Follow
Subscribe via Email!

Enter your email address to subscribe to this platform and receive notifications of new posts by email.

1.8M Android Apps in Claude AI Misuse Report

Anthropic says an alleged ShinyHunters member used Claude in a pipeline that scanned 1.8 million Android packages for secrets feeding corporate intrusions.
Robot hacker illustration accompanying the report on Claude AI misuse.

A Telegram group received freshly harvested software secrets as ten cloud workers scanned Android apps, according to Anthropic’s account of Claude AI misuse. BleepingComputer reported on September 11 that the company traced the operation to an alleged ShinyHunters member using the handle frkoo. The Claude abuse involved a pipeline that downloaded and examined 1.8 million distinct Android packages, feeding credentials into a wider campaign of corporate intrusions. [1]

Claude AI Misuse Reaches App Stores

Anthropic says frkoo spread the scanning operation across ten AWS EC2 workers (rented cloud computing instances). The pipeline downloaded APKs from several app stores. These packages distribute Android applications; frkoo decompiled them to inspect their contents.

TruffleHog searched for hardcoded secrets: credentials embedded in the software. The Telegram group sorted verified findings into more than 100 source types. Its messages organized potential access points. [1] The headline number counts scanned packages. It does not establish that every package contained a usable secret. Nor does it count breached developers or infected phones. Bill Toulas at BleepingComputer describes Anthropic’s findings as a search through downloadable Android software for embedded credentials that could help frkoo enter systems belonging to other organizations. The supplied reporting gives no total for the secrets that this particular pipeline successfully verified. [1]

GitHub supplied another route. Anthropic says frkoo ran a separate process that collected organization email addresses and used them to obtain Personal Access Tokens (PATs), credentials for accessing GitHub resources. Together, the Android and GitHub pipelines supplied the initial access behind most breaches the company confirmed for this actor. The report does not break those breaches down by pipeline. Which exposed credential led to which victim remains unclear in the supplied account. [1]

Robot hacker illustration used to accompany the Claude AI misuse report.
A robot hacker illustration accompanies the report on the abuse of Claude. (Credit: BleepingComputer)

Stolen Tokens Open Corporate Doors

A suspected ShinyHunters actor needed about 34 hours to extract authentication data and obtain more than 2,100 sets of Azure AD tokens associated with over 40 corporate Microsoft tenants (separate organizational environments). Anthropic described the division of labor bluntly: “AI agents performed nearly all of the work.” BleepingComputer attributes that assessment to the company; the supplied reporting does not include an independent reconstruction of the operation. The case puts a timescale on the Claude AI misuse, although it does not establish how long the same attacker would have needed without the model or identify every human intervention during the intrusion. [1]

Other attacks accelerated after the first foothold. At an enterprise software company, the hackers progressed to bulk data theft within hours, according to Anthropic. In another case, a single stolen developer token led to full administrative control in less than three hours. Suspected ShinyHunters members also stole AI API keys, which provide access to AI services. They used those keys during reconnaissance or attacks on other organizations. [1][4]

The victims extended beyond one provider. Anthropic reported a software service breach affecting data from around 200 downstream customers. It also described a technology provider losing 1TB of data, an airline compromise and access to an energy company’s systems. The supplied article leaves those organizations unnamed, limiting what can be established about the consequences for individual customers. [1]

Read these too!
Emil

Espionage Groups Automate More Work

Anthropic’s review covered December 2025 through August 2026. It also tracked state-linked espionage, including the Russian-speaking actor GTG-20006, whose activity Anthropic associated with Midnight Blizzard in operations against Ukrainian and European government and diplomatic targets. BleepingComputer reports that Midnight Blizzard, a Russian espionage group, used Claude across malware development, phishing, infrastructure acquisition, persistence and data theft, with AI workflows handling repeated tasks while a human operator refined the underlying Claude Code skills. More than 20 government, defense, diplomatic, intelligence and foreign-policy entities appeared among its targets. [1][3][5]

