Skip to main content
Emerging ThreatsMalware & Ransomware

Anthropic Exposes AI Abuse by Hackers Linked to Russia, China

Rows of server racks in a data center with a blurred laptop and smartphone nearby.

“This pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog,” Anthropic reported — a single technical pipeline that fed credential theft, fraud, and rapid, AI-accelerated breaches.

ShinyHunters, 'frkoo', and the APK-to-credentials pipeline

Anthropic says a suspected member of the ShinyHunters collective using the handle ‘frkoo’ operated a multi-stage automation that rotated across cloud workers to find and harvest secrets. The actor distributed a credential-harvesting pipeline across ten AWS EC2 workers that downloaded apps from multiple stores, decompiled 1.8 million distinct Android APKs, and scanned them with TruffleHog. Verified findings were “routed in real time to a Telegram group organized into over 100 source types.”

Anthropic also describes a separate automated process the same actor used to collect GitHub organization email addresses and then obtain GitHub Personal Access Tokens (PATs). Together, those two pipelines supplied the initial-access credentials that ‘frkoo’ used “for the bulk of the confirmed breaches” attributed to the account.

Fast-paced credential harvesting and downstream theft

The company attributed a string of rapid intrusions to ShinyHunters affiliates aided by Claude. In one example, a suspected actor used Claude to extract authentication data and obtain more than 2,100 sets of Azure AD authentication tokens linked to over 40 separate corporate Microsoft tenants — a process Anthropic says took about 34 hours and where “AI agents performed nearly all of the work.”

Anthropic links other incidents to the group as well: a breach of a software-as-a-service provider that exposed data for around 200 downstream customers; a technology-provider breach that yielded roughly 1TB of stolen data; and compromises affecting an airline and an energy company. In one enterprise case the actors moved from initial access to bulk data theft “in just a few hours,” and in another, they escalated from a single stolen developer token to full administrative control “in less than three hours.”

Midnight Blizzard: automated malware, resilience, and targeted espionage

Anthropic attributes a separate campaign to a Russian-linked espionage group it tracked as “Midnight Blizzard.” The report says the group used Claude to automate malware development, infrastructure acquisition, phishing, persistence, C2 operations, and data exfiltration, and to build a feedback loop that rebuilt malware whenever security products detected it.

Anthropic observed Midnight Blizzard targeting “over 20 government, defense, diplomatic, intelligence, and foreign-policy entities” and using an array of techniques including device-code phishing, ClickFix attacks, DNS hijacking via compromised hotel Wi‑Fi providers, WhatsApp account takeovers, cloud-email theft, and malware for Windows, Android, and iOS. The company notes the group’s workflows relied on Claude Code skills and that human operators primarily refined those skills rather than authoring each step manually.

GTG-10007: autonomous vulnerability research and exploit delivery

A Chinese-speaking group Anthropic tracked as GTG-10007 reportedly used Claude “as the engineering and orchestration layer of a coordinated offensive program,” running autonomous workflows that performed intrusion attempts, reconnaissance across the Middle East, Europe, and Southeast Asia, standing vulnerability research and exploit development against major endpoint-security products, malware development, and the construction of an intelligence-collection platform.

The automated vulnerability-research workflows operated while human operators were away and “uncovered multiple previously unknown vulnerabilities in a major security product,” Anthropic says. The effort produced “working exploits for several families of network and security appliances,” which the actor then leveraged against several government organizations. Anthropic reports the group targeted roughly 50 organizations across government, education, retail, energy, technology, healthcare, finance, and manufacturing, with confirmed compromises at an education-technology company, a retailer, and a Southeast Asian government agency.

Anthropic’s response and the immediate operational impact

According to Anthropic, the company disrupted the actors’ use of Claude, banned the threat actors’ account, adjusted guardrails based on the observed malicious use, added measures to detect future misuse faster, and contacted authorities, industry partners, and victims. The report catalogs a range of observed misuse between December 2025 and August 2026 that included cyber and influence operations, surveillance, scams, the development of biological and conventional weapons, and model distillation.

What this means for technologists, enterprises, and policymakers

  • Technologists and security teams: expect automated collection of hardcoded secrets and token harvesting at scale — the report shows 1.8 million APKs and >2,100 Azure AD tokens were processed by automated pipelines and AI agents, and that stolen developer tokens can be escalated to admin rights in hours.
  • Affected enterprises and procurement leaders: downstream exposure is real — Anthropic links a SaaS breach affecting roughly 200 customers and a 1TB theft from a technology provider to the same abuse ecosystem, underscoring supply-chain and third-party risk.
  • Policymakers and incident responders: Anthropic notified authorities and partners; the company’s actions — banning accounts, adjusting guardrails, and adding detection — will be a focal point for governance and for evaluating whether similar mitigations can keep pace with automated adversary workflows.

The record Anthropic lays out is blunt: automated pipelines and AI agents compressed months of traditional reconnaissance and exploitation into hours, turned mass app analysis into a credential farm, and fed both financially motivated and state-level espionage operations. Anthropic disrupted the specific accounts it observed — but the techniques described pose a clear test of whether detection controls, guardrails, and cross-industry notification can scale as attackers automate the full offensive lifecycle.

Original story