Cyber operations · GTG-50021
Fake AI Reseller Services and Credential Theft: GTG-50021 Case
This page is an English translation of the relevant content from Anthropic's September 2026 report, pages 28–30. Actor attribution and activity descriptions come from that report; this site has not independently verified all real-world outcomes.
According to Anthropic's report, the AI supply chain has become a target, loot, and source of attack compute for malicious actors. AI access in the form of stolen API keys, session tokens, and devices is increasingly the sole objective of multiple criminal groups. GTG-50021 is a fake AI reseller service operated by a Russian- and Ukrainian-speaking actor. Customers thought they were buying discounted Claude access, but their traffic was silently routed to other models; the reseller tool also installed a credential collector on the device, reselling account credentials to other proxy networks.
What happened
The capability uplift that comes with AI access is highly sought after by malicious actors and the broader criminal economy. AI access in the form of stolen API keys, session tokens, and devices is increasingly the sole objective of multiple criminal groups. These groups then often sell that access through brokers, who typically feed it into fake AI reseller networks that rotate through new stolen API keys and session tokens until their usage limits are exhausted. Malicious actors also use, or buy from brokers, these stolen API keys and session tokens for their cyberattack operations.
A criminal AI supply chain has established a range of avenues to harvest victims' API keys and session tokens. One method involves disguising malware as a legitimate AI service provider. Actors set up websites claiming to be intermediary services between multiple AI models and offering discounted access to frontier AI models. Website visitors are compromised in multiple ways, the most persistent of which is having victims download and install malicious client applications, often disguised as popular AI tools (including Claude Code), that are actually credential collectors gathering all credentials and authenticated session tokens on the victim's device and sending them to the attacker. This includes any AI-related session tokens or API keys on the victim's device. Because the victim's API keys or accounts may be identified as compromised and reset, the credential collector continues to identify any new sessions on the device and send them to the actor. In this way, the actor effectively mimics the same fake reseller networks they supply with stolen credentials, but instead they use this scheme to have victims continuously supply the attacker with credentials, which are then sold to fake resellers.
GTG-50021 is a group engaged in similar activity. They are a Russian- and Ukrainian-speaking group, one of whom uses the alias "kl1zy." They operated a fake AI reseller business offering cheap Claude access—which turned out to be neither cheap nor actually Claude. Customers thought they were buying discounted Claude access, but their traffic was actually silently proxied to another AI model, while the reseller's tool installed a credential collector that stole their Anthropic account credentials and resold them to other AI proxy resellers for malicious use.
There are also groups that attempt to target the AI ecosystem and supply chain itself, seeking access to restricted models through AI vendors, evaluation organizations, and trusted access programs. For example, multiple actors were observed intruding into AI wrapper services' implementations of LiteLLM—they used prompt injection to exfiltrate the production API keys used in their cloud-hosted container environments.
Fake resellers are increasingly powered by stolen access. Most commonly, this comes from API keys and session tokens that legitimate customers inadvertently expose in their products, applications, and public code (such as GitHub, mobile app installation files, Docker containers, websites, and chatbots). Malicious actors continuously mine these sources for exposed keys and analyze them for authentication abuse avenues.
An operator who obtains AI credentials gets three things at once: loot—stolen keys and accounts have resale value in established markets; compute—having credentials means their attack workloads can run at someone else's expense; and cover—activity is attributed to the legitimate owner of the credentials.
One hacktivist campaign (described later in this report) ran entirely on stolen API keys for a month. ShinyHunters affiliated members switched their own attack workloads to victims' AI keys after obtaining them during intrusions. GTG-50020 first took the production keys of an AI vendor's evaluation sandbox after intruding into it.
AI API keys and session tokens are the target; the integrations customers build around AI (such as sandboxes, proxies, and resellers) are part of the attack surface. Organizations should treat AI keys and proxy integrations as seriously as production credentials—because attackers treat them just as seriously. AI access should only be purchased through authorized channels. A discount that claims to require routing traffic and credentials through an unknown intermediary poses significant risk to user data and systems.
What the report observed
The report confirmed the chain of fake resale, traffic redirection, and credential resale, placing it within the larger criminal supply chain: stolen access is both the target and a source of compute for subsequent attacks.
The report lists related indicators of compromise (domains, etc.) at the end for defenders to investigate. Per this site's safety boundaries, specific indicator values are not reproduced.

Confirmed & unknown
Confirmed
- The report confirms the existence of fake resale marketed as discounted Claude
- The report confirms customer traffic was routed to other models and credential collectors were installed on devices
- The report confirms stolen credentials enter other proxy reseller networks
Unknown
- The total number of affected users and the amount of financial losses are not given in the report
- Which attacks the resold credentials were ultimately used in is not mapped one-to-one in the report
- Whether all the fake websites stopped operating after being banned is not claimed in the report
Platform response
The report discloses this type of activity as a supply chain risk and shares intelligence with industry partners. This site does not reproduce the specific indicator values listed in the report.
Limits of response:Disclosure and banning can disrupt abuse of Claude, but they do not mean the entire resale black market has disappeared.
Takeaways
- Only purchase AI services through official channels; "especially cheap Claude" is itself a risk signal.
- Don't install unknown "AI clients" or browser plugins just to get a discount.
- Once API keys and login sessions are leaked, they may be resold to completely unrelated attackers.