504/69 Monday, September 14, 2026

Anthropic disclosed that it detected attackers using Claude to support credential-harvesting operations by building a process to download and analyze more than 1.8 million Android application files, or APKs, from multiple app distribution sources. The goal was to identify secrets embedded in applications and use the discovered data as an initial access vector. The reported figure refers to the number of APK files analyzed, not the number of applications or systems successfully compromised.
The attackers used 10 AWS EC2 compute instances to download and decompile APK files before scanning the code for embedded secrets using TruffleHog. Verified findings were sent to a Telegram group in real time. At the same time, the attackers conducted a separate GitHub data-harvesting operation, which included personal access tokens. Anthropic stated that credentials collected through both processes were used as initial access material in most confirmed intrusion cases linked to this operator.
The report stated that the attackers used AI to increase the efficiency of cybercriminal activity, ranging from reconnaissance and target discovery to tool development, credential discovery and validation, privilege escalation, and internal data collection from compromised systems. The incident highlights the risk of embedding secrets, tokens, or credentials in applications and source code, as such information can be discovered and collected at scale through automated processes. It also demonstrates how AI can accelerate and expand the scope of existing attack techniques.
