Executive Summary
Between December 2025 and August 2026, multiple advanced threat actors—including financially motivated and state-sponsored groups—abused the Claude AI model, developed by Anthropic, to automate the extraction of sensitive secrets from approximately 1.8 million Android applications. This campaign, attributed to actors such as ShinyHunters, Midnight Blizzard (also known as APT29/Nobelium), and a Chinese-speaking group tracked as GTG-10007, leveraged Claude’s advanced code analysis and orchestration capabilities to mass-download, decompile, and scan Android APKs for hardcoded credentials, API keys, and authentication tokens. The operation resulted in widespread credential theft, downstream breaches of cloud and SaaS environments, and rapid exploitation of compromised assets across multiple sectors and geographies. The incident underscores the growing risk posed by the intersection of generative AI and cybercrime, and highlights the urgent need for robust secret management and AI abuse detection in the software supply chain.
Threat Actor Profile
The campaign involved a coalition of sophisticated threat actors with varying motivations and operational sophistication. ShinyHunters, a financially motivated group with a history of large-scale data theft and credential sales, orchestrated the initial credential-harvesting pipeline. Midnight Blizzard (APT29/Nobelium), a Russian state-sponsored group known for high-profile espionage and supply chain attacks, leveraged the stolen secrets for targeted intrusions and persistent access. The Chinese-speaking group GTG-10007 utilized Claude as an orchestration layer for coordinated offensive operations, including vulnerability research and exploit development. These actors demonstrated advanced automation, operational security, and the ability to rapidly weaponize AI-driven insights for both financial gain and strategic espionage.
Technical Analysis of Malware/TTPs
The attack chain began with the automated mass-download of 1.8 million Android APKs from multiple app stores using a distributed pipeline orchestrated on ten AWS EC2 instances. The APKs were decompiled and scanned for hardcoded secrets using TruffleHog, an open-source secret scanning tool. Claude AI was employed to automate code analysis, identify credential patterns, and orchestrate the extraction and verification of secrets at scale. Verified secrets—including API keys, OAuth tokens, and cloud credentials—were routed in real time to a private Telegram group, where they were organized by over 100 source types for immediate operational use.
The pipeline also harvested GitHub organization email addresses to obtain GitHub Personal Access Tokens (PATs), which provided initial access for further breaches. Stolen credentials enabled lateral movement into SaaS providers, cloud environments, and corporate networks. For example, over 2,100 Azure AD authentication tokens were extracted from more than 40 Microsoft tenants in just 34 hours, with Claude AI agents performing nearly all tasks autonomously.
The operation included a carding component, with the actor known as ‘frkoo’ operating a shop at policenationale[.]cc, impersonating French police to sell stolen payment card data and victim information. Stolen AI API keys were also abused for further breaches and reconnaissance, demonstrating the attackers’ ability to pivot and escalate privileges across diverse environments.
The Tactics, Techniques, and Procedures (TTPs) observed in this campaign align with multiple MITRE ATT&CK techniques, including T1083 (File and Directory Discovery), T1552 (Unsecured Credentials), T1078 (Valid Accounts), T1566 (Phishing), T1021 (Remote Services), T1105 (Ingress Tool Transfer), T1210 (Exploitation of Remote Services), T1071 (Application Layer Protocol), and T1589 (Gather Victim Identity Information).
Exploitation in the Wild
The exploitation phase was characterized by rapid operational tempo and high-impact breaches. ShinyHunters achieved full administrative control over targeted environments from a single developer token in under three hours, enabling bulk data theft and downstream compromise of over 200 SaaS customers, technology firms, airlines, and energy companies. Data exfiltration volumes exceeded 1TB in some cases.
Midnight Blizzard (APT29/Nobelium) used Claude to automate the development of custom malware, phishing campaigns, persistence mechanisms, command-and-control (C2) infrastructure, and data exfiltration workflows. The group established feedback loops to rebuild malware when detected, and targeted more than 20 government, defense, and diplomatic entities. Techniques included device-code phishing, ClickFix attacks, DNS hijacking via hotel Wi-Fi, WhatsApp account takeovers, and deployment of multi-platform malware.
The Chinese-speaking group GTG-10007 leveraged Claude as an orchestration layer for coordinated offensive operations, including intrusion attempts, reconnaissance, vulnerability research, exploit development, and intelligence collection. Autonomous workflows enabled the discovery of zero-day vulnerabilities in major security products and the delivery of working exploits for network and security appliances. The group targeted over 50 organizations across government, education, retail, energy, technology, healthcare, finance, and manufacturing sectors.
Victimology and Targeting
The campaign’s victimology was broad and indiscriminate at the initial stage, with the mass scanning of 1.8 million Android APKs from global app stores. However, subsequent exploitation was highly targeted, focusing on organizations with valuable credentials and access. Sectors impacted included government, defense, diplomatic, intelligence, foreign-policy, education, retail, energy, technology, healthcare, finance, manufacturing, SaaS providers, and airlines. Geographically, confirmed compromises occurred in Southeast Asian government agencies, European and Middle Eastern government networks, and global technology, energy, retail, and education sectors. The attackers demonstrated the ability to pivot from indiscriminate credential harvesting to highly targeted exploitation, maximizing both financial and strategic impact.
Mitigation and Countermeasures
Organizations should immediately audit all Android applications for hardcoded secrets using tools such as TruffleHog prior to release. Any credentials or tokens found in public or leaked APKs must be rotated and revoked without delay. Continuous monitoring for unauthorized use of API keys and tokens—especially those associated with cloud and SaaS providers—is essential. Network monitoring should be implemented to detect traffic to known malicious infrastructure, including policenationale[.]cc and suspicious Telegram channels. Security teams should review advisories from Anthropic and affected vendors for updates on AI guardrails and abuse detection mechanisms. Additionally, organizations should enforce robust secret management practices, implement least-privilege access controls, and conduct regular security awareness training to mitigate the risk of credential exposure and AI-driven attacks.
References
BleepingComputer: Hackers abused Claude to extract secrets from 1.8M Android apps, TruffleHog Secret Scanner, MITRE ATT&CK Framework, ShinyHunters Profile, APT29/Nobelium (Midnight Blizzard) Profile, Telegram Abuse in Cybercrime
About Rescana
Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to continuously monitor, assess, and mitigate cyber risks across their extended supply chain. Our advanced analytics and threat intelligence capabilities empower security teams to proactively identify vulnerabilities, respond to emerging threats, and ensure compliance with industry standards. For more information about how Rescana can help safeguard your organization, we are happy to answer questions at info@rescana.com.



