Anthropic: Claude hijacked to scan 1.8 million Android apps for secrets
Anthropic has detailed eight months of malicious use of its model, including an automated chain that combed 1.8 million Android applications for hard-coded secrets. Initial access now happens in series.

Anthropic has published a review of malicious uses of Claude covering December 2025 to August 2026, reported on 11 September 2026 by Bleeping Computer. The company catalogues cyber operations, influence campaigns, surveillance, fraud, biological and conventional weapons development, and model distillation. The actors involved range from criminal collectives to espionage groups linked to Russia and China.
A secret scanner run across 1.8 million applications
The largest case by volume is attributed to a suspected member of the ShinyHunters collective, described as French-speaking and operating under the handle frkoo. The setup ran on ten AWS EC2 workers: bulk downloads from several app stores, decompilation, then a search for hard-coded secrets with TruffleHog. Volume processed, according to Anthropic: 1.8 million distinct Android APKs. Verified results were pushed in real time to a Telegram group, organised into more than a hundred types of source.
A second automated chain targeted GitHub: collecting e-mail addresses tied to organisations, then obtaining personal access tokens. Anthropic attributes most of this actor’s confirmed compromises to those two chains. The same profile also ran a shop reselling stolen banking data that impersonated the French national police, offering card statements, full cardholder details and an interactive map of victims’ addresses.
Thirty-four hours for two thousand tokens
In another episode attributed to ShinyHunters, more than 2,100 sets of Azure AD authentication tokens, tied to more than forty distinct Microsoft tenants, were extracted in roughly thirty-four hours. Anthropic says the AI agents did nearly all of the work. Elsewhere, going from a single stolen developer token to full administrative control took less than three hours; at an enterprise software vendor, a few hours were enough to reach mass data theft.
The victims cited include a technology provider, with one terabyte of data stolen, an airline, a company in the energy sector, and a SaaS provider whose compromise exposed the data of roughly 200 downstream customers. API keys for AI services were also stolen, then reused to break into other organisations or to carry out reconnaissance.
Espionage chains that run with no operator present
The Russian espionage group Midnight Blizzard used Claude to automate malware development, research, infrastructure acquisition, phishing, persistence, command and control, and exfiltration. Anthropic describes a feedback loop that rebuilt the malware every time a security product detected it, and counts more than twenty government, defence, diplomatic, intelligence and foreign-policy entities among the targets. The tradecraft observed ranges from device-code phishing to ClickFix attacks, DNS hijacking through compromised hotel Wi-Fi providers, WhatsApp account takeover and cloud mailbox theft, with Windows, Android and iOS implants. All of it rested on workflows built around Claude Code skills, the human operator stepping in mainly to adjust them.
The Chinese-speaking group tracked as GTG-10007 relied on the model as an engineering and orchestration layer: reconnaissance of government networks in the Middle East, Europe and South-East Asia, intrusion attempts against production systems, malware development, and the construction of an intelligence collection platform. Its vulnerability research chains ran while the operators were away, and surfaced several previously unknown flaws in a major security product, along with working exploits.
None of the techniques described here is new: decompiling an application to look for a forgotten key is an old move. What changes comes down to one figure — 1.8 million applications combed through, work nobody would have taken on by hand.
Sources (1)
- Hackers abused Claude to extract secrets from 1.8M Android appsbleepingcomputer.com
Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.

