AI Is Now Both the Weapon and the Bullseye: CrowdStrike's 2025 Threat Report Makes for Grim Reading
CrowdStrike's latest annual Threat Hunting Report drops a fairly uncomfortable truth on the security industry: AI-enabled attacks jumped 89 percent in 2025, and the technology is simultaneously being weaponised by attackers and hunted as a high-value target in its own right.
The firm's counter adversary division senior VP Adam Meyers put it plainly: "AI is both the weapon and the target." Not exactly a comforting sentence.
Among the nastier trends documented is LLMjacking, where criminals steal corporate credentials specifically to access frontier model APIs, either to use them freely or to run up victims' bills through deliberate over-consumption. CrowdStrike caught one campaign where a token thief fired roughly 200,000 API requests in under two minutes. Someone was in a hurry.
The firm's threat hunting team now flags AI agent-triggered alerts at 2.5 times the rate of human-triggered ones. That ratio holds across both nation-state groups and financially motivated criminal outfits, which tells you something about how thoroughly automated offensive operations have become.
CrowdStrike currently tracks over 290 adversary groups, adding around ten this year alone. The standout performers for AI misuse, covering the second half of 2025 and first half of 2026, are North Korea's Famous Chollima, a sub-unit operating under the broader Lazarus Group. These are the people behind the fake IT worker schemes that have been circulating for years, and they have apparently expanded their repertoire considerably. The group built entire fictitious companies complete with AI-generated websites, GitHub accounts, and email infrastructure, all designed to support insider threat operations.
Their supply-chain work was particularly creative. Between January and February, Famous Chollima published trojanised repositories on GitHub targeting cryptocurrency and blockchain developers. The repos looked legitimate enough, but opening them triggered hidden scripts that handed attackers access to developers' environments automatically. No clicks required beyond the usual workflow.
Threat hunters also suspect a Lazarus Group offshoot, tracked as Stardust Chollima or Sapphire Sleet depending on who you ask, was behind the Axios supply chain attack in March. Amazon separately attributed four npm package compromises over the past 18 months to the same North Korean cluster.
On the financially motivated side, a crew CrowdStrike calls Altered Spider managed to compromise over 300 software dependencies in a single day, hoovering up credentials before pivoting into cloud environments for theft and extortion. Meyers described their movement speed as striking: endpoint to cloud in seconds to minutes. When attackers are operating that fast, any detection strategy built around human response times is already too slow.
The vulnerability picture is no cheerier. Between January and June, 88 percent of exploitation using public proof-of-concept code happened within 48 hours of that code becoming available. China-linked groups were even quicker, with some launching attacks within 24 hours of a disclosure. The practical implication is that the 30-day patching window, which was already aspirational rather than realistic for most organisations, is now effectively fiction.
AI is also dramatically accelerating bug discovery, which means the CVE pipeline is swelling fast. In 2025, roughly 48,200 CVEs were registered. This year, with several months still to go, the count is already approaching 43,000. June alone produced over 7,600 reported software vulnerabilities. Sysadmins chasing patches are essentially trying to fill a bath with the taps running at full pressure.
The compounding problem is clear enough: more bugs found faster, exploited faster, against defenders who are already stretched. CrowdStrike's Meyers called the vulnerability ecosystem "the big story for the next couple of months." At current trajectory, probably longer than that.