TTO-2026-0914-126 · September 14, 2026 AI AbuseNation-StateCredential Theft

Anthropic Documents Eight-Month Claude Abuse Campaign by ShinyHunters, Midnight Blizzard, and GTG-10007

anthropic.comShinyHunters frkooMidnight Blizzard APT29GTG-10007 China-nexus1.8M Android APKs2,100 Azure AD token setsDrone SDK theftDec 2025 - Aug 2026

Summary

Anthropic published a threat intelligence report on September 10, 2026 documenting eight months of Claude abuse by three distinct threat clusters between December 2025 and August 2026: the ShinyHunters collective, the Russian state-sponsored group Midnight Blizzard (APT29/Nobelium), and a Chinese-speaking espionage group Anthropic designates GTG-10007. The disclosed activities span credential harvesting at industrial scale, AI-assisted malware development, drone system intellectual property theft, mass surveillance infrastructure, and influence operations. Anthropic states it disrupted all documented campaigns by banning the relevant accounts and modifying detection systems.

Timeline

DateEvent
Dec 2025Anthropic begins observing coordinated misuse of Claude by multiple threat clusters
Dec 2025 - Aug 2026ShinyHunters affiliate frkoo runs 1.8M Android APK credential pipeline; Azure AD token harvesting campaign runs in parallel
Early 2026Midnight Blizzard uses Claude for malware lifecycle automation targeting 20+ government and diplomatic entities
Mid 2026GTG-10007 uses Claude as orchestration layer for intrusion, vulnerability research, and intelligence collection
Sep 10, 2026Anthropic publishes threat intelligence report

What Happened

ShinyHunters — industrial-scale credential harvesting. A French-speaking ShinyHunters member operating as frkoo deployed a credential-harvesting pipeline across ten AWS EC2 workers. The pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app stores, decompiled them, and used TruffleHog to scan for hardcoded secrets including API keys, authentication tokens, and database credentials. Claude classified and triaged the resulting volume of findings. Verified credentials were routed in real time to a Telegram group organized into more than 100 source type categories. In a separate operation, frkoo extracted 2,100 sets of Azure AD authentication tokens linked to more than 40 corporate Microsoft tenants in approximately 34 hours.

Midnight Blizzard — AI-assisted malware development. The Russian state-sponsored group used Claude to write self-modifying code designed to evade antivirus detection, generate command-and-control communication protocols, and automate reconnaissance against more than 20 government and diplomatic entities. Some intrusion activity ran through compromised hotel guest Wi-Fi networks, a technique Microsoft separately documented in July 2026 as CaptiveCrunch. Midnight Blizzard also used Claude to steal a complete proprietary software development kit for a drone vision system.

GTG-10007 — AI-orchestrated espionage. The Chinese-speaking group used Claude as an orchestration layer across multiple phases of intrusion operations: initial reconnaissance, vulnerability research, exploit development, lateral movement automation, and intelligence collection and summarization across multiple sectors and geographies.

Anthropic states that in all documented cases it identified the abuse, banned the relevant accounts, and modified its systems to improve detection. The company notes that Claude’s responses to misuse attempts — including refusals and modified outputs — provided signals that assisted in identifying and disrupting the campaigns.

Domain Intelligence

anthropic.com — 57.25

anthropic.com scores at 57.25, in the low-trust range. Anthropic is the reporting party in this bulletin — the organization that identified, investigated, and disclosed the abuse campaigns. The score carries a T6_CONSUMER_REPUTATION_PENALTY flag, which reflects consumer-facing reputation signals in the engine’s T6 layer rather than infrastructure deficiencies. This flag does not indicate a security concern about anthropic.com itself and should not be read as a finding about the quality of Anthropic’s threat intelligence disclosure.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 14, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026