Skip to content
Tech News
← Back to articles

Hackers abused Claude to extract secrets from 1.8M Android apps

read original get Yubico YubiKey 5 NFC Security Key → more articles
Why This Matters

Anthropic's disclosure shows AI models are now standard tooling in the attack chain, not just a theoretical risk: a ShinyHunters-linked actor used Claude to build a pipeline that decompiled 1.8 million Android APKs and harvested hardcoded secrets at scale. That matters because the weak link is developer hygiene — leaked API keys and tokens baked into shipped apps — which AI automation can now mine industrially. It also raises pressure on AI vendors to police misuse spanning criminal crews and state-linked espionage groups.

Key Takeaways
Worth a Look

Yubico YubiKey 5 NFC Security Key — Since attacks like ShinyHunters' typically start with stolen credentials and social engineering, a hardware security key is one of the strongest defenses you can add to your accounts. The YubiKey 5 NFC plugs into USB-A or taps against a phone via NFC, and works with major services that support FIDO2/WebAuthn logins. It's a simple physical step that keeps a phished password from being enough.

See Yubico YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes.

The AI company says that between December 2025 and August 2026, it recorded various forms of artificial intelligence misuse, including for cyber and influence operations, surveillance, scams, development of biological and conventional weapons, and model distillation.

Over the eight-month period, Anthropic disrupted several activities linked to the ShinyHunters collective, infamous for massive data theft attacks that typically begin with social engineering and account compromise.

An alleged French-speaking member of the group that used the handle ‘frkoo’ distributed a credential-harvesting pipeline across ten AWS EC2 workers that downloaded from multiple stores and then scanned for secrets in 1.8 million Android APKs.

“This pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog,” Anthropic explains.

“Verified findings were routed in real time to a Telegram group organized into over 100 source types.”

The same actor used a separate automated process to collect GitHub organization email addresses and used them to obtain GitHub Personal Access Tokens (PATs).

The two pipelines provided initial-access credentials that 'frkoo' used "for the bulk of the confirmed breaches" associated with the hacker.

Anthropic says that 'frkoo' also set up a carding shop at policenationale[.]cc that impersonated the French national police to sell stolen payment-card records, full cardholder information, and an interactive map of victim addresses.

Suspected ShinyHunters members also stole AI API keys and used them for breaching other organizations or for reconnaissance activity.

... continue reading