Anthropic’s Claude Mythos has become the first AI model to autonomously complete the full cyber kill chain, according to Booz Allen’s new Cyber Weapon Index. This capability was demonstrated in rigorous testing, highlighting the growing reality of AI-driven cyber threats and signalling a new era in cybersecurity risk.
Claude Mythos Leads in Autonomous Cyber Attacks
The Cyber Weapon Index, released by Booz Allen, evaluated 18 advanced language models from both US and Chinese developers. The focus was on how well each AI could independently identify vulnerabilities, create offensive tools, and execute a complete cyber intrusion without human intervention. Out of the models tested, only Anthropic’s Claude Mythos achieved a full, end-to-end cyber kill chain, marking a significant milestone in AI cybersecurity capabilities.
The cyber kill chain refers to the sequence of stages an attacker must complete to compromise a target, usually including reconnaissance, initial access, privilege escalation, lateral movement, and final impact. Claude Mythos managed to autonomously perform all these steps, both when provided with stolen credentials and even when starting without them.
- Vendor: Anthropic
- Model: Claude Mythos
- Tested by: Booz Allen in its first Cyber Weapon Index
- Date: September 2026
- Scope: 18 models (9 US, 9 Chinese), tested under identical conditions
How the Cyber Weapon Index Was Conducted
The index assessed each model with two major scores: a Vulnerability Research Score (VRS), measuring the AI’s ability to find both known and novel vulnerabilities, and a Kill Chain Attainment Score (KCAS), reflecting how far the model could progress through a simulated attack scenario. Each model was tested with and without valid credentials to evaluate its full range of offensive capabilities.
Claude Mythos achieved a CWI score of 80, significantly higher than all other models. When supplied with stolen employee credentials, the model was able to infiltrate target networks and escalate its privileges to administrator in every attempt. Even more concerning, Claude Mythos independently adapted its strategy based on real-time network findings, rather than following a scripted attack path. When denied credentials, it still ultimately compromised the domain, showcasing highly advanced autonomous decision-making and problem-solving abilities.
- Highest CWI Score: Claude Mythos (80)
- Close contenders: xAI’s Grok-4.5 (49), OpenAI’s GPT-5.6 Sol (46), Meta’s Muse Spark 1.1 (38), Moonshot AI’s Kimi K3 (38)
- Other models nearing full kill chain autonomy
Ranking of AI Models by CWI Score
- Claude Mythos (80)
- Grok-4.5 (49)
- GPT-5.6 Sol (46)
- Muse Spark 1.1 (38)
- Kimi K3 (38)
- GLM-5.2 (37)
- Claude Opus 4.8 (36)
- GPT-5.5-Cyber (34)
- Nemotron-Ultra (33)
While only Claude Mythos executed the full cyber kill chain independently, three other models (Grok-4.5, Muse Spark 1.1, and GLM-5.2) managed to reach full domain access and control, suggesting that similar capabilities will soon be widespread among leading AI platforms.
Implications and Imminent Threat of AI-Enabled Cyber Attacks
The Cyber Weapon Index report warns that the gap between Claude Mythos and other leading models is narrowing quickly. Booz Allen estimates that most of the remaining 17 tested models are likely to reach full kill chain autonomy within the next six months. This rapid progress raises the spectre of mainstream, AI-enabled attacks, not just by nation-state actors but also by financially motivated cybercriminals such as ransomware gangs.
One notable absence from the test group was OpenAI’s soon-to-be-released Astra. According to OpenAI, Astra has already reached a “critical” cybersecurity capability threshold, demonstrating proficiency in finding and exploiting zero-day vulnerabilities. This marks the arrival of AI models that could independently inflict harm on digital infrastructure, either through malicious users or potential misalignment of the AI itself.
- AI models can accelerate the speed and scale of cyber attacks.
- Critical infrastructure and enterprises face heightened risks from autonomous AI threats.
- Sector-specific resilience standards may be necessary to keep pace with the evolving threat landscape.
Why This Matters Now
The fact that Claude Mythos can execute the entire cyber kill chain without human intervention signals a major shift in the threat landscape. AI-enabled offensive operations are no longer theoretical. The ability for AI to autonomously discover vulnerabilities, exploit them, and escalate privileges means that traditional defences may be rendered obsolete much faster than previously anticipated.
Booz Allen’s report calls for urgent action, urging governments and critical infrastructure operators to demonstrate AI-specific resilience. The window to prepare for AI-powered attacks is narrowing as models rapidly improve.
What Organisations Should Do
Organisations should prioritise validating their existing security controls against AI-enabled attacks. This includes ensuring multi-factor authentication is enforced, credentials are well managed, segmentation is robust, and detection and response capabilities are sufficiently rapid to counter machine-speed threats. Businesses should monitor developments in AI offensive capabilities and review their cyber incident response plans accordingly.
Originally reported by theregister.com.





