Security analysts monitor a network operations center dashboard showing AI-driven infrastructure, cloud services, and threat alerts.
A year of AI-enabled attacks was scored, and the highest-scoring attacker didn't look dangerous by the usual yardstick. Anthropic's threat intelligence team found that the campaign it ranked at the very top looked unremarkable on technique count. That matters to anyone who runs Windows domains, Entra tenants or a SIEM. The detection logic most of us inherited leans heavily on counting and matching things.

Security analysts monitor a network operations center dashboard showing AI-driven infrastructure, cloud services, and threat alerts. The headline finding: 30 techniques, a perfect score​

Anthropic mapped 832 accounts it banned for malicious cyber activity between March 2025 and March 2026 onto MITRE ATT&CK. In all, it observed 13,873 actions across 482 unique techniques and all 14 ATT&CK tactics. Anthropic says these accounts are a subset of its total bans, chosen because it had enough detail to map them. This is a dataset of banned accounts on one vendor's platform. It is not a census of all attackers.

Anthropic scored each actor from 0 to 100 using a method it calls the AI Risk Enablement Score (ARiES). The standout was GTG-1002, the actor behind the espionage campaign Anthropic disclosed in November 2025. That campaign had a maximum risk score of 100 yet used a number of techniques comparable to medium-risk actors. Anthropic's own write-up puts the profile at 30 techniques across 13 tactics. It adds that the median actor used 16 techniques and that several low-risk actors also exceeded 30.

So the scariest actor in the dataset would have blended into the crowd on a technique-count chart. Anthropic's conclusion is that the attack stood out because of how the attackers used an AI agent to orchestrate the techniques, not because of how many it used.

What ARiES actually measures​

ARiES is Anthropic's own composite score. It is not a MITRE standard. It adds three components:

  • Threat (0–35): intent, technical sophistication, threat-intelligence signals and evasion.
  • Vulnerability (0–35): how much the model and interface enable the requested harm. APIs and agentic coding tools score highest because they can automate actions.
  • Impact (0–30): actual or potential real-world consequences attributable to the AI's involvement.

Anthropic chose an additive formula over a multiplicative one so that a missing component, such as no identified victim yet, doesn't zero out the others. The trade-off, in Anthropic's words, is that the scores are not predictions of attack success. They measure how concerning an AI-involved misuse case is. Treat the 100 as "Anthropic is very worried about this one", not as a forecast of damage.

The numbers that undercut the usual risk proxies​

Anthropic tested whether familiar attacker attributes predict risk:

  • Technique breadth: the correlation with risk score is only weakly positive (r = 0.27).
  • Technical sophistication: once removed from the composite to avoid circularity, it correlates with the remaining risk components at only r = 0.28. Removing it leaves the top six actors in the same rank order.
  • Skill versus technique count: the least-skilled actors averaged about 16 distinct techniques, against about 20 for the most skilled.
  • Interface: whether an actor used Claude Code, an API or a chat window did not correlate with risk level.

These findings come from one company's data and scoring system. They challenge shortcuts such as "many techniques means a sophisticated actor" or "agentic tool means scarier actor". They do not prove those signals are useless everywhere.

Where the risk concentrates: inside the network​

Most AI use in the dataset was preparatory. The most common activity was malware writing, used by 560 of the 832 accounts (67.3%). Anthropic's full report says the next most common techniques were obfuscation, collecting data from the local system, and impairing defenses.

The riskiest behavior was rarer. Only 54 of 832 actors (6.5%) used models for lateral movement. Those 54 averaged a risk score of 56.4, against a dataset mean of 46.8. Anthropic says no other technique had that much predictive power. The techniques most common among its highest-risk actors were:

  • Remote services over SSH and SMB
  • Valid accounts
  • OS credential dumping
  • Archiving collected data
  • Web shell deployment

Anthropic says these were three to five times more common among the highest-risk actors than in the overall population.

This is a correlation. The data does not show that lateral movement causes high risk scores. It does show that the actors using AI after getting in were the ones scored highest.

A shift toward post-compromise work​

The study also reports a drift over its twelve months:

  • The share of actors rated medium risk or higher rose from about 33% in the first half to about 56% in the second, roughly a 1.7-fold increase.
  • AI use for account discovery rose 8.9%, while AI-assisted phishing fell 8.6%.
  • Anthropic says this suggests attackers are applying AI deeper in the attack life cycle, once they are inside the system.

Anthropic itself cautions that better detection may have contributed to the rise. In its full report it also describes a shift of about 22.6 percentage points in the cohort. That differs from the 8.9% and 8.6% figures, so don't read those as percentage-point changes.

What GTG-1002 actually did​

Anthropic's November 2025 disclosure gives the operational picture. The company assesses with high confidence that the actor was a Chinese state-sponsored group. It manipulated Claude Code into attempting infiltration of roughly thirty global targets and succeeded in a small number of cases. Targets included large tech companies, financial institutions, chemical manufacturers and government agencies. MITRE tracks the activity as campaign C0062 and describes the actor as "likely China nexus". These are attributed assessments. No victims have been named.

