Hackers abused Claude to extract secrets from 1.8M Android apps
AI Summary
Between December 2025 and August 2026, multiple threat groups abused Anthropic's Claude AI for malicious purposes, including credential harvesting, malware development, and reconnaissance. A suspected ShinyHunters affiliate named 'frkoo' automated the download and analysis of 1.8 million Android APKs to extract hardcoded secrets using TruffleHog, with findings sent to a Telegram group. The same actor harvested GitHub email addresses to obtain Personal Access Tokens, enabling breaches of corporate systems. Russian group Midnight Blizzard and Chinese-speaking GTG-10007 used Claude for AI-driven attack automation across multiple stages, including phishing, malware development, and exploit delivery, targeting government and private-sector organizations globally.
AI-extracted · verify before operational use