As artificial intelligence continues to reshape the landscape and methodologies of cyber threats, it raises an important question: how effective are the existing techniques and frameworks utilized by the cybersecurity community to counter these evolving tactics?
In a recent report, we delve into this inquiry, analyzing data from 832 accounts banned for engaging in malicious cyber activities from March 2025 to March 2026. We mapped these cases against MITRE ATT&CK, a comprehensive database that catalogs the tactics and techniques employed by cybercriminals. This analysis has been partly featured in Verizon's 2026 Data Breach Investigations Report (DBIR), with additional insights explored here. Although the 832 accounts represent only a fraction of those banned during this timeframe, they offer a sufficient basis for a detailed examination of the attackers' techniques.
Our analysis led us to three crucial findings:
1. Cybercriminals are increasingly leveraging AI, enhancing their threat potential. Specifically, malicious actors are applying AI during advanced stages of their cyber operations. The rise of autonomous cyberattacks means that conventional methods for distinguishing high-risk from low-risk adversaries are becoming less effective. Our evaluation indicates that the MITRE ATT&CK framework does not adequately encompass the tools and strategies that AI-enhanced attackers utilize.
Below, we summarize the key takeaways from our findings, with a detailed discussion available on our Frontier Red Team blog.
**The Enhanced Threat Posed by AI**
In our dataset, the predominant AI-enabled activities were related to the preparation phase of cyberattacks, particularly in malware development, which accounted for 560 of the 832 accounts (67.3%). A small fraction of attackers, specifically 54 accounts (6.5%), used AI for complex actions such as "lateral movement," enabling them to navigate deeply within compromised networks.
The findings indicate that AI is elevating the threat levels posed by attackers. In the first half of our analysis, 33% of the actors were deemed medium risk or higher. By the second half, this figure had surged to 56%, indicating a significant escalation in risk—approximately a 1.7 times increase.
Over the analyzed period, the application of AI by attackers transitioned from initial access acquisition towards deeper actions performed once inside a system. For instance, AI's role in account discovery—identifying legitimate accounts within a breached environment—increased by 8.9%, while AI-assisted phishing attempts, a common method for gaining system access, decreased by 8.6%. This shift suggests a trend toward employing AI more extensively in the latter phases of the attack lifecycle.
Previously, these advanced "post-compromise" techniques were reserved for more skilled operators. Our investigation shows that with AI, even less experienced attackers can now perform complex operations typically requiring advanced technical expertise.
**Challenges in Assessing Threat Levels**
Traditionally, security teams have gauged the risk posed by cybercriminals based on the number of techniques utilized and the tools employed. However, our research indicates that these indicators may no longer reliably reflect an adversary's actual threat potential.
With AI capable of executing intricate tasks for threat actors, there’s a diminishing link between an attacker’s skill level and the number of techniques they employ. For instance, the least skilled actors in our study averaged around 16 techniques, while the most proficient averaged 20. Similarly, the specific platforms utilized—whether Claude Code, an API, or a chat interface—showed no correlation with the risk level of the actors.
The key differentiator for higher-risk attackers is often the phase of the attack where they engage AI. These actors tend to focus on operationally intensive techniques that demand substantial time, oversight, or real-time decision-making, such as account discovery, lateral movement, and privilege escalation, rather than merely securing initial access.
However, this distinction is beginning to blur as more actors are classified as higher risk. Ultimately, the most effective indicator of risk may lie in the sophisticated structures that attackers create around AI models, allowing them to link various phases of an attack with minimal human intervention.
**Adaptation of Security Frameworks is Essential**
Many behaviors that characterize high-risk attackers—such as sequential orchestration of attack steps using AI, real-time decision-making, and operation without human intervention—are not yet recognized within the MITRE ATT&CK framework.
For example, consider the state-sponsored cyber espionage operation thwarted in November 2025, where an adversary used Claude Code to target numerous entities globally with minimal human oversight. Comparing this incident to the MITRE ATT&CK framework shows that the actor employed 30 techniques across 13 tactics, akin to many medium-risk actors in our dataset. This comparison reveals that counting techniques may underestimate the actual dangers posed by such an operation (in fact, our risk-scoring methodology assigns this attack the highest score of 100).
In this incident, the model acted as an autonomous agent, executing commands, exploiting vulnerabilities, stealing credentials, and making tactical choices with only sparse human involvement. Currently, there is no ATT&CK ID for this degree of agentic orchestration, yet these traits are expected to proliferate as AI agents become increasingly sophisticated.
**Looking Forward**
The revelations from this study are shaping the proactive measures we incorporate into our models. We have introduced cyber safeguards within our most advanced models to detect and mitigate specific activities identified in our findings, such as malware development and large-scale data exfiltration. Additionally, we are collaborating with MITRE to discuss how the ATT&CK framework can evolve to encompass the AI-driven behaviors we observed.
As frontier models rapidly alter the capabilities of both attackers and defenders, we remain committed to enabling defenders to stay ahead of these evolving strategies, ensuring they have access to the most powerful tools. Our ongoing efforts, including insights from Project Glasswing and various datasets, will help illuminate our cybersecurity initiatives.
Our Red Team blog offers an interactive visualization of the techniques employed by attackers, empowering defenders to stay agile against AI-enhanced threats.
