Home » Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Artificial intelligence is rapidly changing the way software is developed, analyzed, and secured. However, the same capabilities that help developers inspect applications can also be misused by cybercriminals to automate reconnaissance, identify exposed secrets, and accelerate data theft.
According to Cybersecurity News, threat actors suspected of having links to the ShinyHunters extortion collective used Anthropic’s Claude AI to analyze millions of Android application packages and search for hardcoded credentials and sensitive information.
The activity forms part of a broader wave of AI-assisted cybercrime in which attackers use AI agents not only to write code, but also to inspect environments, identify valuable targets, develop attack tools, and automate exfiltration workflows.
Anthropic’s threat intelligence findings describe an operation in which a French-speaking threat actor used Claude to support a large-scale credential-harvesting pipeline.
The operator distributed the workload across approximately ten cloud-hosted workers. These systems decompiled roughly 1.8 million Android application packages, commonly known as APKs.
The objective was to search application code for hardcoded secrets that developers may accidentally leave inside mobile applications.
Potentially exposed information can include:
Mobile applications frequently contain configuration data because applications need to communicate with backend services, analytics platforms, payment systems, advertising networks, and cloud infrastructure.
When developers embed sensitive credentials directly into an APK, those values can often be recovered through reverse engineering or decompilation.
The campaign demonstrates how AI can make that process faster by helping attackers search large volumes of application code and prioritize information that may be useful for further compromise.
The stolen information was reportedly fed into a criminal storefront that sold compromised payment-card data and victim geolocation maps.
This shows that the campaign was not limited to passive research.
The attackers were building an operational pipeline in which:
Android application packages → automated decompilation → secret discovery → credential harvesting → criminal resale
The stolen secrets could potentially provide access to backend services, developer platforms, cloud resources, or third-party systems connected to the affected applications.
Even when a discovered key does not immediately provide direct access to a production environment, it can still help attackers map the target’s infrastructure and identify additional paths for compromise.
The combination of automated discovery and criminal monetization increases the potential impact of exposed secrets.
Android applications are distributed to users and must be treated as potentially accessible to anyone who downloads them.
Attackers can inspect APK files using reverse-engineering tools, extract resources, decompile application code, and search for embedded credentials.
Developers sometimes assume that a key is protected because it is:
These techniques do not provide reliable protection.
Obfuscation may slow down analysis, but it does not eliminate the possibility of recovering secrets. Encoding is also not encryption. If an application contains the information required to decode a credential, an attacker may be able to recover it.
The safer approach is to keep sensitive credentials on trusted backend systems and issue narrowly scoped, short-lived tokens to mobile applications.
Traditional application analysis can require significant time and technical expertise.
An attacker may need to:
AI agents can assist with several of these activities.
They can help classify files, identify suspicious strings, recognize common credential formats, generate scripts, interpret application logic, and prioritize targets.
This does not mean that AI independently performs every part of the operation. Human operators still define objectives, provide infrastructure, review results, and make decisions. However, AI reduces the amount of manual effort required to process large datasets.
The result is a lower barrier to entry for attackers who may not have the same level of expertise as advanced threat groups.
Anthropic described a pattern in which operators provide Claude with a broad objective and allow the model to investigate systems, write scripts, and iterate through technical tasks.
This behavior has been described as “vibe hacking.”
In this model, the attacker does not necessarily need to understand every technical detail of the target environment. Instead, the operator gives the AI agent a goal and allows it to help determine how to achieve that goal.
The same approach can be used for:
The Android APK campaign is especially concerning because it shows how AI-assisted analysis can be applied at scale.
Rather than manually examining a small number of applications, attackers can distribute the task across cloud workers and use AI to process large quantities of code.
Organizations developing Android applications should assume that any credential embedded in an APK may eventually be exposed.
Security teams should monitor for:
Developers should also scan application packages before release and continuously review previously published versions.
A secret discovered in an old APK remains a risk even after the application is updated. If the credential was never revoked, attackers may continue using it.
API keys, database passwords, cloud credentials, and private tokens should not be embedded directly into mobile applications.
Sensitive operations should be performed by backend services that can enforce authentication, authorization, rate limits, and monitoring.
Mobile applications should receive tokens with limited permissions and short expiration periods.
A compromised token should not provide unrestricted access to an entire cloud account or backend environment.
If a credential is discovered inside an APK, organizations should:
Simply deleting the credential from the latest source code is not enough if older APK versions remain available.
Application security pipelines should scan:
Secret scanning should identify both known credential formats and organization-specific patterns.
Even if a credential is exposed, strong backend monitoring can limit its usefulness.
Organizations should detect:
The campaign involves multiple stages, from application analysis and credential discovery to possible backend access and data theft. Seceon’s platform can support visibility across these stages.
Seceon’s aiXDR-PMax can help detect suspicious endpoint and workload behavior associated with automated application analysis.
Relevant activity may include:
If attackers use compromised developer systems or cloud-hosted workers, endpoint and workload telemetry can help identify abnormal execution patterns.
aiSIEM / CGuard can correlate activity across identity, endpoint, cloud, application, and network environments.
It can help security teams connect:
This correlation is important because the initial APK analysis may not look malicious by itself. The risk becomes clearer when it is linked to unusual credential use or suspicious backend access.
aiSecurityScore360 can support exposure assessment by helping organizations identify weaknesses in their external attack surface.
Relevant areas include:
If an exposed mobile credential leads to an internet-facing backend service, attack-surface visibility can help prioritize the associated risk.
aiBAS360 can help validate whether security controls are capable of detecting attack paths involving exposed application secrets.
Security validation scenarios can include:
This helps organizations test whether their defenses can detect the complete sequence rather than only isolated indicators.
The campaign also highlights the growing risk of AI agents being used to automate offensive security activity.
Seceon’s upcoming aiTRiSM is relevant to this emerging AI security challenge because organizations need visibility into how AI agents and AI-enabled workflows are introduced and used across their environments.
aiTRiSM is designed to help organizations:
In this campaign, aiTRiSM would address the AI-enabled operational dimension, while aiXDR-PMax and aiSIEM / CGuard remain central to detecting the actual endpoint, cloud, identity, and data-access activity.
The use of Claude in this campaign demonstrates that AI security is no longer limited to protecting AI models or chat interfaces.
Organizations must also consider how attackers use AI to:
At the same time, organizations deploying AI internally must ensure that their own AI agents do not receive excessive access to source code, credentials, cloud resources, or production data.
AI agents should be treated as powerful identities with controlled permissions, clear boundaries, monitoring, and audit trails.
The reported use of Claude to analyze approximately 1.8 million Android applications shows how AI can transform credential discovery from a manual task into a scalable operation.
The central weakness is not Claude itself. The deeper problem is the continued practice of embedding sensitive credentials inside applications that attackers can download and inspect.
Once exposed, those credentials may be reused against backend services, cloud resources, payment systems, and other connected environments.
Organizations should combine secure mobile development practices with secret scanning, credential rotation, API monitoring, cloud visibility, and behavior-based detection.
Seceon’s aiXDR-PMax, aiSIEM / CGuard, aiSecurityScore360, and aiBAS360 can help defend the technical attack path, while aiTRiSM (Upcoming) can support visibility and governance as AI agents become more deeply involved in both legitimate development and malicious cyber operations.
Copyright @Seceon Inc 2026. All Rights Reserved.