threat_intelligence882 wordsRead on Arc Codex

CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates

The CrowdStrike 2026 Threat Hunting Report illustrates the next evolution in trust abuse. Adversaries are targeting trusted users and tools across identity systems, cloud environments, SaaS applications, AI services, software supply chains, and developer workflows to blend into legitimate business activity and reach critical assets before defenders can detect them. Our frontline intelligence in this year’s report underscores this shift: - One LLMJacking campaign generated nearly 200,000 API requests in two minutes, resulting in large-scale financial and operational impact. - Vishing intrusions in the first half of 2026 increased 2x compared to the second half of 2025. - eCrime threat actors CORDIAL SPIDER and SNARKY SPIDER used vishing to exfiltrate data from SaaS applications and compromise single sign-on accounts; in one case, SNARKY SPIDER moved from account takeover to data theft in under five minutes. - Monthly device code phishing attempts jumped 15x in the past six months. Organizations that understand these evolving threats are better prepared to stop them. The CrowdStrike 2026 Threat Hunting Report provides the information they need. In its pages, the CrowdStrike Counter Adversary Operations team, composed of CrowdStrike Intelligence and CrowdStrike OverWatch, details key observations and trends that define the modern threat landscape. AI Evolves as an Adversary Tool and Target The same AI tools driving modern businesses forward are creating underdefended attack surfaces, and threat actors are taking advantage. AI systems have become targets for adversaries seeking to steal secrets, abuse AI model access, and harvest compute power. FAMOUS CHOLLIMA, associated with the Democratic People’s Republic of Korea (DPRK), is among those driving this trend. This adversary weaponized trusted AI-centric environments to compromise cryptocurrency and blockchain companies. Its campaign was among the most sophisticated examples of the MITRE ATLAS™ initial access technique AI Supply Chain Compromise (AML.T0010). Widespread AI adoption is increasing the volume of signals across customer environments that threat hunters must assess. AI agent-triggered detection leads now surface 2.5x more threat leads than manually driven activity, CrowdStrike OverWatch found. This increase makes it more difficult for defenders to distinguish malicious activity from expected AI-driven behavior. Vulnerability Exploitation Windows Collapse to Hours Adversaries are accelerating vulnerability exploitation and putting pressure on patching cycles. From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public PoC was conducted within 48 hours of the PoC’s release. China-nexus adversaries moved faster: VAULT PANDA and GENESIS PANDA launched deliberate attacks within 24 hours of public disclosure of a critical web application vulnerability. After the React2Shell vulnerability disclosure, CrowdStrike OverWatch responded to 800+ hunting leads across more than 80 victims in just four days. Belarus-nexus adversary UMBRAL BISON is also quick to act, as evidenced by its exploitation of Linux LPE vulnerability CVE-2026-31431 in April 2026. On April 29, the vulnerability was publicly disclosed, and an industry researcher released a PoC exploit and technical details for it. The following day, CrowdStrike OverWatch detected widespread deployment of the exploit, with approximately 94% of events in the first 24 hours related to testing behavior based on public PoC code. They uncovered Belarus-nexus activity in just over 20 hours after public disclosure. CrowdStrike anticipates exploitation timelines will continue to shrink. While this pattern predates the emergence of frontier AI models, the implementation of these systems is likely to compress vulnerability exploitation timelines by accelerating vulnerability discovery and exploit development. This could, in turn, increase the pressure on defenders already struggling to keep pace. Software Supply Chain Attacks Evolve Adversaries are exploiting trust across the developer ecosystem as open-source dependency adoption accelerates. They are moving into CI/CD pipelines, container registries, package registries, and integrated development environment (IDE) extensions, where one compromised dependency or trusted component can rapidly spread across downstream environments. Over the past year, DPRK-nexus adversary STARDUST CHOLLIMA and ALTERED SPIDER drove some of the most consequential software supply chain attacks and demonstrated how both nation-state and financially motivated threat actors are targeting this attack surface. ALTERED SPIDER, for example, compromised more than 300 software dependencies in one day, harvested credentials, and pivoted into cloud environments. In March 2026, STARDUST CHOLLIMA used stolen maintainer credentials to compromise the Axios Node Package Manager (npm) package and deliver platform-specific variants of their ZshBucket malware. In June 2026, the same adversary injected a malicious npm package as a dependency into at least 131 Mastra AI framework packages, indicating that trusted AI building blocks are becoming supply chain targets. The npm package ecosystem, referenced in the above scenario, is the primary vector for supply chain attacks: 87% of identified software registry threats in the first half of 2026 involved npm packages. This indicates adversaries’ preference for JavaScript’s scale, dependency chains, and automatic install scripts to spread downstream risk. Always Watching the Adversary CrowdStrike now tracks 290+ named adversaries. The CrowdStrike 2026 Threat Hunting Report provides critical information on the threat activity we have observed in the past year, and the adversaries behind it, to give readers a detailed picture of the modern threat landscape. To learn more about what we’re seeing, download the full report. Additional Resources - Learn more about CrowdStrike Counter Adversary Operations threat intelligence and threat hunting. - Tune in to the Adversary Universe podcast, where CrowdStrike reveals the threat actors behind the latest cyberattacks. - Interested in learning more? Join us at Fal.Con 2026, where these conversations take center stage.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.