Midnight Blizzard also created a feedback loop that rebuilt malware when security products detected it. Its campaigns included device-code phishing, ClickFix attacks and DNS hijacking through compromised hotel Wi-Fi providers. Anthropic additionally observed WhatsApp account takeovers, cloud-email theft and malware for Windows, Android and iOS. Anthropic describes Claude AI misuse across multiple attack stages. The reporting does not say every listed target suffered a successful breach. [1]

Google Play illustration accompanying a report about deceptive Early Access applications.
Google Play is the subject of a separate report on deceptive Early Access applications. (Credit: The Hacker News)

Chinese-speaking operators tracked as GTG-10007 pursued another broad campaign. Anthropic says their automated vulnerability research continued while human operators were away, discovering previously unknown weaknesses in a major security product and producing working exploits for network and security appliances. The operators then used exploit code against government organizations. Anthropic counted roughly 50 targets across several industries. It confirmed breaches involving a retailer, an education-technology business and a government agency in Southeast Asia. [1]

Android Faces a Separate Store Problem

Android also features in a separate September 10 investigation reported by The Hacker News. Bitdefender found deceptive apps exploiting Google Play’s Early Access program, where users cannot post public reviews or star ratings. Bitdefender investigated misleading applications and advertising. The supplied sources do not connect those operators to frkoo, ShinyHunters or the Claude-assisted credential scan. Google Play is only one part of the wider Android distribution environment discussed in these reports. [2]

One app, Vice Streets: Open World, imitated Grand Theft Auto. It accumulated more than a million downloads without reviews or ratings. It subsequently disappeared from Google Play. The Hacker News could not establish who removed it. Bitdefender also described reward apps promoted through TikTok and Facebook advertisements, including AI-generated celebrity deepfakes, that offered virtual earnings before slowing progress toward a withdrawal and never delivering the promised payout. [2]

A portrait of Dario Amodei accompanying coverage of Claude AI misuse.
A portrait of Dario Amodei illustrates TNW’s coverage of Anthropic’s misuse report. (Credit: TNW)

Publicly accessible software can expose information its publishers did not intend to spotlight, as PerEXP Teamworks also reported in its coverage of the Steam achievements leak involving unreleased games. Here, Anthropic describes credentials extracted from application packages. Bitdefender instead identifies missing public feedback as an opening for deceptive apps. Each report locates the exposure in a different part of software distribution. [1][2]

Anthropic Bans Accounts; Questions Remain

Anthropic says it disrupted the harmful activity and banned the actors’ accounts. It also adjusted guardrails, added measures intended to detect future misuse faster, and contacted authorities, industry partners and victims. Anthropic’s broader review covered influence operations, surveillance, scams, weapons-related activity and model distillation as well as cyber operations; those categories do not all belong to the Android credential-harvesting case. [1][3][4]

The supplied reports do not independently verify Anthropic’s intrusion findings or disclose how many Android-derived credentials remain usable.

BleepingComputer’s account of Claude AI misuse leaves several concrete details unresolved: the complete list of app stores scanned, the affected applications, and the number of organizations breached through Android-derived secrets specifically. Anthropic’s account bans establish action against access to Claude. The supplied reporting does not establish whether every affected organization revoked exposed credentials or recovered stolen data. Google’s response to the separate Early Access investigation was also pending in The Hacker News report. [1][2]

Sources
  1. ONLINE NEWS Toulas, B. (2026, September 11). Hackers abused Claude to extract secrets from 1.8M Android apps. BleepingComputer. [Article Link]
  2. ONLINE NEWS The Hacker News. (2026, September 10). Google Play Early Access abused to push thousands of deceptive Android apps. [Article Link]
  3. ONLINE NEWS Constantin, A. M. (2026, September 10). Anthropic’s Claude misuse report: spying, weapons and more. TNW. [Article Link]
  4. ONLINE NEWS Techweez. (2026, September 11). Anthropic Reveals How Criminals Tried to Weaponize Claude. [Article Link]
  5. ONLINE NEWS Baran, G. (2026, September 11). Hackers Use Claude AI Agents to Automate Cyberattacks, Develop 0-Days and Evade Detection. Cyber Security News. [Article Link]

Leave a Comment

Related Posts
Total
0
Share