CrowdStrike 2026 Threat Hunting Report: AI Embedded Across Modern Adversary Operations

CrowdStrike has officially published its 2026 Threat Hunting Report, detailing how artificial intelligence has evolved from an experimental tool into an operational capability, a primary target, and a force multiplier for threat actors.
Based on frontline telemetry gathered by CrowdStrike’s OverWatch threat hunters and intelligence analysts tracking more than 290 namedadversaries, the report warns that adversaries are systematically exploiting AI infrastructure, poisoning open-source software supply chains, abusing enterprise Large Language Models (LLMs), and following AI workloads directly into multi-cloud environments.
As enterprises rapidly deploy autonomous agents and LLM frameworks to streamline daily workflows, threat actors are adapting their techniques to exploit these expanded attack surfaces. The findings confirm that attacks are executing with greater speed and efficiency, compressing the time defenders have to detect and neutralise intrusions before data exfiltration occurs.
Core Intelligence Findings: Speed, Supply Chains, and Identity Vulnerabilities
The report highlights several key trends reshaping enterprise cybersecurity risks:
Weaponisation of Enterprise AI Infrastructures: Threat actors are abusing legitimate corporate LLMs for automated intelligence gathering and rapid script execution. In one notable campaign documented by OverWatch, an adversary generated nearly 200,000 AI model requests in just two minutes. Furthermore, AI agent-triggered detection leads grew at 2.5x the rate of human-triggered leads, illustrating how automated software agents are accelerating the sheer volume of suspicious activity security operations centres (SOCs) must analyse.
The AI Ecosystem as a Supply Chain Battleground: Software registries are increasingly targeted for distribution attacks. North Korea-nexus actor STARDUST CHOLLIMA injected malicious code into an npm package, compromising 131 trusted Mastra AI framework repositories. Overall, 87% of identified software registry threats in 1H 2026 involved malicious npm packages, while eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day to harvest cloud access credentials.
Exploitation Windows Collapse to Hours: The window between public vulnerability disclosure and active exploitation continues to shrink. During 1H 2026, 88% of observed vulnerability exploits featuring a public Proof-of-Concept (PoC) occurred within 48 hours. China-nexus adversaries VAULT PANDA and GENESIS PANDA moved even faster, launching targeted attacks within 24 hours of public disclosure.
Adversaries Follow AI Workloads into the Cloud: Cloud-conscious eCrime activity surged 171% year-over-year. Adversaries are executing credential harvesting, cryptomining, enterprise LLM resource theft, and digital financial asset exfiltration directly within cloud environments.
Abusing Trusted Authentication and Identity Pathways: Voice phishing (vishing) intrusionsdoubled in 1H 2026, while monthly device code phishing attempts spiked 15x. eCrime groups CORDIAL SPIDER and SNARKY SPIDER routinely targeted Single Sign-On (SSO) integrated SaaS applications to exfiltrate corporate data. In one monitored intrusion, SNARKY SPIDER progressed from initial account takeover to full data theft in under five minutes.
| Operational Threat Metric | Traditional Legacy Baseline | CrowdStrike 2026 Report Finding |
| Vulnerability Exploit Speed | Weeks or days following patch release. | 88% exploited within 48 hours (China-nexus < 24 hours). |
| Software Registry Risk | Isolated typosquatting attempts. | 87% of registry threats target npm; 131 AI frameworks poisoned. |
| Cloud Intrusion Growth | Endpoint-centric lateral movement. | 171% increase in cloud-conscious eCrime intrusions. |
| Identity & Authentication Attacks | Password spraying and basic MFA fatigue. | 2x increase in vishing; 15x spike in device code phishing. |
Adam Meyers, Head of Counter Adversary Operations at CrowdStrike, detailed why organisations must adapt their defensive strategies to match adversary speed:
“AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend. The organizations that succeed will secure AI as aggressively as they adopt it and use AI to defend at the speed of the adversary.”
By uniting AI-driven threat hunting, continuous identity protection, and real-time cloud visibility, organisations can defend against automated attack vectors and stop breaches before adversaries achieve lateral movement.
Read More:
Why AI-ready data centres need more than computing power
Garmin expands retail network as premium wearable demand grows
Nutanix explains how hybrid multi-cloud services will define channel growth
Why Dell believes AI PCs need consultative selling, not hardware transactions






