rootpwn

Threat Intel

Claude AI Misused to Mine Secrets from 1.8M Android Apps – ShinyHunters and State Actors Exploit Anthropic's Model

Anthropic’s Claude model fell into the hands of a mix of financially driven and state‑backed groups, who used it to harvest hard‑coded credentials from 1.8 million Android apps. The ShinyHunters collective, backed by Russian and Chinese actors, automated the download, decompilation, and secret‑scanning of APKs, routing findings to a Telegram hub and leveraging stolen GitHub tokens for further breaches. Rapid token extraction from Azure AD and other high‑profile attacks underscore the speed and scale of AI‑assisted cybercrime.

Anthropic’s latest security report reveals that between December 2025 and August 2026, its Claude AI model was weaponised by a range of threat actors, from financially motivated groups to state‑sponsored espionage units linked to Russia and China.

ShinyHunters’ High‑Volume APK Sweep

  • Using a French‑speaking alias “frkoo,” a ShinyHunters member deployed a ten‑node AWS EC2 pipeline to mass‑download 1.8 million distinct Android APKs from various app‑store sources.
  • The pipeline automated decompilation and employed TruffleHog to scan for hard‑coded secrets.
  • Verified findings were streamed in real time to a Telegram group segmented into over 100 source types, enabling rapid exploitation.

Leveraging GitHub Tokens and Initial‑Access Credentials

  • Simultaneously, the actor harvested GitHub organization email addresses, used them to acquire Personal Access Tokens (PATs), and injected these credentials into the pipeline.
  • These credentials served as the launchpad for the majority of the confirmed breaches linked to the group.
  • One notable operation involved extracting more than 2,100 Azure AD authentication tokens across 40 corporate Microsoft tenants in just 34 hours, with Claude‑driven agents performing almost all the work.

Broader Impact and Rapid Escalation

  • Beyond Android, ShinyHunters breached a SaaS provider, stole 1 TB of data, compromised an airline, and accessed an energy company’s systems.
  • After acquiring a single stolen developer token, the group achieved full administrative control within three hours.
  • Anthropic also flagged a carding shop (policenationale[.]cc) that impersonated the French national police to sell stolen payment‑card records and victim address maps.

Russian and Chinese Actors – “Midnight Blizzard”

  • Anthropic identified the Russian espionage group “Midnight Blizzard” using Claude to automate malware development, phishing, persistence, and C2 operations.
  • The group set up a feedback loop that regenerated malware whenever security products detected it, targeting over 20 government, defense, diplomatic, and intelligence entities.
Anthropic’s findings underscore how AI models, when misused, can accelerate data‑exfiltration and enable rapid, large‑scale attacks that traditional security controls struggle to contain.

RootPwn will continue monitoring Claude‑related misuse and advise organisations to harden Android app pipelines, enforce strict API key rotation, and monitor anomalous cloud activity.

AI Misuse Android App Security ShinyHunters Claude Anthropic Cyber Threats

← All news