TL;DR
- A ShinyHunters-affiliated actor dumped more than 2,100 Azure AD session token sets across 40+ corporate tenants in about 34 hours – AI agents performed nearly all of the work.
- The same operator cluster escalated a single stolen developer token to full administrative control of a victim's cloud environment in roughly three hours.
- A Russian state-nexus espionage actor's primary access technique was device code phishing, abusing legitimate Microsoft 365 sign-in flows to steal authenticated sessions – no exploit required.
- AI credentials themselves are now a criminal target: fraudulent "discount Claude" resellers, evaluation-sandbox compromises, and mass scraping of exposed API keys are farming non-human identities (NHIs) for loot, compute, and cover.
- An Iranian-nexus actor's Windows implant extracted Chrome credentials by bypassing App-Bound Encryption, while a separate China-nexus group ran a standing vulnerability-research program against a major endpoint-security product.
- Anthropic's own conclusion: None of the disrupted operations depended on a genuinely novel technique. AI changed the economics of the attacks, not the attacks themselves.
Source: Anthropic, Detecting and Countering Misuse of AI, September 2026
Anthropic’s threat intelligence team spent eight months (December 2025 – August 2026) identifying and disrupting Claude misuse across cyber operations, influence operations, surveillance, scams, illicit distillation and more to compile their recent “Detecting and countering misuse of AI: September 2026” report.
At SpyCloud, we focus on what the cyber operations chapter means for identity threat protection: how attackers are getting in, staying in, moving through the AI supply chain itself, and what you can do to protect your organization. We also focus on how AI accelerates post-authentication abuse – including stolen-cookie selection, session replay, token exploitation, and automated privilege discovery.
Here’s what stood out.
For a foundational explanation of session hijacking, read what session hijacking is. For browser-fingerprint spoofing tradecraft, see how anti-detect browsers use stolen digital fingerprints. For broader MFA-bypass methods, see this overview of MFA bypass techniques.
The throughline: tokens, not passwords, are the target
Anthropic’s report tracks threat actors it calls Generative Threat Groups (GTGs). The clearest identity story comes from GTG-50014, a cluster of ShinyHunters-affiliated operators who ran distributed credential-harvesting pipelines. One actor decompiled 1.8 million Android APKs across a fleet of cloud workers, scanning for hardcoded secrets and feeding verified findings into a Telegram-based criminal storefront.
A separate affiliate breached a SaaS vendor, then used that foothold to pull data from roughly 200 of the vendor’s downstream customers, including a session-store dump of more than 2,100 Azure AD token sets spanning 40-plus corporate tenants – completed in about 34 hours, with AI agents performing nearly all of the work. Another compromise in the same cluster went from one stolen developer token to full administrative control of a victim’s cloud environment in about three hours.
Source: Anthropic, Detecting and Countering Misuse of AI, September 2026
This matches what we’re seeing in recaptured darknet data. SpyCloud recaptured 8.6 billion stolen session cookies circulating in criminal underground sources last year – active, post-authentication access that skips the login page (and every control sitting on it) entirely. A stolen session token doesn’t need to be cracked, guessed, or phished from scratch; it’s already authenticated. SpyCloud Workforce Threat Protection gives visibility into those stolen sessions and invalidate them before an attacker can weaponize them against you.
Multi-factor authentication succeeds, and the attacker still gets in
The report’s clearest authentication-bypass case is GTG-20006, an actor Anthropic assesses is consistent with Midnight Blizzard. Their primary access technique against Ukrainian and European government, diplomatic, and defense targets was device code phishing – abusing a legitimate cloud sign-in flow through a self-built framework the actor called “Embassy Kit” to run a Microsoft 365 token-theft campaign. Separately, an Iranian-nexus actor (GTG-30006) built tooling that compromised M365 mailboxes without triggering any OAuth consent flow at all: scripts decrypted DPAPI-protected keys, parsed token caches, and replayed the extracted tokens against Outlook’s web APIs while spoofing genuine desktop User-Agent strings – making the traffic indistinguishable from a real Outlook client.
