Blog
How AI agents could make threat attribution harder
As autonomous AI agents begin to execute more of the cyber attack lifecycle, traditional threat attribution may become harder. This article explores how AI-driven behaviour could obscure attacker identity, weaken familiar TTP signals and force defenders to rethink what attribution means.
Skip to:
- The fading human operator in AI-driven cyber attacks
- When AI-generated TTPs obscure attacker identity
- Beyond TTPs: the changing signals of cyber attribution
- How AI could poison attribution at scale
- The human fingerprint in AI-enabled intrusions
- Why attribution may depend on privileged visibility
- Why defenders may need faster intelligence more than attribution
Threat actor attribution has always been one of the most valuable and contested disciplines in cyber threat intelligence. When an intrusion is discovered, incident responders and intelligence teams quickly ask who was behind it. The answer can shape how the incident is interpreted, which follow-on actions defenders expect, and how organisations understand the broader campaign. At the strategic level, attribution can influence national security assessments, diplomatic responses and the way governments and businesses interpret the threat landscape.
But attribution has never been an exact science. Analysts rarely identify an attacker from a single piece of evidence. Instead, they work from overlapping signals: infrastructure, malware, targeting choices, working hours, language artefacts, command syntax, historical behaviour and tactics, techniques and procedures. Over time, these signals can create an operational fingerprint. The growing use of autonomous AI agents in cyber operations challenges that assumption because the behaviour defenders observe may increasingly belong to software, not directly to the human operator behind the attack.
The fading human operator in AI-driven cyber attacks
Advanced intrusions could soon involve far less direct human control. An autonomous reconnaissance agent might identify exposed infrastructure, while another component adapts exploit code, maps the environment, searches for credentials and determines how to move toward the objective. The human operator may provide only the intent: compromise a target, obtain specific information, avoid unnecessary disruption and return the results.
That possibility is no longer purely theoretical. In 2025, Anthropic reported an AI-orchestrated espionage campaign attributed with high confidence to a likely China-nexus actor tracked as GTG-1002. MITRE records the campaign as involving Claude Code agents and Model Context Protocol tools to automate reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis and exfiltration against roughly 30 entities across technology, finance, chemicals and government. Anthropic said the operation showed AI being used not simply as an adviser, but as a system executing much of the attack lifecycle with minimal human involvement.
When AI-generated TTPs obscure attacker identity
Tactics, techniques and procedures remain central to modern threat intelligence because they describe how adversaries behave inside an environment. However, their attribution value may change when the executor is autonomous. Tactics such as credential access, discovery, collection and exfiltration still matter. Techniques remain essential for detection and defence. The more fragile layer is the procedure: the specific way a technique is implemented.
Human operators develop habits. They reuse scripts, prefer certain tools and solve similar problems in recognisable ways. Autonomous systems behave differently. They may select whatever action appears most effective in a specific environment. Two unrelated attackers using the same capable offensive agent against similar Microsoft environments could therefore generate very similar telemetry, not because they share training or doctrine, but because the software reached the same conclusion. The reverse is also possible: the same threat actor could appear different from one victim to another if the agent dynamically selects different paths.
Conscia ThreatInsights
The only threat intelligence newsletter that focuses primarily on Europe According to Forrester, European organisations face several different cybersecurity threats compared to their global counterpar…
Beyond TTPs: the changing signals of cyber attribution
This does not make frameworks such as MITRE ATT&CK obsolete. They remain highly useful for describing what happened and organising defensive knowledge. The question is whether procedures will continue to carry the same attribution value when they are generated at runtime. If autonomous systems increasingly decide which techniques to use, analysts may need to study not only what the attacker did, but how the system decided what to do.
One way to describe this missing layer is Agentic Operational Patterns: recurring characteristics in how an autonomous attack system plans, delegates, selects, adapts and escalates actions. TTPs describe the activity itself. Agentic Operational Patterns describe the decision process behind it. That could include how many failed attempts an agent tolerates before changing strategy, whether it prioritises identity infrastructure before endpoints, when it introduces custom payloads, or whether it requires human approval before disruptive actions.
