Tech · Anthropic
Ai Enabled Cyber Threats Mitre Attack
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
★ Tier-1 Source
In a new report, they seek to answer that question.
Key facts
- The team examine 832 accounts that were banned for malicious cyber activity between March 2025 and March 2026 and map them onto MITRE ATT&CK, a longstanding database of the tactics and techniques used
- The most common AI-enabled activities in their database related to preparing for a cyberattack, such as writing malware (560 of the 832 accounts they studied, or 67.3%, used AI for this purpose)
- Mapping it against the MITRE ATT&CK framework shows that the actor used 30 techniques across 13 tactics, which was comparable to many medium-risk actors in their dataset
- For example, the use of AI for account discovery—identifying valid accounts inside a compromised environment—rose 8.9%, while AI-assisted phishing—a common technique to gain access to a system—fell
Summary
As AI transforms the nature of and methods behind cyberattacks, how well do the techniques and frameworks used by the security community hold up? Malicious actors are using AI in ways that make them more dangerous. Cyberattacks are becoming more autonomous, and the fact that AI can be used to chain together many parts of the attack means that the old ways of differentiating high- from low-risk actors are no longer as effective. The MITRE ATT&CK framework does not fully capture the tools and activities that make AI-enabled attackers so dangerous.