Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes.
The AI company says that between December 2025 and August 2026, it recorded various forms of artificial intelligence misuse, including for cyber and influence operations, surveillance, scams, development of biological and conventional weapons, and model distillation.
Over the eight-month period, Anthropic disrupted several activities linked to the ShinyHunters collective, infamous for massive data theft attacks that typically begin with social engineering and account compromise.
An alleged French-speaking member of the group that used the handle ‘frkoo’ distributed a credential-harvesting pipeline across ten AWS EC2 workers that downloaded from multiple stores and then scanned for secrets in 1.8 million Android APKs.
“This pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog,” Anthropic explains.
“Verified findings were routed in real time to a Telegram group organized into over 100 source types.”
The same actor used a separate automated process to collect GitHub organization email addresses and used them to obtain GitHub Personal Access Tokens (PATs).
The two pipelines provided initial-access credentials that 'frkoo' used "for the bulk of the confirmed breaches" associated with the hacker.
Anthropic says that 'frkoo' also set up a carding shop at policenationale[.]cc that impersonated the French national police to sell stolen payment-card records, full cardholder information, and an interactive map of victim addresses.
Suspected ShinyHunters members also stole AI API keys and used them for breaching other organizations or for reconnaissance activity.
... continue reading