Both cases illustrate the same gap: MFA protects the login event, not what happens after it. Device code phishing and adversary-in-the-middle (AitM) kits don’t beat MFA – they let the victim clear it for real, then walk away with the token minted at the end. That’s the same technique behind Tycoon 2FA and similar phishing-as-a-service (PhaaS) platforms, whose infrastructure SpyCloud helped a global takedown effort disrupted earlier this year by contributing victim identity intelligence. It’s also why SpyCloud’s Enterprise Protection solutions are built to catch what’s stolen after a clean, successful, alarm-free login – because that’s precisely the scenario device code phishing is designed to create. AI further accelerates that post-authentication abuse by helping attackers leverage valuable stolen cookies, replay sessions faster, mimic user behavior, and map privilege paths after login.
The attackers’ new focus: the AI supply chain
One of the report’s more novel findings for defenders: attackers are no longer just using AI, they’re farming access to it. Anthropic describes a criminal AI supply chain built around three payoffs for stealing AI credentials:
resale value of stolen credentials
running attack workloads at someone else’s expense
attributing malicious activity to the legitimate owner
GTG-50021, a Russian- and Ukrainian-speaking group, ran a fraudulent reseller offering “cheap Claude access” that was neither cheap nor actually Claude – customer traffic was silently proxied elsewhere while a credential harvester stole their Anthropic account credentials for resale. GTG-50020 went further, injecting malicious instructions into an AI vendor’s own automated evaluation sandbox to extract its production API keys, then reused those keys in a follow-on campaign against roughly 30 AI companies in four days. Elsewhere, ShinyHunters affiliates who obtained a victim’s AI keys during an intrusion simply switched their own attack workloads onto them.
Source: Anthropic, Detecting and Countering Misuse of AI, September 2026
This is the non-human identity (NHI) story SpyCloud has been tracking directly. We have recaptured more than 1T identity assets, including over 18.1 million exposed API keys, tokens, and more than 70B cookie records in 2025 alone, spanning payment platforms, cloud infrastructure, and developer ecosystems – the exact class of credential Anthropic describes attackers mining from GitHub, mobile app packages, Docker containers, and exposed code. API keys and session tokens don’t sit in isolation; they’re recaptured alongside session cookies, third-party credentials, and personally identifiable information (PII) that make follow-on abuse far more effective. SpyCloud Supply Chain Threat Protection is built for exactly this expanding, largely invisible layer of machine-to-machine access.
Malware still works, and EDR isn't closing the gap
Anthropic’s cases also confirm two things SpyCloud’s own data has shown for years: infostealer-style malware remains effective, and endpoint tools alone don’t stop it.
GTG-30006, an Iranian-nexus actor, built SECOMS64, a modular Windows implant that extracted Chrome credentials by bypassing App-Bound Encryption – Chrome’s own defense against exactly this kind of theft – while separately reconnoitering Microsoft Defender and Intune on the victim’s machine.
In a different cluster, GTG-10007, tracked to China-based operators, ran a standing vulnerability-research program specifically targeting a major endpoint-security product, producing multiple previously unknown vulnerabilities the actor validated in their own lab before using them against government targets globally.
SpyCloud’s 2026 Identity Exposure Report found the same pattern at scale: of the 13.2 million infostealer infections we recaptured data from last year, 40% occurred on endpoints that already had EDR or antivirus tools installed. Traditional endpoint defenses are necessary, but Anthropic’s case studies – actors researching and evading the very products meant to catch them – are a direct illustration of why they aren’t sufficient on their own. Proper, Post-infection remediation has to account for everything an infection exposes, not just the malware binary itself.