According to Anthropic, the operators:

  • chose targets and built a framework around Claude Code;
  • split the work into small, innocuous-looking tasks;
  • told the model it was a legitimate security firm doing defensive testing, to get around its guardrails.

In the follow-up analysis, Anthropic says the setup ran Claude Code on a Kali Linux machine, with open-source penetration-testing tools exposed as Model Context Protocol (MCP) servers. It describes the AI as an autonomous operator, not a code-writing assistant. In one environment, Anthropic says the AI:

  1. exploited an SSRF vulnerability in a public-facing web server to proxy commands into the internal cloud environment;
  2. harvested SSH private keys and service account tokens from cloud metadata services and AWS Secrets Manager;
  3. used those credentials to move laterally;
  4. staged and compressed tens of thousands of proprietary records for exfiltration.

The final download to the attacker's machine was human-directed. Anthropic puts AI involvement at 80–90% of the campaign, with humans stepping in at roughly four to six critical decision points. Anthropic corrected an earlier error about speed. The AI made thousands of requests, often multiple per second, not thousands per second. The AI also made mistakes: it sometimes hallucinated credentials or claimed to have found secrets that were actually public.

The campaign was not a single dazzling technique. It was a chain: discovery, then credential access, then lateral movement, then collection and exfiltration, with an AI agent choosing the next step.

Why Windows and Microsoft 365 admins should care​

None of the evidence is specific to Windows, and none of it is a Microsoft vulnerability. But the lessons map directly onto Microsoft-centric estates. This part is my analysis, not Anthropic's.

  • Single events are weak signals. Account enumeration, SMB or RDP sessions, and credential use happen in normal administration every day. An alert on any one of them mostly generates noise. Sequence is where the signal is.
  • Time between steps carries information. Several hours between actions looks like an admin at work. The same actions across multiple systems within minutes looks different. Anthropic's report does not offer a validated threshold. You would have to baseline your own environment.
  • Identity is the connective tissue. Chains cross endpoints, identity providers, networks and cloud. Correlating them is a data-engineering problem before it is a detection problem. Whether your telemetry is complete, correlated and timely may matter more than how much of it you collect.
  • Watch the gaps in the dataset. Anthropic notes that Active Directory exploitation, Kerberos ticket attacks, cloud infrastructure manipulation (including Azure) and container escape were notably underrepresented. That reflects what these banned accounts did with this model. It is not evidence those attacks have gone away.

A sensible exercise is to write down two or three chains relevant to your environment and test whether your tooling can see them end to end. One example is discovery, then credential dumping, then remote-service logon to a new host, then archive creation. Then run benign admin workflows against the same logic to see how often it fires falsely.

A caution on the framework named in the opinion piece​

The TechRadar opinion piece that prompted this story was written by a vendor executive. It describes a behavioral detection framework called APEX, "Adversarial Pattern Extraction and Correlation", as developed around the Anthropic findings. I could not find APEX in Anthropic's published research. Anthropic names its own tools the LLM ATT&CK Navigator and ARiES. Treat APEX as the author's framing, not as part of Anthropic's or MITRE's work, until there is independent documentation.

The opinion piece also argues that AI is shortening the useful life of indicators of compromise. That is plausible, and it echoes the long-standing Pyramid of Pain argument. But Anthropic's statistics don't test it. The study questions technique-count and interface-based risk judgments. It does not show that IOC feeds are obsolete. The sound reading is that indicators remain useful for blocking known-bad activity and for retrospective hunting, but should not be the whole detection program.

What happens to ATT&CK​

Anthropic says the behaviors that distinguish the highest-risk actors have no ATT&CK IDs. They include autonomous orchestration, real-time pivot decisions and AI-directed execution without human intervention. All 13,873 observations mapped to existing categories, but the orchestration layer didn't. Anthropic says it is in active discussions with MITRE about how the framework might evolve. Anthropic is also building detection signals for patterns such as multistep autonomous execution, AI-directed pivots and tool-augmented operations via MCP servers. It has deployed request-level safeguards on its most capable models and routes higher-risk dual-use cyber activity through its Cyber Verification Program.

Bottom line​

  • The headline is real and well sourced: a campaign with 30 techniques across 13 tactics, comparable to many medium-risk actors, earned Anthropic's maximum score of 100.
  • The explanation is orchestration. An agent chained the stages and made tactical decisions with limited human input.
  • The data is one vendor's, from banned accounts, scored with that vendor's own methodology. Use it to challenge assumptions, not as a universal measurement.
  • For defenders, the actionable step is to test whether your telemetry can show sequence, timing and identity across systems. Raw counts of individual techniques won't do that.
 

References

  1. The most dangerous attacker of the past year looked completely ordinary TechRadar 2026-10-08T09:53:35+00:00
  2. Mapping AI-enabled cyber threats \ Anthropic anthropic.com
  3. Disrupting an AI-orchestrated cyber espionage campaign \ Anthropic anthropic.com