工具与项目 3.0 · 值得看 2026-06-03 · 文章

What we learned mapping a year's worth of AI-enabled cyber threats

As AI transforms the nature of and methods behind cyberattacks, how well do the techniques and frameworks used by the security community hol...

打开原文回到归档

What we learned mapping a year's worth of AI-enabled cyber threats

English

As AI transforms the nature of and methods behind cyberattacks, how well do the techniques and frameworks used by the security community hold up?

In a new report, we seek to answer that question. We examine 832 accounts that were banned for malicious cyber activity between March 2025 and March 2026 and map them onto MITRE ATT&CK, a longstanding database of the tactics and techniques used by cyberattackers. We published some of these results in Verizon's 2026 Data Breach Investigations Report (DBIR), and are sharing a more detailed analysis here. These 832 cases are just a subset of the total number of accounts banned during this period, but they represent those where we had enough detail to conduct a thorough assessment of the attackers' techniques.

There were three main conclusions from our analysis:

1. Malicious actors are using AI in ways that make them more dangerous. More specifically, threat actors are using AI in the later, more complex stages of their cyber operations. 2. Cyberattacks are becoming more autonomous, and the fact that AI can be used to chain together many parts of the attack means that the old ways of differentiating high- from low-risk actors are no longer as effective. 3. The MITRE ATT&CK framework does not fully capture the tools and activities that make AI-enabled attackers so dangerous.

How AI makes attackers more dangerous

The most common AI-enabled activities in our database related to preparing for a cyberattack, such as writing malware (560 of the 832 accounts we studied, or 67.3%, used AI for this purpose). A smaller number of actors use AI for more complex activities — for example, 54 of the 832 actors (6.5%) used AI to assist with "lateral movement," which involves navigating deep inside a compromised network.

We found evidence consistent with AI being used to help increase the threat level of attackers. In the first six-month period of our analysis, 33% of actors were classified by our risk-scoring system as medium risk or higher. But by the second six-month period, that share had jumped to 56% — a roughly 1.7-fold increase.

Across the period we studied, attackers' use of AI shifted from techniques to gain initial access to a system towards activity carried out once they were inside the system. For example, the use of AI for account discovery — identifying valid accounts inside a compromised environment — rose 8.9%, while AI-assisted phishing — a common technique to gain access to a system — fell 8.6%. This suggests that attackers are increasingly applying AI deeper in the attack life cycle.

These sorts of "post-compromise" techniques used to be restricted to actors with the technical knowledge to carry them out. Our investigation shows that AI can now be made to perform these activities on behalf of less sophisticated actors.

Why it's harder to assess an actor's threat level

How do security teams assess the risk level of a cyberattacker? Traditionally, they've used information like how many different techniques they employ and what tools or interfaces they use. But our analysis suggests that these signals no longer paint an accurate picture of the risk level of a given threat actor.

Now that AI can perform highly technical tasks on an actor's behalf, there's little correlation between the skill of a threat actor and how many techniques they use: the least-skilled actors in our dataset used about 16 distinct techniques on average, whereas the most skilled used about 20. Likewise, the specific platform used — Claude Code, an API, or a chat interface — also did not correlate with an actor's risk level.

What often helps distinguish higher-risk actors is where in the attack life cycle they apply AI. For example, they concentrate their use of AI on more operationally demanding techniques — those that require significant time, oversight, or real-time decision making to carry out — like account discovery, lateral movement, and privilege escalation, rather than just on tasks that allow them to gain initial access to the system.

But even that signal is already eroding: as discussed in the previous section, those operational techniques are exactly where the broader population is heading as more actors get classified as higher risk. The more durable differentiator is the type of scaffolding attackers build around the model: higher-risk actors design architectures that allow models to chain together discrete stages of a cyberattack and carry them out with minimal human input.

Why security frameworks need to change

Many of the behaviors that distinguish the highest-risk actors — such as the use of AI to orchestrate steps in the attack chain sequentially, make real-time decisions about what to do next, and execute without human intervention — are not yet included as attacker techniques in the MITRE ATT&CK framework.

Consider the state-sponsored cyber espionage operation we disrupted in November 2025. In that case, a malicious actor manipulated Claude Code into attempting to infiltrate targets around the world, with little human intervention. Mapping it against the MITRE ATT&CK framework shows that the actor used 30 techniques across 13 tactics, which was comparable to many medium-risk actors in our dataset. Clearly, focusing on the number of techniques this actor used underplays how dangerous they really were (by contrast, applying our risk-scoring methodology to this attack earns it the maximum risk score of 100).

In that attack, the model worked as an autonomous agent: it executed commands, exploited vulnerabilities, stole credentials, and made tactical decisions, only requiring human input at a few key moments. There is no ATT&CK ID for this type of agentic orchestration — yet these are precisely the behaviors we expect to see much more of as AI agents become more capable.

Looking ahead

The findings from this analysis helped inform the safeguards we build into our models. For example, we've developed and deployed cyber safeguards on our most capable models to detect and block some of the activities uncovered here, like developing malware or mass data exfiltration. Following on from our work with Verizon, we're also in discussions with MITRE about how the ATT&CK framework might evolve to include the AI-enabled behaviors we observed.

Frontier models are rapidly changing the tools both attackers and defenders have at their disposal. We are committed to helping defenders get ahead of these evolving tactics, and to putting the most powerful tools in the hands of defenders first. We'll continue to share what we learn from Project Glasswing, from datasets like the one we gathered here, and from our other cybersecurity activities.

中文

随着 AI 改变网络攻击的本质与手段,安全社区所使用的技术与框架是否还能站得住脚?

