IC Technology & Surveillance — 2026-05-04

MITRE ATT&CK v19 Adds AI-Orchestrated Espionage Campaign and First LLM-Querying Malware Entries

MITRE released ATT&CK v19 on April 28, documenting two AI-enabled threat entries: the Anthropic AI-orchestrated Campaign, attributed to a PRC-directed cluster that used Claude Code to autonomously execute portions of a multi-stage espionage operation, and LAMEHUG, described by MITRE as the first known malware to query a large language model during live operations and associated with APT28. Industrial Cyber, reporting on the release, notes the framework also added new ICS sub-techniques across firmware, communications, and discovery, restructured Defense Evasion, and introduced detection strategies for the Mobile domain. New threat intelligence coverage includes Void Manticore tied to the 2026 Stryker attack, cross-domain wiper campaigns against Polish energy infrastructure, and 2025 npm supply chain compromises captured under GlassWorm and Shai-Hulud.

Analysis
ATT&CK v19 formalizes two distinct offensive LLM employment models: a PRC-directed cluster delegating operational decisions to Claude Code and APT28's LAMEHUG adapting behavior from live LLM queries, each implying different detection surfaces now codified in the framework. Per single-source Industrial Cyber coverage without independent technical validation, the entries move AI-enabled offense from theoretical to catalogued, a categorization that reshapes defender prioritization regardless of deployment frequency. The concurrent ICS sub-technique additions and Void Manticore's Stryker linkage suggest a release cycle shaped by Iran-conflict operational tempo. Autonomous LLM use may remain a poorly scalable edge case relative to traditional automation, but the detection architecture now exists.
1 sources
  1. MITRE ATT&CK v19 brings structural overhaul, industrial visibility, detection strategies as AI-driven attacks emerge - Industrial Cyber

View in full brief →

UNCLASSIFIED // OPEN SOURCE