Although ImageNet was initially proposed as a dataset for performance\nbenchmarking in the domain of computer vision, it also enabled a variety of\nother research efforts. Adversarial machine learning is one such research\neffort, employing deceptive inputs to fool models in making wrong predictions.\nTo evaluate attacks and defenses in the field of adversarial machine learning,\nImageNet remains one of the most frequently used datasets. However, a topic\nthat is yet to be investigated is the nature of the classes into which\nadversarial examples are misclassified. In this paper, we perform a detailed\nanalysis of these misclassification classes, leveraging the ImageNet class\nhierarchy and measuring the relative positions of the aforementioned type of\nclasses in the unperturbed origins of the adversarial examples. We find that\n$71\\%$ of the adversarial examples that achieve model-to-model adversarial\ntransferability are misclassified into one of the top-5 classes predicted for\nthe underlying source images. We also find that a large subset of untargeted\nmisclassifications are, in fact, misclassifications into semantically similar\nclasses. Based on these findings, we discuss the need to take into account the\nImageNet class hierarchy when evaluating untargeted adversarial successes.\nFurthermore, we advocate for future research efforts to incorporate categorical\ninformation.\n