What happened
AI is being placed inside the attack loop
Anthropic's September 2026 threat intelligence report describes malicious use it identified and disrupted between December 2025 and August 2026. The company says a majority of the cyber operations in its selected case studies involved direct AI execution or orchestration rather than simple question-and-answer assistance.
Humans still chose targets and reviewed sensitive results. Between those decisions, however, agentic workflows reportedly performed reconnaissance, prepared infrastructure, supported exploitation, harvested credentials, moved through environments, processed stolen data, and maintained access.
Important scope limitation
Observed change
Automation compresses the work between attacker decisions
| Operational stage | Provider-reported use | Defender implication |
|---|---|---|
| Reconnaissance | Fingerprinting exposed services and building target lists | Reduce unnecessary exposure and monitor systematic enumeration across identity, cloud, and edge systems. |
| Initial access | Phishing infrastructure, credential use, and exploitation workflows | Correlate identity events with endpoint and network activity instead of reviewing alerts in isolation. |
| Execution and persistence | Tool generation, deployment, and repeated adaptation | Favor behavior-based controls that survive changes to filenames, hashes, and code structure. |
| Collection and exfiltration | Bulk extraction, organization, and analysis of stolen data | Detect unusual export volume, token use, cross-tenant access, and new exfiltration destinations. |
One suspected Russian state-linked operation allegedly used AI-assisted workflows to monitor whether malware was detected, then modify and rebuild the tooling. Anthropic assessed the actor's tradecraft and targeting as consistent with public reporting on Midnight Blizzard; that wording is an assessment, not independent proof of attribution.
Why it matters
Static indicators may lose value faster
Hashes, domains, and filenames remain useful for scoping known activity, but an automated attacker can regenerate some artifacts faster than a manual operation. The durable signals are increasingly the relationships between actions: an unusual sign-in followed by device registration, token creation, mailbox export, privilege escalation, or high-volume collection.
Microsoft's separate reporting on the CaptiveCrunch campaign supports part of this operational picture. It documented AI-augmented activity alongside compromised hospitality networks, captive-portal traffic manipulation, fake update prompts, device-code phishing, credential theft, and malware delivery.
Threat Field Notes assessment
Defender actions
Build controls around the operational chain
- 1
Protect secrets used by automation. Inventory AI, cloud, source-control, and CI/CD tokens. Remove secrets from code and images, restrict scope, rotate exposed credentials, and alert on use from new infrastructure.
- 2
Constrain device-code authentication. Block the device-code flow where it is unnecessary. Where business use requires it, apply Conditional Access, phishing-resistant MFA, device restrictions, and monitoring for anomalous registrations.
- 3
Correlate behavior across systems. Join sign-in, OAuth, endpoint, email, source-control, and cloud audit events so a multi-stage sequence becomes one investigation rather than several low-confidence alerts.
- 4
Hunt for automated collection. Baseline mailbox exports, repository cloning, API enumeration, database reads, token minting, and cross-tenant activity. Investigate sharp changes in volume, cadence, and access breadth.
- 5
Test detections against variation. Validate that important detections still work when a tool changes its hash, name, command formatting, parent process, or hosting location while preserving the same objective.
- 6
Prepare rapid credential containment. Document how to revoke sessions, disable applications, rotate developer tokens, isolate endpoints, and preserve identity evidence without waiting for full attribution.
Hunting priorities
Look for the seams automation still exposes
- New device registrations or OAuth grants shortly after an unusual sign-in or device-code event.
- High-volume mailbox, repository, object-storage, or SaaS exports from identities that do not normally perform bulk collection.
- A developer or AI API key used from unfamiliar networks, cloud regions, user agents, or workloads.
- Repeated tool rebuilds or payload changes followed by the same persistence, credential-access, or exfiltration behavior.
- Fake update, verification, or captive-portal activity that launches command interpreters or downloads executable content.
- Security-control tampering followed by token theft, session replay, or outbound transfers.
Editorial note
How this analysis was prepared
This topic was surfaced by The Cyber Security Hub newsletter on LinkedIn. Threat Field Notes independently reviewed the cited Anthropic report and related Microsoft research, then wrote this defender-focused analysis in original language.
The underlying cases are based substantially on provider telemetry and provider attribution. Defenders should treat the report as a source of hypotheses, behaviors, and indicators to validate—not as proof that every sophisticated intrusion now uses autonomous AI.