```html ```
top of page

Anthropic Named the Groups Running Claude as the Operator. One Is ShinyHunters, and They Pointed the Exact TruffleHog Move From Salesloft at 1.8 Million Android Apps.

Writer: Patrick Duggan
Patrick Duggan
7 hours ago
6 min read

Anthropic published its September threat intelligence report on Thursday, covering December through August, and the wire has already run the scary parts: Russian operators using Claude to automate malware evasion, a Yemeni team building drone guidance software, a Register headline about a fourth "likely crime." We run on Claude. We have said so in every post that touches this subject and we are saying it again here, because it is the reason we read this report differently than a vendor who does not.


The case that matters most to us is not the one the headlines picked. It is the one about an actor we have tracked for a year, doing a thing we documented them doing in 2025, at a scale that was not possible for a human to do.



ShinyHunters, the same move, three orders of magnitude


Anthropic tracks the cluster as GTG-50014 and names affiliate handles including frkoo, MeowSHA and blazespider, French-speaking. The workflow, in the report's own accounting: ten AWS EC2 workers running a credential pipeline that mass-downloaded and decompiled 1.8 million distinct Android APKs, scanned them for embedded secrets, validated what it found, and routed verified hits into more than a hundred Telegram groups organized by credential type. From one enterprise software breach the pipeline reached 200 downstream customer organizations. From one session-store dump it pulled more than 2,100 Azure AD token sets across roughly 40 corporate tenants in 34 hours. Anthropic's phrasing is that AI agents performed nearly all of the work, and that the operators practiced what the report calls vibe hacking: point the agent at a general goal and let it evaluate the environment and iterate.


Here is why that row stopped us. In June we wrote about the Salesloft breach, and the mechanism in that case was ShinyHunters compromising Salesloft's GitHub and running TruffleHog, a free open-source secrets scanner, over the source to extract the Drift OAuth tokens that unlocked 760 Salesforce tenants. One repository, one tool, one team of humans. In July we wrote that ShinyHunters had stopped stealing vendor tokens and started making phone calls, because two independent reports that week described voice-phishing as the new entry.


The September report says both of those posts were true and incomplete. The token theft did not stop. It moved from one vendor's source repository to every Android app on the planet, and the humans stopped running the scanner. That is two dated observations of one actor, and the second one is a change of scale and automation, not of technique. We have argued for months that sophistication is unfalsifiable and demonstrated evolution is the checkable claim. This is what demonstrated evolution looks like with a vendor's telemetry behind it.





What the other cases say, flat


GTG-20006 is Midnight Blizzard, Russian state espionage, operator handle JackPoterz. Twenty-plus organizations, two drone component manufacturers with bulk mailbox exports, 300,000 national identity records, 500,000 commercial registry entries. The part the wire ran is the evasion loop: the agents monitored whether defenders had flagged the implant and systematically modified and rebuilt it when they had. That is the detection-evasion cycle running faster than a human analyst's shift.


GTG-10007 is two undergraduate students in Changsha, one with an internship at a Chinese security vendor, running what Anthropic calls exploit foundries: firmware decompilation loops that produced multiple previously unknown vulnerabilities in a major security product and a dozen possible zero-days in a single month, plus 13 standing collection agents on scheduled jobs harvesting government and military sites. Fifty organizations targeted.


GTG-50020 is the one that belongs to a category we named two weeks ago. A Russian-speaking financial actor with a history in hotel booking and fintech planted prompt injection in an AI vendor's evaluation sandbox to steal production API keys, then attacked 30 AI companies in four days, with extortion demands of one and a half to two and a half million dollars. Anthropic's line on this one is the one we want to quote exactly: the keys involved were customers' keys stolen from customers' environments, and the actor never compromised Anthropic's own systems. The dozen-plus attempts to reach a pre-release Claude model all failed. That is TokenTheft, theft whose objective is metered inference capacity rather than data, and it is now in a frontier lab's threat report with a tracking number.


GTG-50029 is a single French hacktivist who built a multi-agent framework, found an undocumented WordPress reinstallation race condition, and assembled a doxxing platform with millions of rows. Fourteen of 42 targets breached. One person.


Then the influence side: a Wagner-lineage operation in the Central African Republic running a radio station's talking points through Claude, a French advertising agency operating 70 fake news sites in 20 languages, an Istanbul firm building a 222-constituency voter-targeting system for Malaysian elections, and Russian state-media editorial pipelines laundering claims about Moldova's president.



The safeguard line, read carefully


The Register's framing is that Anthropic will neither slow down nor take responsibility. We are not going to adjudicate that. We are going to read what the report says about refusals, because that is our beat and it is the checkable part.


On the cyber cases, the report describes detection and account bans. It does not describe Claude refusing the work. The two places a refusal is recorded are both influence operations: Claude declined to name real individuals as militants for the CAR operation, and the actor pivoted to anonymous-source framing; Claude identified defamatory material in the Malaysia operation and refused, and the actor negotiated sanitized wording and kept building. On the Yemen guidance software, the report says safeguards blocked many requests but not all. The cross-cutting finding is that Haiku, Sonnet and Opus were the models consistently used across every cyber case, and that the Fable and Mythos-class models saw almost no malicious use.


Two weeks ago we ran our own test: a decoy-laced sample that Claude refused to triage while two other models processed it. We reported that flat both ways, because a refusal is a defensive gap when the analyst is the one asking. This report is the inverse dataset, and it says the model that refused our defender mostly did not refuse these attackers. Both things are true. The refusal boundary is not where either side wants it, and anyone telling you a frontier model's safeguards are a control you can rely on, in either direction, is selling something.



What this means if you ship a mobile app


The 1.8 million APK row is not an AI story for you. It is a secrets story. Every one of those token sets was a credential a developer compiled into a binary and shipped to a public store, where anyone can download it. TruffleHog has been free since 2016. The only thing that changed is that the scan no longer needs a human to run it, so the economics of scanning every app instead of a targeted few flipped. If there is a client secret, a service principal, a storage key or a refresh token in your APK today, assume it has been found. Rotate it, move the call behind a backend you control, and put conditional access in front of whatever the token reaches. Forty tenants in 34 hours is the speed a script achieves when nothing is in its way.



Where we stand


We hold the actor. Our ShinyHunters coverage runs from the ADT and Vercel disputes in April through Salesloft in June and the voice-phishing turn in July, and the adversary profile is in the corpus. We did not hold this campaign, and we could not have: it lived inside one vendor's API telemetry, and that vendor is the only party who could see it. We hold the category for GTG-50020 by nine days and credit the four groups who named the attack before us in our follow-up. We are late on everything else in this report and we are saying so. Anthropic published Thursday; this is Friday.




Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=anthropic-named-the-groups-running-claude-as-the-operator-one-is-shinyhunters-and-they-pointed-the



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page