
Anthropic says multiple threat groups, including financially motivated and state-sponsored espionage groups linked to Russia and China, have tried to misuse its Claude AI model for malicious purposes.
The AI company says that between December 2025 and August 2026, it recorded various forms of abuse of AI, including for cyber and influence operations, surveillance, fraud, biological and conventional weapons development, and pattern distillation.
During the eight-month period, Anthropic disrupted several activities related to the ShinyHunters collective, known for massive data theft attacks that typically begin with social engineering and account compromise.
An alleged French-speaking member of the group using the handle “frkoo” distributed a credential-harvesting pipeline among ten AWS EC2 employees who downloaded from multiple stores and then scanned for secrets in 1.8 million Android APKs.
“This pipeline massively downloaded 1.8 million individual Android APKs from multiple app store sources, decompiled them, and scanned them for hard-coded secrets with TruffleHog.” Anthropic explains.
“The verified findings were directed in real time to a Telegram group organized in over 100 types of sources.”
The same actor uses a separate automated process to collect GitHub organization email addresses and use them to obtain GitHub Personal Access Tokens (PATs).
The two channels provide initial access credentials that “frkoo” uses “for the majority of confirmed breaches” linked to the hacker.
Anthropic says “frkoo” also set up a card shop on policenationale(.)cc, posing as the French National Police, to sell records of stolen payment cards, full cardholder information and an interactive map of victims’ addresses.
The alleged members of ShinyHunters have also stolen AI API keys and used them to infiltrate other organizations or for intelligence activities.
In one case, they breached a software-as-a-service provider and stole data belonging to about 200 downstream customers.
Quick attacks
Using the suspected threat actor’s Claude AI, ShinyHunters took approximately 34 hours to extract authentication data and obtain more than 2,100 sets of Azure AD authentication tokens associated with over 40 individual Microsoft enterprise tenants. According to Anthropic, “AI agents have done almost all the work.”
Additional malicious activity involving Claude and attributed to affiliates of ShinyHunters included infiltrating a technology provider and stealing 1TB of data, compromising an airline and accessing energy company systems.
ShinyHunters moved quickly after gaining initial access. In the case of an enterprise software company, hackers undertook a massive data theft in just a few hours.
In another case, the AI company says an attacker went from one stolen developer token to full administrative control in less than three hours.
Russian and Chinese hackers
Anthropic’s report also highlighted activity attributed to the Russian spy group Midnight Blizzard, which used Claude to automate malware development, research, infrastructure acquisition, phishing, persistence, command and control (C2) operations, and data exfiltration.
The threat actor also created a feedback loop that restores malware when security products detect it.
Anthropic oversees Midnight Blizzard targeting over 20 government, defense, diplomatic, intelligence and foreign policy entities.
The campaigns included device code phishing, ClickFix attacks, DNS hijacking via compromised hotel Wi-Fi providers, WhatsApp account hijacking, cloud email theft and Windows, Android and iOS malware, with Claude being used throughout all stages of the attack.
Midnight Blizzard automates its operations through AI-driven workflows built around Claude Code skills, with a human operator essentially modifying those skills as they need refinement.
Anthropic also described an espionage operation attributed to a Chinese-speaking group tracked as GTG-10007 where Claude was used “as the engineering and orchestration layer of a coordinated offensive program involving various tasks,” such as:
- attempts to penetrate production systems
- intelligence on foreign government networks in the Middle East, Europe and Southeast Asia
- ongoing efforts to research vulnerabilities and develop exploits against major endpoint security products
- malware development
- building an information gathering platform
Spy group GTG-10007 ran autonomous vulnerability research workflows while human operators were away, which uncovered multiple previously unknown vulnerabilities in a major security product.
In addition, the automated effort also provided “working exploits for several families of network and security devices.” The actor then used the exploit code against several government organizations around the world.
The group’s operations targeted around 50 organizations in government, education, retail, energy, technology, healthcare, finance and manufacturing, with confirmed deals in an education technology company, a retailer and a government agency from Southeast Asia.
The AI company notes that it has stopped actors from using Claude for malicious activities and has banned the threat actor’s account.
In addition, Anthropic adjusted its safeguards based on observed malicious use, added measures to more quickly detect future abuse, and contacted authorities, industry partners, and victims.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital meeting on what AI attacks are changing, what defenders need to stop doing, and how to validate, solve, fix, and revalidate at machine speed.
