Cybersecurity firm CrowdStrike reports an 89 percent increase in AI-enabled cyberattacks in 2025, noting that artificial intelligence is being utilized by adversaries as both a weapon and a target. The company's annual Threat Hunting Report indicates that both criminal organizations and state-sponsored groups are integrating AI across the entire attack chain. Attackers are also specifically targeting AI infrastructure and compromising popular software packages to affect users.
CrowdStrike's counter adversary division senior vice president, Adam Meyers, stated that AI represents a high-value attack surface increasingly exploited by threat actors. The firm's threat hunting team now identifies AI agent-triggered leads at 2.5 times the rate of human-triggered threats, a trend observed across government-backed and financially motivated groups.
Among the 290 adversary groups tracked by CrowdStrike, the North Korean group Famous Chollima, a sub-unit of the Lazarus Group, demonstrated the most advanced AI usage between the second half of 2025 and the first half of 2026. This group is known for creating entirely fake companies with AI-generated websites, GitHub accounts, and email infrastructure to support insider threat operations.
AI supply-chain compromise was identified as the second most common MITRE ATLAS technique for initial access. Famous Chollima's campaign targeting AI-focused development environments was cited as a sophisticated example of this technique. This included a supply-chain attack in January and February targeting cryptocurrency and blockchain companies, where trojanized repositories, primarily on GitHub, contained legitimate-looking project files alongside hidden malicious scripts. These scripts automatically executed commands, granting Famous Chollima access to developer environments.
Another Lazarus Group offshoot, tracked as Stardust Chollima or Sapphire Sleet, is suspected to be behind the March Axios supply chain attack. Amazon has also attributed four npm compromises over the past 18 months to the same North Korean crew.
Financially motivated groups are also leveraging AI. CrowdStrike tracks Altered Spider, also known as TeamPCP, which targeted developers' AI tools, compromising over 300 software dependencies in a single day. This group harvested credentials and secrets before moving into cloud environments for theft and extortion. Meyers noted that Altered Spider can compromise an endpoint in seconds and penetrate cloud environments within minutes, demonstrating rapid movement tied to software supply chains.
CrowdStrike also highlights that AI is accelerating the exploitation of newly disclosed vulnerabilities. From January to June, 88 percent of observed exploitation using public proof-of-concept (PoC) code occurred within 48 hours of the code's release. China-linked groups such as Vault Panda and Genesis Panda launched attacks even faster, within 24 hours of disclosure.
This rapid weaponization of vulnerabilities by AI is rendering the traditional 30-day patch window obsolete, shortening it to 24-hour or 48-hour cycles. Organizations are reportedly struggling to keep pace.
Concurrently, AI is proving highly effective at discovering new software bugs. In 2025, approximately 48,200 CVEs were registered. As of early August this year, 43,000 CVEs have already been recorded, nearing last year's total. June alone saw over 7,600 software bugs reported and tracked through CVEs, indicating a significant increase in the vulnerability ecosystem.






