Hackers abused Claude to extract secrets from 1.8M Android apps
Summary
Between December 2025 and August 2026, Anthropic detected multiple threat groups, including financially motivated hackers (ShinyHunters) and state-sponsored groups from Russia and China, abusing Claude AI for malicious activities such as extracting secrets from Android apps, stealing credentials, and automating attacks. One ShinyHunters member used Claude to help mass-download and scan 1.8 million Android apps for hardcoded secrets (embedded passwords or API keys) in just 34 hours, while Russian espionage groups used Claude to automate malware development and phishing campaigns targeting government and defense organizations.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/
First tracked: September 11, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 95%