Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Report: AI now ‘embedded’ within the cyber adversary ecosystem

CrowdStrike’s 2026 Threat Hunting Report reveals an uncomfortable fact: for hackers, artificial intelligence is a tool, a force multiplier, and a target.

Tue, 04 Aug 2026
Report: AI now “embedded” within the cyber adversary ecosystem

Cyber security firm CrowdStrike released its 2026 Threat Hunting Report overnight, revealing the full scope of the impact of artificial intelligence in adversary operations for both nation-state actors and criminal operators.

Hackers of both stripes, according to the report, are now commonly using AI in three distinct areas: developing resources, gaining initial access, and accessing AI models themselves.

Resource development is the field where AI is used, largely to generate payloads and utility shell commands once access is achieved.

 
 

The North Korean-linked actor known as Famous Chollima is arguably the most notable user of AI in this manner, and has been observed creating entire fake organisations, complete with websites, email infrastructure, and even GitHub accounts, all to support its activity.

“Other state-sponsored threat actors employed LLM-generated reverse shells with professional commenting and resilient auto-reconnect logic or used LLM-generated commands for reconnaissance and data collection,” CrowdStrike said in its report.

“Meanwhile, eCrime threat actors have utilised utility scripts, reverse shells, and credential harvesters likely written by LLMs.”

Used like this, AI, CrowdStrike contends, is lowering the bar for entry for less-skilled adversaries, letting threat actors operate faster and at higher relative skill levels.

Famous Chollima’s activity earlier in 2026 was also a perfect example of using AI to gain initial access. Through January and February, the group created several seemingly legitimate repositories on GitHub, each one hosting project files containing malicious scripts.

When opened, a built-in terminal ran malicious commands automatically – and without any victim interaction – which gave the threat actor access to the targeted environment.

Finally, threat actors are increasingly attempting to either access AI models and exploit AI-related server software, or impact how organisations actually use AI. For example, CrowdStrike observed one adversary delivering a crypto-mining payload via a vulnerability in AI-related server software.

The company has also observed threat actors using a technique known as cost harvesting, whereby the actor deliberately drives a victim’s use of AI beyond normal capacity, driving up the cost of those services and causing the victim financial harm.

CrowdStrike also noted a massive increase in zero-day exploitation, a trend that it expects AI to impact even more severely. Between January and June, 88 per cent of all the vulnerabilities with a publicly available proof of concept were exploited within 48 hours of publication.

While this data may predate the widespread use of frontier AI to discover vulnerabilities, the company fully expects the time between disclosure and exploitation to continue to drop.

“AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organisations must defend,” Adam Meyers, head of counter adversary operations at CrowdStrike, said in a 3 August statement.

“The organisations that succeed will secure AI as aggressively as they adopt it and use AI to defend at the speed of the adversary.”

You can read the full report here.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: