VYPR
researchPublished Aug 3, 2026· 2 sources

AI Becomes Double-Edged Sword in Cyberattacks, CrowdStrike Report Reveals

Cyber adversaries are increasingly leveraging Artificial Intelligence for malicious purposes while simultaneously targeting AI infrastructure, marking a significant escalation in cyber threats, according to CrowdStrike's latest report.

The cybersecurity landscape is witnessing a dramatic shift as Artificial Intelligence (AI) emerges as both a potent weapon for attackers and a high-value target, according to CrowdStrike's annual Threat Hunting Report. The report details an alarming 89% surge in AI-enabled cyberattacks throughout 2025, with threat actors across both criminal and nation-state groups integrating AI tools across the entire attack chain. This evolution signifies a fundamental change in how cyber threats are conceived and executed.

Adversaries are not only employing AI to enhance their existing attack methodologies but are also actively targeting the very infrastructure that powers AI development and deployment. This dual approach includes sophisticated techniques like 'LLMjacking,' where criminals pilfer corporate credentials to gain unauthorized access to advanced AI model APIs, and 'cost harvesting,' a method designed to inflate a victim's AI usage bills through deliberate overconsumption. CrowdStrike documented instances where a single token thief initiated approximately 200,000 API requests in mere minutes, illustrating the scale and speed of these AI-driven attacks.

The report highlights that CrowdStrike's threat hunting team now tracks AI agent-triggered leads at a rate 2.5 times higher than human-triggered threats. This trend is consistent across various threat actor types, from government-backed entities to financially motivated cybercriminals. Among the most sophisticated users of AI identified is North Korea's Famous Chollima group, a unit operating under the Lazarus Group umbrella. This group has demonstrated advanced AI capabilities by creating entire fake companies, complete with AI-generated websites, GitHub repositories, and email infrastructure, to facilitate insider threat operations.

AI supply-chain compromise has become a significant vector for initial access, ranking as the second most common MITRE ATLAS technique observed. Famous Chollima's campaign, which targeted AI-focused development environments, exemplifies this by publishing trojanized repositories on platforms like GitHub. These repositories contained legitimate-looking project files alongside hidden malicious scripts that executed commands upon opening, granting the attackers access to developers' environments. This tactic underscores the vulnerability of AI development pipelines and the software packages they depend on.

Financially motivated groups are also capitalizing on the AI trend. CrowdStrike tracks a group known as Altered Spider, which has compromised over 300 software dependencies in a single day, specifically targeting developers' AI tools. This campaign focused on harvesting credentials and sensitive secrets before pivoting into cloud environments for theft and extortion. The speed at which Altered Spider operates, moving from endpoint compromise to cloud infiltration within minutes, highlights the accelerated pace of modern cyberattacks, largely facilitated by AI.

Furthermore, AI is dramatically shrinking the window for vulnerability exploitation. CrowdStrike observed that 88% of exploitation attempts using public proof-of-concept (PoC) code occurred within 48 hours of the code's release between January and June. Nation-state actors, such as China-linked groups Vault Panda and Genesis Panda, have been observed launching attacks within 24 hours of vulnerability disclosure. This rapid weaponization of exploits renders traditional patch management cycles obsolete, forcing organizations into near-instantaneous patching.

The sheer volume of newly discovered vulnerabilities is also escalating, partly due to AI's capability in code analysis. With approximately 48,200 CVEs registered in 2025 and already nearing that number by August 2026, the vulnerability ecosystem presents a growing challenge. June alone saw over 7,600 software bugs reported. This burgeoning landscape of vulnerabilities, coupled with AI's ability to rapidly develop exploits, creates a fertile ground for attackers and places immense pressure on defenders to keep pace.

In conclusion, the dual role of AI as both an enabler of sophisticated cyberattacks and a target itself presents a complex and evolving threat landscape. Organizations must not only bolster their defenses against AI-powered intrusions but also secure their AI infrastructure and supply chains to mitigate the risks associated with this transformative technology.

The new article from CyberScoop provides further detail on CrowdStrike's findings, emphasizing the alarming speed at which AI is weaponizing vulnerabilities, with 88% being exploited within 48 hours. It also highlights how AI is expanding the attack surface by creating new targets like AI tools themselves and the associated infrastructure, necessitating a drastic reduction in patching cycles to a 24-48 hour window.

Synthesized by Vypr AI