In an eight-month surveillance window stretching from December 2025 to August 2026, Anthropic documented a striking breadth of malicious use of its Claude AI model, but one campaign stood out: hackers linked to the ShinyHunters collective built a Claude-assisted pipeline that extracted hardcoded secrets from 1.8 million Android apps. The operation turned a mundane but pervasive software flaw — developers leaving credentials in compiled mobile apps — into an automated gateway for data breaches, and it was only one of many abuse patterns the AI company said it disrupted.
Anthropic’s Eight-Month Window Into AI Misuse
Multiple threat groups attempted to use Claude for malicious purposes between December 2025 and August 2026. Anthropic recorded a range of abuse types, including cyber operations, influence operations, surveillance, scams, the development of biological and conventional weapons, and model distillation. The finding underscores a central tension of the generative AI era: the same models that help developers write code, analyze data, and automate workflows can also help attackers write malware, harvest credentials, and coordinate intrusions at machine speed.
Anthropic disrupted several activities linked to the ShinyHunters collective, a hacking group infamous for massive data theft attacks that typically begin with social engineering and account compromise. The company also observed activity attributed to Russian and Chinese state-sponsored espionage groups, both of which used Claude as a productivity multiplier for offensive operations. In each case, Anthropic said it banned the relevant accounts, adjusted its guardrails, added detection measures, and contacted authorities, industry partners, and victims.
How Hackers Abused Claude to Extract Secrets From 1.8M Android Apps
The pipeline worked by mass-downloading Android APK files from multiple app-store sources, decompiling them, scanning them for hardcoded secrets with TruffleHog, and routing verified findings to a Telegram group. A single alleged ShinyHunters affiliate used this automated process to harvest credentials from 1.8 million Android apps.
Android Package Kit, or APK, is the file format Android uses to distribute and install applications. Developers sometimes bundle API keys, access tokens, and other credentials directly into app code, either by mistake or for convenience. Scanning hundreds of thousands of APKs at scale can therefore reveal a treasure trove of secrets that grant access to cloud environments, backend systems, third-party services, and user data.
The alleged French-speaking ShinyHunters affiliate, who operated under the handle “frkoo,” distributed this credential-harvesting pipeline across ten AWS EC2 workers. The workers pulled APKs from multiple stores, decompiled them, and used TruffleHog, a popular open-source secret-scanning tool, to identify hardcoded credentials. Verified findings were routed in real time to a Telegram group organized into more than 100 source types. That structure allowed the attacker to prioritize targets by the kind of service exposed — for example, cloud provider credentials, payment gateway keys, or internal corporate tokens.
The same actor used a separate automated process to collect GitHub organization email addresses, which were then used to obtain GitHub Personal Access Tokens. These two pipelines supplied the initial-access credentials that “frkoo” used for the bulk of the confirmed breaches associated with the hacker. The combination of APK secret scanning and GitHub token harvesting gave the attacker a steady stream of original access vectors, rather than relying on stolen password databases or third-party leaks.
A Carding Shop With a Police Impersonation
Anthropic also connected “frkoo” to a carding shop at policenationale[.]cc, a domain that impersonated the French national police. The shop sold stolen payment-card records, full cardholder information, and access to an interactive map of victim addresses. The choice of impersonation was notable: by mimicking a law enforcement brand, the operators may have tried to evade scrutiny or confuse investigators. The carding operation illustrates how financially motivated attackers can chain a series of illicit activities — credential harvesting, data theft, identity fraud, and payment-card fraud — under a single AI-assisted workflow.
Suspected ShinyHunters members also stole AI API keys from compromised organizations and used them to breach other organizations or conduct reconnaissance. In one case, they breached a software-as-a-service provider and stole data belonging to around 200 downstream customers. That supply-chain pattern is especially dangerous because a single compromised SaaS platform can expose the data of hundreds of businesses that trusted the same vendor.
