CrowdStrike’s 2026 Global Threat Report indicates that artificial intelligence is both a primary accelerant and a growing target for cyber adversaries, leading to a significant decrease in breakout times and an expansion of attack vectors.
The report, compiled from intelligence gathered by CrowdStrike’s threat hunters and intelligence analysts tracking over 280 named adversaries, highlights that the average eCrime breakout time dropped to 29 minutes in 2025. This represents a 65% increase in speed from 2024, with the fastest recorded breakout occurring in a mere 27 seconds. Adversaries are actively exploiting AI systems, injecting malicious prompts into legitimate generative AI (GenAI) tools at more than 90 organizations, and misusing AI development platforms.
Prompts have emerged as a new form of malware, used by adversaries to generate commands for credential and cryptocurrency theft. Attackers have also leveraged vulnerabilities in AI development platforms to establish persistence and deploy ransomware, alongside publishing malicious AI servers that impersonate trusted services to intercept sensitive data.
The use of AI by both nation-state and eCrime actors has surged by 89% year-over-year. Russia-nexus FANCY BEAR has deployed LLM-enabled malware (LAMEHUG) for automated reconnaissance and document collection. eCrime actor PUNK SPIDER has utilized AI-generated scripts to expedite credential dumping and erase forensic evidence, while DPRK-nexus FAMOUS CHOLLIMA has employed AI-generated personas to scale insider operations.
China-nexus activity saw a 38% increase in 2025, with the logistics sector experiencing an 85% rise in targeting. Notably, 67% of vulnerabilities exploited by China-nexus actors provided immediate system access, and 40% targeted internet-facing edge devices. DPRK-linked incidents increased by over 130%, with FAMOUS CHOLLIMA activity more than doubling. PRESSURE CHOLLIMA was responsible for a $1.46 billion cryptocurrency theft, marking the largest single financial heist reported.
Exploitation of zero-day vulnerabilities also grew, with 42% of vulnerabilities being leveraged before public disclosure for initial access, remote code execution, and privilege escalation. Cloud-conscious intrusions rose by 37% overall, and state-nexus threat actors increased their targeting of cloud environments for intelligence collection by 266%.
Adam Meyers, head of counter adversary operations at CrowdStrike, described the situation as an “AI arms race.” He emphasized that the compressed breakout time signifies a shift in intrusions, with adversaries moving from initial access to lateral movement within minutes. Meyers noted that AI is shortening the gap between intent and execution, simultaneously making enterprise AI systems prime targets, necessitating that security teams enhance their speed to counter these threats.