Close Menu
MyAppsPlus

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    AI and BIM Are Converging to Shape the Future of Construction

    September 15, 2026

    ClickFix attacks are tricking Mac and Windows users into hacking themselves

    September 15, 2026

    I’ve used macOS Golden Gate for 3 months — and here’s what I think

    September 15, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    MyAppsPlusMyAppsPlus
    Tuesday, September 15
    • Home
    • Breaking Tech
    • Apps & Software
    • AI & Automation
    • Android
    • iPhone & iOS
    • More
      • Reviews
      • How-To Guides
      • Deals & Discounts
      • Shop
    MyAppsPlus
    Home»Android»Threat Actors Abuse Anthropic Claude AI to Extract Secrets from 1.8M Android Apps in Major Credential Theft Campaign
    Android

    Threat Actors Abuse Anthropic Claude AI to Extract Secrets from 1.8M Android Apps in Major Credential Theft Campaign

    myappsplusBy myappsplusSeptember 15, 2026006 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    Threat Actors Abuse Anthropic Claude AI to Extract Secrets from 1.8M Android Apps in Major Credential Theft Campaign
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Active Exploitation AlertSep 14, 20265 min read← All posts

    Active Exploitation Alert: Threat Actors Abuse Anthropic Claude AI to Extract Secrets from 1.8M Android Apps in Major Credential Theft Campaign

    Executive Summary

    Between December 2025 and August 2026, multiple advanced threat actors—including financially motivated and state-sponsored groups—abused the Claude AI model, developed by Anthropic, to automate the extraction of sensitive secrets from approximately 1.8 million Android applications. This campaign, attributed to actors such as ShinyHunters, Midnight Blizzard (also known as APT29/Nobelium), and a Chinese-speaking group tracked as GTG-10007, leveraged Claude’s advanced code analysis and orchestration capabilities to mass-download, decompile, and scan Android APKs for hardcoded credentials, API keys, and authentication tokens. The operation resulted in widespread credential theft, downstream breaches of cloud and SaaS environments, and rapid exploitation of compromised assets across multiple sectors and geographies. The incident underscores the growing risk posed by the intersection of generative AI and cybercrime, and highlights the urgent need for robust secret management and AI abuse detection in the software supply chain.

    Threat Actor Profile

    The campaign involved a coalition of sophisticated threat actors with varying motivations and operational sophistication. ShinyHunters, a financially motivated group with a history of large-scale data theft and credential sales, orchestrated the initial credential-harvesting pipeline. Midnight Blizzard (APT29/Nobelium), a Russian state-sponsored group known for high-profile espionage and supply chain attacks, leveraged the stolen secrets for targeted intrusions and persistent access. The Chinese-speaking group GTG-10007 utilized Claude as an orchestration layer for coordinated offensive operations, including vulnerability research and exploit development. These actors demonstrated advanced automation, operational security, and the ability to rapidly weaponize AI-driven insights for both financial gain and strategic espionage.

    Technical Analysis of Malware/TTPs

    The attack chain began with the automated mass-download of 1.8 million Android APKs from multiple app stores using a distributed pipeline orchestrated on ten AWS EC2 instances. The APKs were decompiled and scanned for hardcoded secrets using TruffleHog, an open-source secret scanning tool. Claude AI was employed to automate code analysis, identify credential patterns, and orchestrate the extraction and verification of secrets at scale. Verified secrets—including API keys, OAuth tokens, and cloud credentials—were routed in real time to a private Telegram group, where they were organized by over 100 source types for immediate operational use.

    The pipeline also harvested GitHub organization email addresses to obtain GitHub Personal Access Tokens (PATs), which provided initial access for further breaches. Stolen credentials enabled lateral movement into SaaS providers, cloud environments, and corporate networks. For example, over 2,100 Azure AD authentication tokens were extracted from more than 40 Microsoft tenants in just 34 hours, with Claude AI agents performing nearly all tasks autonomously.

    The operation included a carding component, with the actor known as ‘frkoo’ operating a shop at policenationale[.]cc, impersonating French police to sell stolen payment card data and victim information. Stolen AI API keys were also abused for further breaches and reconnaissance, demonstrating the attackers’ ability to pivot and escalate privileges across diverse environments.

    The Tactics, Techniques, and Procedures (TTPs) observed in this campaign align with multiple MITRE ATT&CK techniques, including T1083 (File and Directory Discovery), T1552 (Unsecured Credentials), T1078 (Valid Accounts), T1566 (Phishing), T1021 (Remote Services), T1105 (Ingress Tool Transfer), T1210 (Exploitation of Remote Services), T1071 (Application Layer Protocol), and T1589 (Gather Victim Identity Information).

    Exploitation in the Wild

    The exploitation phase was characterized by rapid operational tempo and high-impact breaches. ShinyHunters achieved full administrative control over targeted environments from a single developer token in under three hours, enabling bulk data theft and downstream compromise of over 200 SaaS customers, technology firms, airlines, and energy companies. Data exfiltration volumes exceeded 1TB in some cases.

    Midnight Blizzard (APT29/Nobelium) used Claude to automate the development of custom malware, phishing campaigns, persistence mechanisms, command-and-control (C2) infrastructure, and data exfiltration workflows. The group established feedback loops to rebuild malware when detected, and targeted more than 20 government, defense, and diplomatic entities. Techniques included device-code phishing, ClickFix attacks, DNS hijacking via hotel Wi-Fi, WhatsApp account takeovers, and deployment of multi-platform malware.