AI moves the barrier, not the ceiling
Anthropic’s own conclusion about all of this is worth quoting directly: “None of the operations in this report depended on an entirely novel technique that defenders haven’t seen before. Stolen credentials, unpatched edge devices, exposed services, and phishing are all familiar. What changed is the economics – reconnaissance, exploitation, tool development, and data processing that used to require a team now run in AI harnesses at machine speed. A lone French-speaking hacktivist (GTG-50029) reached advanced-persistent-threat-level impact acting alone, using Claude across the full kill chain from exploit development to backup poisoning. A state-nexus espionage operator and a financially motivated crew scraping mobile apps for secrets used near-identical methodology.”
For identity threat protection, that’s the real headline: the barrier to running a multi-victim, credential-driven campaign has collapsed, but the campaigns themselves still run on the same fuel they always have – exposed credentials, tokens, and sessions. That’s exactly the fuel supply SpyCloud exists to cut off.
How to architect defenses for AI-assisted session abuse
To counter AI-assisted post-authentication abuse, security teams need an architecture that monitors the session itself rather than the login event alone.
- Compromised-session monitoring: Detect stolen cookies and tokens tied to active accounts.
- Identity-risk enrichment: Combine recaptured identity intelligence with account context to prioritize high-value users and suspicious sessions.
- Automated cookie invalidation: Use SpyCloud Workforce Threat Protection and Identity Guardians to invalidate and remediate compromised cookies before attackers can reuse them.
- Token revocation: Revoke exposed session and refresh tokens to cut off post-authentication access.
- Device remediation: Pair session response with endpoint cleanup when malware-stolen cookies indicate device compromise.
- Escalation rules for high-value accounts: Apply tighter response paths for administrators, developers, and other privileged identities where compromised sessions have the highest impact.
Key takeaways for security teams
The report is an interesting and valuable look into the vast evolution cybercrime has had in the last several years. The ease in which AI misuse has allowed the ecosystem to blossom is not going unnoticed and there are things defenders need to be mindful of to protect organizations and their users from these, not so much new, but definitely advanced tactics.
- Prioritize Token Security: Treat session and refresh tokens as primary targets; password resets alone do not invalidate active stolen sessions
- Address Phishing Evolution: Recognize that device code phishing and AitM kits bypass traditional awareness training by using legitimate login flows.
- Govern AI Credentials: Apply the same governance to API keys and AI session tokens as production credentials
- Supplement EDR: Implement post-infection remediation that accounts for exposed identity artifacts, not just malware removal
- Monitor Supply Chain: Track third-party exposure, as a single SaaS compromise can impact thousands of downstream tokens
SpyCloud recaptures stolen credentials, session tokens, API keys, and other identity artifacts directly from successful phishing, infostealer malware, breaches and other underground sources, and automates remediation – including revocation through the identity providers you already run – before attackers get the chance to use them.
To see where your organization's tokens, credentials, and machine identities are already exposed, check your exposure now:
FAQs
AI changes session hijacking by accelerating the work that happens after credentials or cookies are stolen. Attackers can use AI to sort stolen-cookie inventories, identify the most valuable active sessions, replay those sessions faster, mimic normal user behavior, and automate privilege discovery inside the victim environment.
MFA protects the login event, but a replayed session uses the authenticated token or cookie created after that login succeeds. If an attacker steals that session artifact, they can bypass the login prompt entirely and inherit the trusted session unless the organization invalidates the cookie or revokes the token.
Security teams identify malware-stolen cookies by correlating recaptured cookie records with identity intelligence, endpoint signals, and account context. Look for exposed session artifacts tied to active users, signs of infostealer activity on the associated device, suspicious session reuse, and abnormal privilege access that appears after a legitimate login.
Infostealer malware is the most common compromise method, with 13.2 million infections recaptured in the last year – 40% occurring on endpoints already running EDR or antivirus. These infections extract passwords, session cookies, API keys, and tokens directly from browsers and applications before any security tool can intervene.