Summary
Anthropic published a threat intelligence report on September 10, 2026 documenting eight months of Claude abuse by three distinct threat clusters between December 2025 and August 2026: the ShinyHunters collective, the Russian state-sponsored group Midnight Blizzard (APT29/Nobelium), and a Chinese-speaking espionage group Anthropic designates GTG-10007. The disclosed activities span credential harvesting at industrial scale, AI-assisted malware development, drone system intellectual property theft, mass surveillance infrastructure, and influence operations. Anthropic states it disrupted all documented campaigns by banning the relevant accounts and modifying detection systems.
Timeline
| Date | Event |
|---|---|
| Dec 2025 | Anthropic begins observing coordinated misuse of Claude by multiple threat clusters |
| Dec 2025 - Aug 2026 | ShinyHunters affiliate frkoo runs 1.8M Android APK credential pipeline; Azure AD token harvesting campaign runs in parallel |
| Early 2026 | Midnight Blizzard uses Claude for malware lifecycle automation targeting 20+ government and diplomatic entities |
| Mid 2026 | GTG-10007 uses Claude as orchestration layer for intrusion, vulnerability research, and intelligence collection |
| Sep 10, 2026 | Anthropic publishes threat intelligence report |
What Happened
ShinyHunters — industrial-scale credential harvesting. A French-speaking ShinyHunters member operating as frkoo deployed a credential-harvesting pipeline across ten AWS EC2 workers. The pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app stores, decompiled them, and used TruffleHog to scan for hardcoded secrets including API keys, authentication tokens, and database credentials. Claude classified and triaged the resulting volume of findings. Verified credentials were routed in real time to a Telegram group organized into more than 100 source type categories. In a separate operation, frkoo extracted 2,100 sets of Azure AD authentication tokens linked to more than 40 corporate Microsoft tenants in approximately 34 hours.
Midnight Blizzard — AI-assisted malware development. The Russian state-sponsored group used Claude to write self-modifying code designed to evade antivirus detection, generate command-and-control communication protocols, and automate reconnaissance against more than 20 government and diplomatic entities. Some intrusion activity ran through compromised hotel guest Wi-Fi networks, a technique Microsoft separately documented in July 2026 as CaptiveCrunch. Midnight Blizzard also used Claude to steal a complete proprietary software development kit for a drone vision system.
GTG-10007 — AI-orchestrated espionage. The Chinese-speaking group used Claude as an orchestration layer across multiple phases of intrusion operations: initial reconnaissance, vulnerability research, exploit development, lateral movement automation, and intelligence collection and summarization across multiple sectors and geographies.
Anthropic states that in all documented cases it identified the abuse, banned the relevant accounts, and modified its systems to improve detection. The company notes that Claude’s responses to misuse attempts — including refusals and modified outputs — provided signals that assisted in identifying and disrupting the campaigns.
Domain Intelligence
anthropic.com — 57.25
anthropic.com scores at 57.25, in the low-trust range. Anthropic is the reporting party in this bulletin — the organization that identified, investigated, and disclosed the abuse campaigns. The score carries a T6_CONSUMER_REPUTATION_PENALTY flag, which reflects consumer-facing reputation signals in the engine’s T6 layer rather than infrastructure deficiencies. This flag does not indicate a security concern about anthropic.com itself and should not be read as a finding about the quality of Anthropic’s threat intelligence disclosure.
The Trust Observatory · thetrustobservatory.com · September 14, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026