Claude Mythos only model to complete full cyber kill chain, experts say
A Booz Allen study revealed that Anthropic’s Claude Mythos is the first AI model to autonomously complete the entire cyber kill chain, demonstrating a significant capability for independent attacks. The study, dubbed the Cyber Weapon Index, highlights a growing threat from advanced AI models, both developed in the US and China, and emphasizes the importance of ‘overmatch’ – developing both offensive and defensive AI capabilities. Crucially, the report found that the ‘attack harness’ – the software connecting the AI model to hacking tools – is as important as the model itself in enabling autonomous attacks, and that Chinese models are rapidly closing the gap in offensive cyber capabilities.
A Booz Allen study, the Cyber Weapon Index, has identified Anthropic’s Claude Mythos as the first AI model to independently complete the full cyber kill chain. The research, which tested 18 models – nine from American and nine from Chinese developers – found that Claude Mythos successfully broke into its target network and gained administrator-level control in every attempt, even without initial credentials. The model independently identified how to gain higher-level access based on what it found within the network, not by following a predetermined attack plan.
This capability is particularly concerning because the study suggests that other advanced AI models, including xAI’s Grok-4.5, OpenAI’s GPT-5.6 Sol, and Meta’s Muse Spark 1.1, are rapidly approaching Mythos’ level of autonomous attack capability within six months. The report emphasizes that the ‘attack harness’ – the software that connects the AI model to hacking tools and orchestration logic – is a critical factor in amplifying the model’s effectiveness.
Notably, the study found that even when intentionally introduced vulnerabilities, all models scored near the ceiling on the vulnerability research score (VRS) component. However, when tested against real bugs, only Claude Mythos exploited them. The report calls for the US to develop ‘overmatch’ – a combined offensive and defensive strategy – to counter this growing threat, acknowledging that Chinese models are also rapidly gaining offensive cyber skills and that the US may neither control nor fully understand the capabilities it could face.
“The result is not a ‘smarter’ model but rather a system that makes its intelligence far more actionable while also lowering the expertise required to use it,” the report states. This highlights a significant shift in the cybersecurity landscape, where AI-powered attacks are becoming increasingly sophisticated and autonomous, requiring a proactive and adaptive defense strategy.