TLDR: The CrowdStrike 2025 Threat Hunting Report highlights a significant shift in cyber warfare, with adversaries increasingly leveraging Artificial Intelligence, particularly Generative AI (GenAI), to conduct large-scale, sophisticated attacks. The report reveals that AI is being weaponized to accelerate operations, scale social engineering tactics, and target autonomous AI agents, creating a new frontier for enterprise vulnerabilities. Traditional defenses are proving inadequate against these AI-powered, often malware-free, intrusions.
The cybersecurity landscape is undergoing a profound transformation, as detailed in the CrowdStrike 2025 Threat Hunting Report, released on August 4, 2025. The report unequivocally states that cybercriminals are now extensively utilizing Artificial Intelligence (AI) and Generative AI (GenAI) to amplify the scale and sophistication of their attacks, marking a new and dangerous phase in modern cyber threats. Adam Meyers, CrowdStrike’s Head of Counter Adversary Operations, noted, ‘The AI era has redefined how businesses operate, and how adversaries attack. We’re seeing threat actors use GenAI to scale social engineering, accelerate operations, and lower the barrier to entry for hands-on-keyboard intrusions.’
Key findings from the report, which draws insights from CrowdStrike’s OverWatch team’s investigations between July 1, 2024, and June 30, 2025, paint a concerning picture. Over 320 organizations have been infiltrated by North Korea-linked (DPRK-nexus) adversaries employing GenAI-accelerated attacks. A striking statistic reveals that 81% of interactive intrusions—where attackers actively modify tactics in real-time—were malware-free, indicating a shift towards more stealthy, identity-based attacks. Overall, interactive intrusions increased by 27% over the past year, demonstrating adversaries’ enhanced ability to innovate and bypass legacy detection methods.
One of the most critical revelations is that autonomous AI agents and the tools used to develop them have become a primary target and a new attack surface for cybercriminals. Threat actors are exploiting vulnerabilities in these tools to gain unauthorized access, establish persistence, steal credentials, and deploy malware and ransomware. This signifies that autonomous systems and system-generated identities are now central components of the enterprise attack surface.
GenAI is being weaponized in various ways:
Scaling Operations and Deception: Adversaries are using GenAI to accelerate the speed, scale, and deception in their attacks. For instance, the DPRK-nexus adversary FAMOUS CHOLLIMA has leveraged GenAI to automate every phase of its insider attack program, from creating synthetic résumés and conducting deepfake interviews to performing technical tasks under false identities.
Social Engineering: Iran-nexus adversary CHARMING KITTEN has deployed LLM-crafted phishing lures targeting entities in the U.S. and EU, while Russia-nexus adversary EMBER BEAR used GenAI to amplify pro-Russia narratives.
Lowering Entry Barriers: GenAI is enabling lower-tier eCrime and hacktivist groups to generate scripts, solve technical problems, and even build malware, automating tasks that previously required advanced expertise. Examples like Funklocker and SparkCat demonstrate that GenAI-built malware is already operational.
Malware-Free Tactics: The report highlights that AI has enabled malware-free tactics, automated lateral movement, and scaled social engineering, rendering many traditional defenses obsolete.
The report also notes a significant surge in cloud intrusions, with a 136% increase observed in the first half of 2025. Adversaries linked to China, such as GENESIS PANDA and MURKY PANDA, are exploiting misconfigurations and trusted relationships to move across cloud environments. Groups like SCATTERED SPIDER have resurged with faster, more aggressive tradecraft, employing vishing (voice phishing) and help desk impersonation to reset credentials, bypass multi-factor authentication (MFA), and move laterally across SaaS and cloud infrastructures, often sidestepping endpoint detection entirely.
Also Read:
- AI-Powered Open-Source Platform Revolutionizes Cyber Attack Automation
- Accelerated AI Adoption Demands Faster Data Security Evolution
CrowdStrike emphasizes that traditional cybersecurity tools, designed for a world of malware and single-domain attacks, are ill-equipped to handle today’s AI-enabled adversaries who operate malware-free, navigate across domains at machine speed, and exploit human trust through AI-enabled deception. The report underscores the urgent need for a new approach to security to counter this revolution in adversary operations.


