Timeline

Anthropic's Project Glasswing analyses banned cyberattack accounts

Malware writing was the most common AI-assisted technique, but the sharpest rise was in more advanced stages such as lateral movement, which the MITRE framework does not track well.

  • Security & misuse
  • Minor

Anthropic published an analysis, under the name Project Glasswing, of 832 Claude accounts it had banned for malicious cyber activity between March 2025 and March 2026, mapping the techniques those accounts used against the MITRE ATT&CK framework, the industry-standard catalogue of attacker tactics.

Writing malware was the single most common use, appearing in an estimated two-thirds of the banned accounts. But the report’s central finding was about trajectory rather than volume: use of AI in more advanced attack stages, such as lateral movement within a compromised network, grew faster over the period than use in initial access. Anthropic argued this shift undermines standard ways of triaging threat severity — technique count or platform used — because AI assistance lets less-skilled operators carry out attacks that previously required specialist expertise. It also noted a structural gap: the ATT&CK framework has no entries for AI-specific behaviour such as autonomous orchestration of an attack chain or real-time adaptive decision-making, which the report identified as the capabilities distinguishing the highest-risk actors.

The report is one of a series of periodic threat disclosures from Anthropic’s trust-and-safety team documenting misuse of Claude, following earlier reports on state-linked espionage and disinformation campaigns. It reflects a broader pattern among frontier labs of publishing their own abuse data as both a transparency measure and evidence for the argument that AI-enabled cyber-offence capability is advancing unevenly across the kill chain, favouring stages defenders monitor least closely.