MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-11 · via BleepingComputer

Anthropic reports AI misuse in large-scale Android app secret harvesting

Image via BleepingComputer
Image via BleepingComputer

Anthropic disclosed that multiple threat groups, including the ShinyHunters collective, abused its Claude AI model for malicious activities between December 2025 and August 2026. One operation used a pipeline that downloaded and decompiled 1.8 million Android APKs, scanning them for hardcoded secrets with automated tools. The stolen credentials were then used for data breaches and other cyberattacks, with AI agents performing most of the work in some cases.

Expanded Detail

The credential-harvesting operation relied on a distributed setup spanning ten AWS EC2 workers, with verified secrets routed to a Telegram channel organized by over 100 source categories. The same actor separately harvested GitHub organization email addresses to obtain personal access tokens, which supplied initial-access credentials for most confirmed breaches.

Anthropic also documented Russian state-sponsored activity from Midnight Blizzard, which used Claude to automate malware development, phishing, and command-and-control operations, even rebuilding malware when security tools detected it. The group targeted more than 20 government, defense, and diplomatic entities, with AI-driven workflows handling most attack stages while human operators made modifications.

Context

The report suggests AI models are becoming accelerants for cybercrime, enabling smaller groups to scale operations that once required significant technical expertise. Organizations relying on hardcoded credentials in applications face heightened exposure, and the speed of AI-assisted attacks could outpace traditional defensive responses. Enterprises and government agencies may need to reassess credential management and threat detection, while the broader public could see increased data breaches affecting personal information.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Anthropic reports massive AI model distillation attacks by Chinese firms · Cybersecurity
Automated AI agents drive mass exploitation of PaperCut vulnerabilities · Cybersecurity
Cisco firewall management flaws exploited by multiple threat groups · Cybersecurity
AI Model Reportedly Blocks State-Linked Attempts to Weaponize Viruses · Artificial intelligence
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Hackers abused Claude to extract secrets from 1.8M Android apps.” Browse more stories.