在最新发布的报告中,我们试图回答这个问题。我们审视了 2025 年 3 月至 2026 年 3 月间因恶意网络活动而被封禁的 832 个账号,并将它们映射到 MITRE ATT&CK(一个被长期使用、记录攻击者战术与技术的数据库)。我们已将这些结果的一部分发表在 Verizon 的《2026 年数据泄露调查报告》(DBIR)中,本文将提供更详细的分析。这 832 起案例只是该时间段内被封禁账号的一个子集,但代表了那些我们有足够细节来对攻击者技术进行全面评估的案例。

我们的分析得出三个主要结论:

1. 恶意行为者正以更具威胁性的方式使用 AI。具体来说,威胁行为者在网络行动中更靠后、更复杂的阶段使用 AI。 2. 网络攻击正变得更加自主,而 AI 还能把攻击的多个环节串联起来,这意味着过去用来区分高风险与低风险行为者的方法已经不再那么有效。 3. MITRE ATT&CK 框架并未完全捕捉到让 AI 赋能的威胁行为者如此危险的那些工具与活动。

AI 如何让攻击者变得更危险

我们数据库中最常见的 AI 赋能活动与"为网络攻击做准备"相关,例如编写恶意软件(在我们研究的 832 个账号中,560 个、即 67.3% 把 AI 用在了这个目的)。少量行为者将 AI 用于更复杂的活动——例如,832 个行为者中有 54 个(6.5%)借助 AI 进行"横向移动",即在被攻陷网络内部进行更深的渗透。

我们发现了与"AI 被用于抬升威胁等级"相一致的证据。在我们分析的前六个月里,33% 的行为者被风险评分系统归为中等风险或更高;而到了后六个月,这一比例跃升至 56%——大约 1.7 倍的增长。

在我们研究的时间段内,攻击者对 AI 的使用从"获取对系统的初始访问"的技术,逐渐转向进入系统之后的活动。例如,AI 用于"账号发现"(在被攻陷环境中识别有效账号)的比例上升了 8.9%,而 AI 辅助钓鱼(一种常见的获取系统访问权限的技术)下降了 8.6%。这表明攻击者越来越多地把 AI 用在攻击生命周期的更深处。

这些"入侵后"的技术,过去只有具备相关技术知识的行为者才能实施。我们的调查表明,AI 现在可以代为完成这些活动,从而让技术能力较弱的攻击者也能用上它们。

为何评估行为者威胁等级变得更难

安全团队如何评估一个网络攻击者的风险等级?传统上,他们会参考该攻击者使用多少种不同的技术、采用哪些工具或接口等信息。但我们的分析表明,这些信号已经无法准确反映特定威胁行为者的风险等级。

既然 AI 已经可以替行为者执行高难度任务,技术能力的高低与其使用的技术数量之间几乎不再有相关性:数据集中能力最差的行为者平均使用约 16 种不同技术,而能力最强的则平均使用约 20 种。同样,具体使用的平台——Claude Code、API 或聊天界面——也和行为者的风险等级无关。

真正能区分高风险行为者的,是他们把 AI 部署在攻击生命周期的哪个阶段。例如,他们把 AI 集中用在操作性更强的技术上——那些需要大量时间、监督或实时决策的技术,例如账号发现、横向移动与权限提升——而不仅仅用在"获得对系统的初始访问"这种任务上。

但即便这个信号也已经在弱化:正如上一节所讨论的,这些操作性更强的技术,恰恰也是整个攻击者群体正在朝之演进的方向,越来越多的行为者被划入更高风险等级。更具持续性的差异化因素是攻击者围绕模型所搭建的"脚手架":高风险行为者会设计架构,让模型把网络攻击的离散阶段串起来,并在极少人工介入的情况下执行。

为何安全框架需要更新

许多最能体现最高风险行为者特征的行为——例如用 AI 串联攻击链的各个步骤、对"下一步做什么"做出实时决策、以及在无人工介入的情况下执行——都尚未被纳入 MITRE ATT&CK 框架中作为攻击者技术。

以我们 2025 年 11 月挫败的某国家级网络间谍行动为例。案中,一名恶意行为者操纵 Claude Code 试图渗透全球多个目标,期间几乎没有人工介入。把它映射到 MITRE ATT&CK 框架后可以看到,该行为者使用了 13 个战术类别下的 30 项技术,与我们数据集中许多中等风险行为者相当。显然,单纯看该行为者使用的技术数量会低估其真实危险性(相比之下,用我们的风险评分方法对这次攻击评分,会得到满分 100)。

在那次攻击中,模型扮演了一个自主智能体的角色:它执行命令、利用漏洞、窃取凭据并做出战术决策,只在少数关键节点需要人工介入。对于这种"智能体编排"类型,ATT&CK 中还没有对应的编号——但随着 AI 智能体的能力变强,这类行为正是我们预期会大量出现的。

展望未来

这些分析结论也指导了我们为模型构建的安全防护。例如,我们已经开发并部署了针对我们最强模型的"网络安全防护",以检测并拦截一些本报告揭示的活动,例如开发恶意软件或大规模数据外泄。在与 Verizon 合作的基础上,我们也正在与 MITRE 讨论 ATT&CK 框架如何演进以纳入我们观察到的 AI 赋能行为。

前沿模型正迅速改变攻击者与防御者双方手上的工具。我们致力于帮助防御者跑赢这些不断演化的战术,并让最强大的工具率先落到防御者手中。我们将继续分享从 Project Glasswing、本文所用的这类数据集、以及我们其他网络安全工作中所学到的东西。