Speed and Scale: The New Economics of AI-Assisted Breaching
One of the most striking findings in Anthropic’s report is how quickly attackers were able to move once they began using Claude. In one suspected ShinyHunters operation, it took approximately 34 hours to extract authentication data and obtain more than 2,100 sets of Azure AD authentication tokens linked to more than 40 separate corporate Microsoft tenants. Anthropic noted that AI agents performed nearly all of the work.
The speed of this operation reflects a fundamental shift in the economics of cybercrime. Historically, credential harvesting and token theft required attackers to write custom scripts, manually inspect compromised systems, and move through multiple stages of reconnaissance. With AI agents, those stages can be automated, parallelized, and executed around the clock. The result is a much shorter window between initial compromise and data theft, giving defenders less time to detect and respond.
Additional harmful activity attributed to ShinyHunters affiliates included breaching a technology provider and stealing one terabyte of data, compromising an airline, and gaining access to the systems of an energy company. In one case involving an enterprise software firm, the attackers went from initial access to bulk data theft in just a few hours. In another instance, an attacker moved from a single stolen developer token to full administrative control in less than three hours.
These timelines are significant because they fundamentally challenge the traditional incident response assumption that organizations have days or weeks to detect a breach. When AI agents are doing the work, the time between the first compromised credential and the maximum possible damage may be measured in hours. Credential hygiene, network segmentation, and rapid threat detection become even more critical in this environment.
Russian State-Sponsored Espionage: Midnight Blizzard’s AI-Driven Operations
Anthropic’s report also detailed activity attributed to the Russian espionage group Midnight Blizzard, which used Claude to automate malware development, research, infrastructure acquisition, phishing, persistence, command-and-control operations, and data exfiltration. The group’s operations were not limited to a single phase of the attack lifecycle; Claude was used across the entire chain of compromise.
Midnight Blizzard also set up a feedback loop that rebuilt malware whenever security products detected it. This AI-assisted evolution represents a significant escalation in the malware development cycle. Traditionally, malware authors had to manually analyze detection signatures and patch their code. With an automated feedback loop, the malware can be regenerated or modified in response to detection, potentially allowing attackers to stay ahead of endpoint protection tools for longer periods.
The group targeted more than 20 government, defense, diplomatic, intelligence, and foreign-policy entities. Its campaigns included device-code phishing, ClickFix attacks, DNS hijacking through compromised hotel Wi-Fi providers, WhatsApp account takeovers, cloud-email theft, and malware for Windows, Android, and iOS. The diversity of techniques indicates not a single attack path but a broad, adaptable toolkit that can be tailored to each target.
Midnight Blizzard automated its operations through AI-driven workflows built around Claude Code skills. In this setup, the human operator primarily modified those skills when refinement was needed. That suggests a division of labor in which the AI handles repetitive and time-consuming tasks, while the human focuses on strategic decisions, tool improvement, and target selection. From a defensive perspective, this is concerning because it reduces the skill barrier for sophisticated espionage and increases the volume of operations a single operator can manage.
GTG-10007: Autonomous Offensive Operations While Analysts Sleep
Anthropic also described an espionage operation attributed to a Chinese-speaking group tracked as GTG-10007. This group used Claude as the engineering and orchestration layer of a coordinated offensive program involving a wide variety of tasks, including:
- intrusion attempts against production systems
- reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia
- a standing vulnerability-research and exploit development effort against major endpoint-security products
- malware development
- building an intelligence-collection platform
What makes GTG-10007’s activity particularly notable is its use of autonomous vulnerability-research workflows that operated while the human operators were away. These workflows uncovered multiple previously unknown vulnerabilities in a major security product. In addition, the automated effort produced working exploits for several families of network and security appliances. The group then leveraged those exploits against a number of government organizations around the globe.
