Anthropic's official article illustration showing a secure laptop
Anthropic's official article illustration showing a secure laptop
+ Anthropic News

Anthropic maps AI-enabled cyber threats to MITRE ATT&CK

Anthropic analyzed 832 banned malicious cyber accounts and found AI use moving from basic access work into lateral movement, account discovery, and chained attack activity.

Anthropic published a June 3 report on AI-enabled cyber misuse, mapping 832 accounts banned for malicious cyber activity between March 2025 and March 2026 onto the MITRE ATT&CK framework. The company says the cases are only a subset of total banned accounts, limited to those where it had enough detail to assess attacker techniques.

The finding to watch is where AI is being used. Anthropic says malicious actors are not only using models to prepare attacks. They are increasingly applying AI deeper in the attack life cycle, including account discovery, lateral movement, privilege escalation, and chained workflows that can execute with less human input.

The shift is post-compromise

The easiest AI-cyber story is phishing and malware drafting. Anthropic’s data points somewhere more operationally important. The most common activity in the dataset was still preparation: 560 of the 832 accounts used AI for malware writing. But Anthropic says a smaller set used AI for harder work, including 54 accounts that used it to help with lateral movement inside a compromised network.

The time trend is the clearer warning. Anthropic says its medium-or-higher risk classification rose from 33% of actors in the first six months of the study to 56% in the second six months. It also says account discovery rose 8.9%, while AI-assisted phishing fell 8.6%. That suggests a move away from only getting into systems and toward doing more once inside.

Those numbers do not prove that every attacker became more capable. They do suggest the risk signal is changing. If AI can help a weaker actor perform post-compromise tasks that previously required more skill, defenders cannot rely on old assumptions about what low-skill activity looks like.

832Banned malicious cyber accounts analyzedAnthropic
67.3%Used AI for malware writingAnthropic
6.5%Used AI for lateral movement assistanceAnthropic
56%Medium-or-higher risk in second halfAnthropic

Old skill signals are getting weaker

Anthropic says traditional risk signals are becoming less reliable. In its dataset, the least-skilled actors used about 16 distinct techniques on average, while the most skilled used about 20. The platform used - Claude Code, API, or chat interface - also did not correlate cleanly with risk.

That is the uncomfortable part. A model can give a less sophisticated actor access to more technique variety, and the surface they use may not reveal much. The stronger signal is what they are trying to do with the model. Anthropic says higher-risk actors concentrated AI use on more operationally demanding tasks such as account discovery, lateral movement, and privilege escalation.

Even that signal may not hold forever. Anthropic’s own analysis says broader AI misuse is moving in that direction. If many attackers begin using models for post-compromise work, defenders need to detect the orchestration pattern, not just the individual technique.

MITRE needs an AI layer

Anthropic’s critique of MITRE ATT&CK is not that the framework is obsolete. It is that many AI-specific behaviors are hard to express inside it. The report points to model-driven orchestration, sequential chaining, real-time decision making, and execution with minimal human intervention as behaviors that distinguish higher-risk actors but are not fully represented as attacker techniques.

That has a practical consequence for security teams. If a detection framework only records the human-visible step, it may miss the part that changed: a model planning the next move, selecting tools, chaining actions, or adapting to feedback. The same final action can carry a different risk profile when it is one step in an AI-assisted loop.

Sources

The AI Feed Desk

The AI Feed Desk

Editorial desk

The AI Feed Desk tracks AI provider updates, model releases, agent tooling, and enterprise adoption, turning fast-moving announcements into source-linked context for builders and operators.

Noticed a typo, incorrect information, or translation error?

Tell us so we can fix it.

Help Improve This Article

Related Articles

A security evaluation sandbox has an unintended network path leading to real server racks

Anthropic says Claude cyber evals reached real systems

Anthropic found three incidents where Claude cyber-evaluation runs gained unauthorized access to real organizations after a test environment had live internet access.

The AI Feed Desk

By The AI Feed Desk

Abstract editorial image of two AI model gateways, one broadly open and one restricted

Anthropic releases Claude Fable 5 and Claude Mythos 5

Anthropic's first broadly available Mythos-class model arrives as Claude Fable 5, with sensitive requests routed to Opus 4.8 and Mythos 5 reserved for trusted access.

The AI Feed Desk

By The AI Feed Desk

Parallel code-review lanes converge on a government security checkpoint

Alberta used Claude Code to scan 466 million lines of government code

Anthropic says Alberta used Claude Code agents to review legacy government systems, find vulnerabilities, generate fixes, and build continuous security-review agents.

The AI Feed Desk

By The AI Feed Desk

Prompt cards pass through a policy checkpoint before entering a model core

Anthropic adds Inference hooks for Claude Enterprise prompt control

Anthropic put Inference hooks into beta for Claude Enterprise, letting governed prompts pass through an organization's security server before Claude processes them.

The AI Feed Desk

By The AI Feed Desk

A governed cloud workspace connects an AI model core to a high-performance compute rack

Claude reaches Microsoft Foundry with Azure governance and GB300 compute

Anthropic made Claude generally available in Microsoft Foundry, while NVIDIA framed the Azure deployment as a GB300 Blackwell Ultra agent platform.

The AI Feed Desk

By The AI Feed Desk