CrowdStrike’s threat hunters see AI as weapon, target, and a shrinking patch window

Security teams used to triage alerts mostly raised by people doing unusual things on a network. That baseline has inverted. In CrowdStrike’s latest annual threat hunting report, published August 3, AI-driven activity now generates roughly 2.5 times as many investigation leads for the firm’s hunters as human-triggered activity does, a shift the company says makes it harder for defenders to tell malicious behavior apart from ordinary automated work.

The report draws on a year of telemetry from CrowdStrike’s OverWatch managed hunting team, which the firm says triages roughly 14 million detection leads each day and tracks more than 290 named adversary groups. The central finding is that AI now runs through adversary operations in three roles at once: as a tool for building attacks, as a target for compromise, and as a force multiplier that lets small teams act at machine speed.

The tool role is the most familiar. Criminals and state-sponsored groups are using large language models to generate phishing material, payloads, and shell commands, and to write credential-harvesting scripts. CrowdStrike says the output is becoming more tailored, with attackers generating custom tools built for specific defensive setups. One documented campaign hammered a victim’s enterprise language model with roughly 200,000 requests in a two-minute burst, an example of LLMJacking in which stolen credentials let attackers run up enormous bills on someone else’s compute.

The target role is newer and, in the report’s telling, more structural. AI infrastructure is becoming a new front in supply chain attacks: frameworks, agent integrations, and the dependency tools AI agents rely on carry broad system access, are installed in both development and production environments, and are updated often, each update a fresh chance to smuggle in malicious code. CrowdStrike cites a DPRK-linked group it calls Stardust Chollima, which injected a malicious npm package into 131 trusted Mastra AI frameworks during the first half of the year, and an eCrime cluster it calls Altered Spider, which took out over 300 software dependencies within a single day by targeting developers’ AI tooling, then pivoted into cloud environments to steal credentials and extort victims.

If our reporting has earned your trust, consider helping us continue our work.

Keep quality journalism alive

The third role is acceleration. CrowdStrike found that 88 percent of exploits it detected between January and June used public proof-of-concept code within 48 hours of disclosure, and some China-linked groups moved faster still, developing working exploits for a critical web application flaw within a day. The traditional 30-day patch cycle, the report argues, is obsolete; the working baseline is now 24 to 48 hours. The firm also notes that two of three recently disclosed local privilege escalation exploits were discovered with AI-assisted research, a sign that the same tools are inflating the volume of vulnerabilities defenders must race to close.

Some of the most sophisticated AI use documented in the report comes from North Korean groups. CrowdStrike credits a DPRK-associated cluster it calls Famous Chollima with the most advanced AI adoption it tracked: the group built fully fictional companies, complete with AI-produced websites, developer accounts, and mail systems, to place insiders at target firms, and it trojanized code repositories used by cryptocurrency and blockchain businesses. The March compromise of the widely downloaded Axios JavaScript package, attributed by Amazon to a group CrowdStrike links to the Lazarus offshoot it calls Stardust Chollima, fits the same pattern of poisoning the developer tools AI systems depend on.

CrowdStrike’s recommendations follow from the findings: treat AI credentials and model endpoints as critical infrastructure, enforce least-privilege access for agents, watch for anomalous usage and cost spikes, and compress vulnerability management to operate on an hours-long timeline rather than a monthly one. The report’s broader warning is that defenders are now competing against AI adoption curves that move faster than most security programs.

Sources: CrowdStrike 2026 Threat Hunting Report: AI is Now Embedded Across Modern Adversary Operations (CrowdStrike press release, Aug 3, 2026); AI is both a cyber weapon and a massive target, CrowdStrike warns (ZDNet, Aug 3, 2026); CrowdStrike: AI is now both the weapon and the target in cyberattacks (CyberScoop, Aug 3, 2026); AI is ‘both the weapon and the target’ in latest wave of cyberattacks (The Register, Aug 3, 2026)

Scroll to Top