hours.

    The company said AI agents performed nearly all of the work. Other attacks attributed to Shiny. Hunters affiliates included the theft of 1TB of data from a technology provider, the compromise of an airline and access to an energy company’s systems.

    In one case, attackers moved from initial access to bulk data theft within hours, while another actor reportedly progressed from a single stolen developer token to full administrative control in less than three hours. Russian and Chinese espionage activity.

    Anthropic also highlighted activity attributed to the Russian espionage group Midnight Blizzard, which allegedly used Claude to automate malware development, phishing, infrastructure acquisition, persistence, command-and-control operations and data exfiltration. The group reportedly targeted more than 20 government, defence, diplomatic, intelligence and foreign-policy organisations.

    Anthropic said the campaigns involved device-code phishing, Click. Fix attacks, DNS hijacking, Whats. App account takeovers, cloud email theft and malware targeting Windows, Android and iOS devices.

    The report also described an operation attributed to a Chinese-speaking group tracked as GTG-10007. Claude was used as an engineering and orchestration layer for intrusion attempts, reconnaissance of government networks, vulnerability research, exploit development, malware creation and intelligence collection.

    The group reportedly operated automated vulnerability-research workflows that uncovered previously unknown vulnerabilities in a major security product and produced working exploits targeting several network and security appliances. Its operations targeted around 50 organisations across government, education, retail, energy, technology, healthcare, finance and manufacturing, with confirmed compromises at an education technology company, a retailer and a Southeast Asian government agency.

    Anthropic said it disrupted the groups’ use of Claude, banned the relevant accounts and strengthened its safeguards to detect similar misuse more quickly. The company also said it notified authorities, industry partners and affected organisations.

    S

    Written by Saba Qamar

    Aman-e-Pakistan Senior Journalist & Bureau Reporter

    Fact Checked & Verified

    Continue Reading: More in Tech

    Swipe or click arrows to explore Tech desk coverage

    Nvidia in talks to invest in Anthropic's mega IPO, sources sayTech

    Nvidia in talks to invest in Anthropic's mega IPO, sources say

    Read Story
    Internet services to resume in AJK capitalTech

    Internet services to resume in AJK capital

    Read Story
    Social media now SMEs' storefrontTech

    Social media now SMEs' storefront

    Read Story
    AJK capital to get broadband internet services after months-long disruptionTech

    AJK capital to get broadband internet services after months-long disruption

    Read Story
    China, Iran among countries that have used AI to aid spying, Anthropic saysTech

    China, Iran among countries that have used AI to aid spying, Anthropic says

    Read Story
    Bollywood also jumps on the viral '80s AI trendTech

    Bollywood also jumps on the viral '80s AI trend

    Read Story