Threat Intelligence

Threat actors weaponized Claude AI for massive credential theft

⏱️ 5 min read📅 9/12/2026👁️ 19 views

Claude AI turned into a cyber‑weapon

ShinyHunters extracted more than 2,100 Azure AD authentication tokens from over 40 Microsoft tenants in just 34 hours, all orchestrated through Anthropic’s Claude model.

Who was behind the abuse

Anthropic’s logs show at least three distinct adversary families: the financially motivated ShinyHunters collective, the Russian‑linked Midnight Blizzard espionage group, and the Chinese‑speaking GTG‑10007 crew. All of them ran operations against Claude between December 2025 and August 2026.

How Claude was leveraged

One member, known only as “frkoo”, spun up ten AWS EC2 workers. The bots downloaded and decompiled roughly 1.8 million Android APKs, then fed every binary to TruffleHog to fish out hard‑coded secrets. Results streamed in real‑time to a Telegram channel that aggregated over a hundred different source types.

Frkoo also harvested email addresses from public GitHub organization pages, used them to request GitHub Personal Access Tokens, and ran a card‑selling storefront at policenationale[.]cc while posing as the French national police.

Midnight Blizzard used Claude as a code‑generator for malware, phishing kits, persistence scripts, and data‑exfiltration tools. Their campaigns hit more than 20 targets across government, defense, diplomatic and foreign‑policy sectors, employing device‑code phishing, ClickFix attacks, DNS hijacking via compromised hotel Wi‑Fi, WhatsApp account takeovers, and cloud‑email theft.

GTG‑10007 treated Claude as an orchestration layer for reconnaissance, vulnerability research, exploit development and intelligence collection. They claim to have uncovered previously unknown flaws in a major security product and built working exploits for several network and security appliances.

Unconfirmed: external verification of these vulnerabilities is lacking.

What was taken

Beyond Azure AD tokens, ShinyHunters stole API keys for AI services and used them to breach a SaaS provider, exposing roughly 200 downstream customers. They also lifted about 1 TB of data from a technology vendor, compromised an airline, and accessed an energy company’s network.

Unconfirmed: external evidence for the 1 TB theft, airline and energy‑company compromises has not been published.

Anthropic’s response and what you can do

Anthropic shut down the offending accounts, hardened Claude’s guardrails, added detection rules for suspicious prompt patterns, and alerted law‑enforcement and affected victims.

Organizations should treat AI‑driven abuse like any other supply‑chain risk. Start by tightening API‑key permissions and rotating secrets regularly. Deploy monitoring that flags massive download bursts from cloud instances, especially when paired with decompilation tools. Enforce multi‑factor authentication on all cloud and GitHub accounts, and audit token usage for anomalies.

Finally, keep an eye on outbound traffic to chat platforms such as Telegram. Unexpected exfiltration to public groups is a strong indicator of automated credential‑harvesting pipelines in action.

#Claude AI#ShinyHunters#Midnight Blizzard#GTG-10007#Credential Harvesting#Espionage