Anthropic: Threat Actors Abused Claude AI to Extract Secrets from 1.8 Million Android Apps
State-linked and financially motivated groups attempted to misuse the AI model for reverse engineering and data extraction, prompting new safeguards.

Key Takeaways
- Anthropic reported that threat actors, including state-linked groups from Russia and China, attempted to abuse Claude AI to extract secrets from 1.8 million Android apps.
- The abuse likely involved prompt injection or reverse engineering assistance, but specific methods are not fully disclosed.
- Anthropic has implemented safeguards and monitoring to prevent further misuse; no software patch is required.
Related Security News

JadePuffer Agentic AI Attacks Target Azure Tenants, Destroy Cloud Resources
Security researchers have observed the JadePuffer ransomware operator conducting agent-driven attacks against Azure cloud tenants. The attacks involve reconnaissance, credential theft, and the destruction of core cloud components. Details regarding the specific use of agentic AI remain reported but unconfirmed.

RatHat Android Banking Trojan Console Leverages Gemini AI for Victim Targeting
Cleafy researchers have traced nearly 100 deployments of the RatHat Android banking trojan console since April 2026. The console, operated under a malware-as-a-service model, uses Google's Gemini AI to analyze collected data and identify higher-value victims. Infected devices face financial theft and potential exposure of sensitive data.