How AI could poison attribution at scale
Moving up the abstraction stack does not remove the risk of deception. False flags already exist in cyber operations, but agentic AI could make them easier to generate consistently and at scale. Instead of manually imitating another actor, an operator could instruct an autonomous system to favour techniques, naming conventions, timing patterns or infrastructure choices associated with a different group. The agent could also vary its behaviour between victims to prevent analysts from establishing stable patterns.
This creates the possibility of attribution poisoning: deliberately generating or manipulating behavioural evidence to distort attribution assessments. As defensive teams also adopt AI for clustering and classification, attribution could become partly an adversarial AI problem, with one system constructing an identity while another attempts to infer it.
The human fingerprint in AI-enabled intrusions
None of this makes attribution impossible. Even highly autonomous attacks still originate from human or organisational intent. Someone defines the objective, selects the target, decides which information is valuable and determines the acceptable level of operational risk. Someone also selects, builds or configures the models, tools and infrastructure surrounding the operation.
As execution-level behaviour becomes more dynamic, attribution may rely more heavily on victimology, geopolitical context, campaign timing, recurring intelligence requirements and the types of information repeatedly targeted. The strongest signals may no longer be individual commands or procedures, but the operational logic, risk tolerance and priorities expressed through the system.
Why attribution may depend on privileged visibility
A further complication is visibility. A victim organisation may see authentication events, processes, network traffic and files, allowing it to reconstruct what happened inside its own environment. But an AI provider may see how accounts interacted with models, which tools were invoked and whether apparently separate activity belongs to the same cluster. Cloud providers, infrastructure companies, major security vendors and government agencies may each hold different parts of the attribution puzzle.
High-confidence attribution may therefore depend less on deep visibility into a single compromised organisation and more on broad visibility across ecosystems. Individual organisations may still be able to establish that incidents belong to the same activity cluster, understand the likely objective and anticipate next steps. But naming the operator, sponsor or country behind the activity may increasingly require telemetry and scale that only a limited set of organisations possess.
Why defenders may need faster intelligence more than attribution
Precise attribution will continue to matter for strategy, policy and long-term intelligence. But during a fast-moving autonomous attack, defenders cannot wait for a sophisticated attribution assessment before acting. The immediate questions are more practical: what can this attacker do, which access path is being exploited, what identities are at risk, which controls worked and where should teams hunt next?
In that sense, the rise of agentic AI separates strategic attribution from operational defence. Cyber threat intelligence does not become less relevant. Its centre of gravity shifts toward understanding new capabilities, assessing how quickly they can be replicated and translating observations into timely defensive action. In an era of extreme attack acceleration, the intelligence advantage may come less from naming the attacker and more from understanding what has changed before that change reaches the organisation – a theme explored in more depth in the full article.
Guide: Secure AI 2026 – effective & future-proof AI
Cut through the hype and standalone technical fixes. Deepen your understanding of AI by recognising that it is not merely a matter of innovation or security, but of governance, responsibility, and lon…
About the author
David Kasabji
Head of Threat Intelligence
David Kasabji is the Head of Threat Intelligence at the Conscia Group. He leads the development and delivery of actionable intelligence across cyber defense and managed security operations, translating complex threat activity into clear outcomes for different audiences — from SOC analysts and incident responders to executive stakeholders and external communications. His work spans end-to-end intelligence operations: collection and analysis of adversary activity, threat actor and campaign profiling, IOC and TTP development, and intelligence-driven guidance for detection, threat hunting, and security prioritization. David is also actively involved in Digital Forensics and Incident Response, supporting investigations and crisis situations with rapid triage, context, and strategic recommendations. A strong focus of his role is continuously improving how intelligence is operationalized through standardization and automation to ensure it is timely, relevant, and measurable.nd strategic crisis management during incidents.
Related