Between December 2025 and August 2026, a concerning trend emerged as a coalition of advanced threat actors exploited the Claude AI model, crafted by Anthropic. This operation involved the automated extraction of sensitive information from approximately 1.8 million Android applications. The campaign was linked to notable groups such as ShinyHunters, Midnight Blizzard (also recognized as APT29/Nobelium), and a Chinese-speaking entity known as GTG-10007. Utilizing Claude’s sophisticated code analysis and orchestration capabilities, these actors mass-downloaded, decompiled, and scrutinized Android APKs for hardcoded credentials, API keys, and authentication tokens. The fallout from this operation included extensive credential theft, subsequent breaches of cloud and SaaS environments, and rapid exploitation of compromised assets across various sectors and regions.
Threat Actor Profile
The campaign showcased a diverse array of sophisticated threat actors, each with distinct motivations and operational capabilities. ShinyHunters, primarily driven by financial gain, initiated the credential-harvesting pipeline, drawing on their history of large-scale data theft and credential sales. In contrast, Midnight Blizzard (APT29/Nobelium), a Russian state-sponsored group, utilized the stolen secrets for targeted intrusions and sustained access, known for their high-profile espionage and supply chain attacks. Meanwhile, the Chinese-speaking group GTG-10007 employed Claude as an orchestration layer for coordinated offensive operations, including vulnerability research and exploit development. Collectively, these actors demonstrated remarkable automation, operational security, and the capacity to swiftly weaponize AI-driven insights for both financial and strategic objectives.
Technical Analysis of Malware/TTPs
The attack commenced with the automated mass-download of 1.8 million Android APKs from various app stores, facilitated by a distributed pipeline operating on ten AWS EC2 instances. The APKs were then decompiled and scanned for hardcoded secrets using TruffleHog, an open-source secret scanning tool. The Claude AI model was instrumental in automating code analysis, identifying credential patterns, and orchestrating the extraction and verification of secrets at scale. Verified secrets, including API keys, OAuth tokens, and cloud credentials, were routed in real-time to a private Telegram group, where they were meticulously organized by over 100 source types for immediate operational deployment.
The pipeline also gathered GitHub organization email addresses to obtain GitHub Personal Access Tokens (PATs), which facilitated initial access for further breaches. This led to lateral movement into SaaS providers, cloud environments, and corporate networks. Notably, over 2,100 Azure AD authentication tokens were extracted from more than 40 Microsoft tenants in just 34 hours, with Claude AI agents executing nearly all tasks autonomously. The operation also included a carding component, with an actor known as ‘frkoo’ running a shop at policenationale[.]cc, impersonating French police to sell stolen payment card data and victim information. Stolen AI API keys were further exploited for additional breaches and reconnaissance, showcasing the attackers’ adaptability and privilege escalation capabilities across diverse environments.
The Tactics, Techniques, and Procedures (TTPs) observed in this campaign align with numerous MITRE ATT&CK techniques, including T1083 (File and Directory Discovery), T1552 (Unsecured Credentials), T1078 (Valid Accounts), T1566 (Phishing), T1021 (Remote Services), T1105 (Ingress Tool Transfer), T1210 (Exploitation of Remote Services), T1071 (Application Layer Protocol), and T1589 (Gather Victim Identity Information).
Exploitation in the Wild
The exploitation phase was marked by a rapid operational tempo and significant breaches. ShinyHunters achieved full administrative control over targeted environments from a single developer token in under three hours, facilitating bulk data theft and the downstream compromise of over 200 SaaS customers, technology firms, airlines, and energy companies. In some instances, data exfiltration volumes exceeded 1TB.
Midnight Blizzard (APT29/Nobelium) utilized Claude to automate the creation of custom malware, phishing campaigns, persistence mechanisms, command-and-control (C2) infrastructure, and data exfiltration workflows. The group established feedback loops to rebuild malware when detected, targeting more than 20 government, defense, and diplomatic entities. Techniques employed included device-code phishing, ClickFix attacks, DNS hijacking via hotel Wi-Fi, WhatsApp account takeovers, and the deployment of multi-platform malware.
The Chinese-speaking group GTG-10007 also leveraged Claude as an orchestration layer for coordinated offensive operations, including intrusion attempts, reconnaissance, vulnerability research, exploit development, and intelligence collection. Their autonomous workflows enabled the discovery of zero-day vulnerabilities in major security products and the delivery of effective exploits for network and security appliances, targeting over 50 organizations across various sectors.
Victimology and Targeting
The campaign’s initial victimology was broad and indiscriminate, characterized by the mass scanning of 1.8 million Android APKs from global app stores. However, subsequent exploitation became highly targeted, focusing on organizations possessing valuable credentials and access. Affected sectors included government, defense, diplomatic, intelligence, foreign-policy, education, retail, energy, technology, healthcare, finance, manufacturing, SaaS providers, and airlines. Geographically, confirmed compromises were noted in Southeast Asian government agencies, European and Middle Eastern government networks, as well as global technology, energy, retail, and education sectors. The attackers exhibited a remarkable ability to pivot from indiscriminate credential harvesting to highly targeted exploitation, maximizing both financial and strategic impact.
Mitigation and Countermeasures
Organizations are urged to conduct immediate audits of all Android applications for hardcoded secrets using tools such as TruffleHog prior to release. Any credentials or tokens discovered in public or leaked APKs should be rotated and revoked without delay. Continuous monitoring for unauthorized use of API keys and tokens—particularly those associated with cloud and SaaS providers—is crucial. Implementing network monitoring to detect traffic to known malicious infrastructure, including policenationale[.]cc and suspicious Telegram channels, is also recommended. Security teams should stay informed by reviewing advisories from Anthropic and affected vendors regarding updates on AI guardrails and abuse detection mechanisms. Furthermore, organizations should enforce robust secret management practices, implement least-privilege access controls, and conduct regular security awareness training to mitigate the risk of credential exposure and AI-driven attacks.
References
- BleepingComputer: Hackers abused Claude to extract secrets from 1.8M Android apps
- TruffleHog Secret Scanner
- MITRE ATT&CK Framework
- ShinyHunters Profile
- APT29/Nobelium (Midnight Blizzard) Profile
- Telegram Abuse in Cybercrime
About Rescana
Rescana stands at the forefront of third-party risk management (TPRM), offering organizations a comprehensive platform to continuously monitor, assess, and mitigate cyber risks throughout their extended supply chain. With advanced analytics and threat intelligence capabilities, we empower security teams to proactively identify vulnerabilities, respond to emerging threats, and ensure compliance with industry standards. For further inquiries on how Rescana can assist in safeguarding your organization, please reach out to us at info@rescana.com.