Anthropic TI: ShinyHunters affiliate used Claude to strip secrets from 1.8M Android APKs
Anthropic’s September 2026 Threat Intelligence report (activity December 2025–August 2026) case GTG-50014 covers ShinyHunters-affiliate smash-and-grab operators. One French-speaking operator (aliases MeowSHA / frkoo / blazespider) ran a Claude-accelerated credential pipeline across ten AWS EC2 workers that mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog, routing verified findings to a Telegram group with over 100 source types. A parallel GitHub organisation-email harvester fed stolen GitHub Personal Access Tokens. Anthropic says those two pipelines supplied initial-access credentials for the bulk of confirmed breaches tied to frkoo. Same case cluster includes a carding storefront at policenationale[.]cc / autoshop, Azure AD token theft via AI agents (reported ~2,100 token sets across 40+ Microsoft tenants in ~34 hours in wire coverage), and SaaS secondary victim data theft. Distinct from desk card anthropic-gtg20006-midnight-blizzard-20260911 (Russian espionage malware-rebuild) and from adapthealth-shinyhunters-20260909 (named victim). Anthropic disrupted the misuse. Primary: Anthropic TI report; wire: BleepingComputer (11 Sep).
- Product
- Anthropic Claude (misuse of production models); Android APK secret mining
- Versions
- n/a (account misuse / agentic credential harvesting; not a product CVE)
- Exploited in Australia?
- unknown
- Patch to
- Rotate secrets found in mobile binaries; hunt unexpected GitHub PATs and Azure AD token issuance; treat APK-hardcoded credentials as compromised
Primary: Anthropic — Detecting and countering misuse of AI (Sep 2026 TI) · Vendor: Anthropic Threat Intelligence · BleepingComputer (11 Sep 2026)
