2 min Security

AI is now a tool, target, and force multiplier for hackers

AI is now a tool, target, and force multiplier for hackers

AI has become a tool, a target, and a force multiplier for attackers. Chinese groups strike within 24 hours of a proof-of-concept (PoC), while North Korean actors have compromised 131 trusted AI framework packages.

This is according to research by CrowdStrike. The takeaway is that AI is intertwined with virtually every phase of modern attacks. Attackers use AI to generate payloads and shell commands, exploit AI infrastructure, and abuse enterprise LLMs. In one campaign, nearly 200,000 AI model requests were sent out in two minutes.

The research is based on frontline intelligence from CrowdStrike’s threat hunters, who track more than 290 named adversaries. AI-agent-triggered detection leads grew 2.5 times faster than those generated by humans. Attacks are accelerating, scaling more efficiently, and increasingly targeting the very AI systems that companies rely on.

The AI ecosystem is emerging as the next battleground. The North Korean group STARDUST CHOLLIMA injected a malicious npm package into 131 trusted Mastra AI frameworks. In the first half of 2026, 87 percent of the detected threats in software registries involved malicious npm packages. The eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day to harvest credentials.

Exploitation windows are shrinking to hours

Speed stands out. In the first half of 2026, 88 percent of vulnerability exploits observed by CrowdStrike, using a proof-of-concept, occurred within 48 hours of publication. The Chinese actors VAULT PANDA and GENESIS PANDA moved even faster: they launched targeted attacks within 24 hours of disclosure.

Attackers are also following AI into the cloud. Cloud-conscious eCrime activity rose by 171 percent, including credential theft, cryptomining, LLM abuse, and theft of digital financial assets.

“AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend,” says Adam Meyers, head of counter-adversary operations at CrowdStrike.

Tip: Microsoft and CrowdStrike are aligning threat naming conventions