The hacker group ShinyHunters used the AI model Claude from Anthropic to automatically search 1.8 million Android apps for hard-coded credentials. This is revealed in the current threat report published by Anthropic on September 10, 2026. A single operator distributed the attack pipeline across ten cloud servers and forwarded captured passwords in real-time to Telegram channels.
Automated pipeline searches millions of app packages
The attack began with the mass downloading of APK files from several app stores. A person operating under the aliases frkoo, MeowSHA, and blazespider, attributed to the ShinyHunters group, subsequently unpacked the programs and used the open-source tool TruffleHog to search for hard-coded credentials in the code. According to the threat report from Anthropic, Claude took on various tasks in automating and evaluating the data stream. The entire pipeline ran in parallel across ten working servers at Amazon Web Services. The apps came from both official stores and alternative marketplaces, indicating a broad-based search not limited to individual platforms.
According to the company, found passwords, API keys, and authentication tokens were forwarded in real-time to Telegram groups sorted by more than a hundred different types of secrets – from cloud accesses to payment service keys. The report does not publicly disclose how many of the 1.8 million app packages actually contained usable credentials; it is also independently unverified how many of the found credentials were still valid at the time of disclosure.
Report also documents state-sponsored attackers
The app scan is just one of several cases in the current Anthropic report, which covers the period from December 2025 to August 2026. The Russian group known as Midnight Blizzard, also referred to as APT29, reportedly used Claude to automate parts of classic espionage attack chains. A Chinese-speaking group, internally referred to by Anthropic as GTG-10007, utilized the model for independent vulnerability analyses and the development of exploits against security products.
Anthropic states that it has suspended the affected accounts in all three cases and introduced additional detection mechanisms against similar abuse. The company has also informed authorities, affected companies, and partners from the security industry. As Anthropic already admitted in the summer, these are not the first security incidents surrounding its models this year – at that time, test environments had unintentionally gained access to foreign systems. The current report, however, concerns the targeted, intentional use by criminals and allegedly state-sponsored groups.
It will be crucial whether account suspensions can effectively combat such distributed and anonymous abuse as long as AI accesses remain available through open APIs and resellers. Anthropic announces stricter automated abuse detection; whether it will stop similar campaigns before a million-fold scan will be shown at the earliest in the next threat report.