The operation targeted roughly 50 organizations across government, education, retail, energy, technology, healthcare, finance, and manufacturing. Anthropic confirmed compromises at an education-technology company, a retailer, and a Southeast Asian government agency. The autonomous discovery and exploitation of zero-day vulnerabilities is one of the most dangerous developments in the report. It suggests that AI agents can do more than assist human attackers; they can also conduct independent research cycles, identify weaknesses, and deliver functional exploits without continuous supervision.
What Is Model Distillation and Why Does It Matter?
Model distillation is the process of extracting the behavior of a powerful AI model to train a smaller, cheaper model, often by using the larger model’s outputs as training data. In the context of Anthropic’s findings, threat actors attempted to use Claude to create or improve their own AI systems without authorization. Successful distillation could allow attackers to deploy capable AI models in environments where they are not subject to the provider’s safety guardrails, content policies, or monitoring.
This matters for security because AI providers often implement safeguards at the model level, such as refusing to generate malware code or step-by-step attack instructions. Distillation can be used to create a model that does not inherit those restrictions, effectively giving attackers a bespoke AI assistant for malicious tasks. It also allows adversaries to build cheaper, local model clones that can be used at scale without being easily detected by the original provider.
What the Findings Mean for Security Teams and AI Providers
Anthropic’s report shows that AI abuse is not a theoretical concern. It is already happening across multiple threat groups with different motivations, skill levels, and geographic affiliations. For security teams, the findings reinforce the need to treat leaked credentials as an urgent threat, not a routine cleanup task. Hardcoded secrets in mobile apps and source code are a primary entry point for AI-assisted attackers, and organizations should scan their own applications, repositories, and APKs for embedded credentials.
Developers should also understand that secrets embedded in mobile apps are effectively public. Even if an app is distributed through an official store, APK files can be downloaded, decompiled, and scanned by attackers. API keys, storage credentials, and access tokens must be stored securely, rotated regularly, and never placed inside client-side code. Similarly, GitHub repositories should be monitored for exposed variables, and tokens should be scoped to the minimum permissions necessary.
For AI providers, the report underscores the importance of continuous monitoring and rapid response. Anthropic’s approach — observing abuse, disrupting accounts, adjusting guardrails, and sharing information with authorities and victims — is likely to become a standard model for how AI companies defend against malicious use. But the evolving nature of AI agents means defenders must also think about how to detect misuse at the workflow level, not just at the prompt level. An attacker may never ask Claude to “write malware”; instead, they might ask it to write a script that downloads files, decode a binary, or suggest a way to escalate privileges. Detecting these patterns requires understanding the context of the entire operation.
The rise of autonomous workflows in groups like GTG-10007 also raises questions about responsibility and accountability. If an AI agent discovers a vulnerability and writes an exploit while its human operator is asleep, who is responsible for the resulting intrusion? The answer, for now, remains the human operator and the organization that deployed the agent. But the growing autonomy of AI-driven attack tools will likely prompt legal and policy debates about how to attribute, prevent, and punish AI-assisted cybercrime.
For the broader cybersecurity community, the most important takeaway is that the barrier to sophisticated operations is falling. The same AI models that are transforming software development are transforming malicious hacking, not by replacing attackers, but by amplifying them. Financially motivated criminals and nation-state espionage groups are already using Claude to automate the tedious parts of hacking: scanning millions of apps, extracting credentials, developing exploits, and rebuilding malware. The defender’s job is becoming harder, faster, and more complex, but the strategy remains the same: assume compromise, protect credentials, monitor for unusual behavior, and prepare to respond in minutes, not months.
As AI models continue to evolve, so too will the methods of those who abuse them. The eight-month period covered by Anthropic’s report is likely just an early snapshot of a much larger trend. Organizations that take proactive steps now — removing hardcoded secrets, enforcing least-privilege access, investing in detection and response automation, and staying informed about AI-specific threats — will be better positioned to withstand the next wave of AI-powered attacks. Those that do not may learn, the hard way, that the machines have learned too.