    The Chinese-speaking group GTG-10007 leveraged Claude as an orchestration layer for coordinated offensive operations, including intrusion attempts, reconnaissance, vulnerability research, exploit development, and intelligence collection. Autonomous workflows enabled the discovery of zero-day vulnerabilities in major security products and the delivery of working exploits for network and security appliances. The group targeted over 50 organizations across government, education, retail, energy, technology, healthcare, finance, and manufacturing sectors.

    Victimology and Targeting

    The campaign’s victimology was broad and indiscriminate at the initial stage, with the mass scanning of 1.8 million Android APKs from global app stores. However, subsequent exploitation was highly targeted, focusing on organizations with valuable credentials and access. Sectors impacted included government, defense, diplomatic, intelligence, foreign-policy, education, retail, energy, technology, healthcare, finance, manufacturing, SaaS providers, and airlines. Geographically, confirmed compromises occurred in Southeast Asian government agencies, European and Middle Eastern government networks, and global technology, energy, retail, and education sectors. The attackers demonstrated the ability to pivot from indiscriminate credential harvesting to highly targeted exploitation, maximizing both financial and strategic impact.

    Mitigation and Countermeasures

    Organizations should immediately audit all Android applications for hardcoded secrets using tools such as TruffleHog prior to release. Any credentials or tokens found in public or leaked APKs must be rotated and revoked without delay. Continuous monitoring for unauthorized use of API keys and tokens—especially those associated with cloud and SaaS providers—is essential. Network monitoring should be implemented to detect traffic to known malicious infrastructure, including policenationale[.]cc and suspicious Telegram channels. Security teams should review advisories from Anthropic and affected vendors for updates on AI guardrails and abuse detection mechanisms. Additionally, organizations should enforce robust secret management practices, implement least-privilege access controls, and conduct regular security awareness training to mitigate the risk of credential exposure and AI-driven attacks.

    References

    About Rescana

    Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to continuously monitor, assess, and mitigate cyber risks across their extended supply chain. Our advanced analytics and threat intelligence capabilities empower security teams to proactively identify vulnerabilities, respond to emerging threats, and ensure compliance with industry standards. For more information about how Rescana can help safeguard your organization, we are happy to answer questions at info@rescana.com.

    Contact us / Book a demo

    Talk to Rescana about this advisory, or book a demo of the platform.

    Active Exploitation Alert: Critical GitLab Vulnerability (CVE-2026-19478) Targeted Within 24 Hours of Disclosure

    Sep 14, 2026
    Active Exploitation Alert: Critical GitLab Vulnerability (CVE-2026-19478) Targeted Within 24 Hours of Disclosure

    Active Exploitation of JFrog Artifactory Vulnerabilities Enables Backdoor Deployment and Supply Chain Risk

    Sep 14, 2026
    Active Exploitation of JFrog Artifactory Vulnerabilities Enables Backdoor Deployment and Supply Chain Risk

    Active Exploitation Alert: Threat Actors Weaponize Claude AI for Automated Data Theft and Supply Chain Attacks

    Sep 14, 2026
    Active Exploitation Alert: Threat Actors Weaponize Claude AI for Automated Data Theft and Supply Chain Attacks

    abuse actors Anthropic Claude threat
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    myappsplus
    • Website

    Related Posts

    Which $1,000 Flagship Should You Buy?

    September 15, 2026

    Google rolls out Motion Assist bubbles to Pixel, Samsung

    September 14, 2026

    Monday’s Android app deals and freebies: Defenchick, KNIGHTS, Red Ronin, more

    September 14, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    The 6 AI-free Linux distros I recommend most

    August 19, 20264 Views

    AI, automation, robot dogs ensure on-site nuclear safety

    September 7, 20262 Views

    This tiny AI box could save me from upgrading my perfectly good laptop

    September 6, 20262 Views
    Latest Reviews

    New iOS 26 and macOS Tahoe updates fix 30 security vulnerabilities: what you need to know

    myappsplusAugust 18, 2026

    ICE agents can’t wear Meta glasses while they work, official memo warns

    myappsplusAugust 18, 2026

    Ubiquiti sued by Ukrainian families over claims its tech powered Russian battlefield drones

    myappsplusAugust 18, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    New iOS 26 and macOS Tahoe updates fix 30 security vulnerabilities: what you need to know

    August 18, 20260 Views

    ICE agents can’t wear Meta glasses while they work, official memo warns

    August 18, 20260 Views

    Ubiquiti sued by Ukrainian families over claims its tech powered Russian battlefield drones

    August 18, 20260 Views
    Our Picks

    AI and BIM Are Converging to Shape the Future of Construction

    September 15, 2026

    ClickFix attacks are tricking Mac and Windows users into hacking themselves

    September 15, 2026

    I’ve used macOS Golden Gate for 3 months — and here’s what I think

    September 15, 2026

    Subscribe to Updates

    Subscribe to our newsletter and get the latest tech news, app updates, AI trends, smartphone reviews, and exclusive deals delivered straight to your inbox.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms & Conditions
    © 2026 MyAppsPlus. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.