AI as Weapon and Target: The New Face of Cyberattacks

0
32

Key Takeaways

  • AI is being used both as an offensive weapon and as a high‑value target by cyber‑criminals and nation‑state actors.
  • Machine‑assisted activity has surged 89 % in 2025, with AI‑triggered leads now occurring 2.5 × more often than human‑triggered threats.
  • Public proof‑of‑concept exploit code is weaponized within 48 hours (often < 24 h for China‑linked groups), rendering the traditional 30‑day patch window obsolete.
  • Supply‑chain attacks targeting AI development environments—especially via trojanized GitHub repositories and compromised npm packages—are a primary initial‑access vector.
  • North Korean groups (Famous Chollima, Stardust Chollima/Sapphire Sleet) demonstrate the most advanced AI usage, creating fake companies and automating insider‑threat operations.
  • Financially motivated crews (e.g., Altered Spider/TeamPCP) can compromise hundreds of software dependencies in a single day and pivot rapidly from endpoints to cloud assets.
  • The volume of disclosed vulnerabilities is exploding (≈ 48 200 CVEs in 2025, with > 7 600 reported in June alone), increasing the burden on defenders to patch faster than ever.
  • Organizations must adopt continuous‑monitoring, AI‑driven threat hunting, and hardened CI/CD pipelines to keep pace with the accelerated exploit cycle.

Overview of AI‑Driven Threat Landscape
CrowdStrike’s annual Threat Hunting Report makes clear that artificial intelligence has become a double‑edged sword in cyber conflict. Adversaries are not only leveraging AI to automate reconnaissance, craft convincing phishing lures, and accelerate exploit development, but they are also actively targeting the AI infrastructure that organizations rely on for model training, inference, and data pipelines. Senior VP Adam Meyers succinctly captured this dynamic: “AI is both the weapon and the target.” The report quantifies the shift, noting an 89 % rise in machine‑assisted malicious activity during 2025, with AI‑agent‑triggered leads now outpacing human‑initiated alerts by a factor of 2.5×. This surge reflects the growing accessibility of large‑language‑model (LLM) APIs and the ease with which threat actors can repurpose them for offensive purposes while simultaneously seeking to steal or sabotage the very models they exploit.

AI‑Enabled Attack Techniques
Among the novel tactics observed, LLMjacking stands out: attackers steal corporate credentials to gain unauthorized access to frontier‑model APIs, then abuse those services for illicit computation or data exfiltration. A closely related method, cost harvesting, deliberately inflates a victim’s AI usage to run up billing charges, turning cloud AI spend into a direct revenue stream for criminals. In one documented campaign, a token thief issued roughly 200,000 API requests in just two minutes, illustrating the scale and speed achievable when AI services are weaponized. Beyond direct abuse, threat hunters are tracking a growing number of AI‑agent‑triggered leads—automated alerts generated when malicious AI scripts interact with defender telemetry—indicating that adversaries are increasingly delegating entire stages of the attack chain to autonomous systems.

Notable Adversary Groups
CrowdStrike monitors more than 290 adversary groups, having added roughly ten new entities over the past year. Of these, a North Korean unit tracked as Famous Chollima—a sub‑unit of the Lazarus Group—has demonstrated the most sophisticated AI usage observed in the second half of 2025 and first half of 2026. The group fabricated entire fake companies, complete with AI‑generated websites, GitHub repositories, and email infrastructures, to support insider‑threat operations and to lure developers into compromised environments. Another Lazarus offshoot, Stardust Chollima (also known as Sapphire Sleet), is suspected of orchestrating the March Axios supply‑chain attack. On the financially motivated side, Altered Spider (also referenced as TeamPCP) has shown an ability to compromise more than 300 software dependencies in a single day, harvest credentials and secrets, and pivot rapidly into cloud assets for theft and extortion. Meyers noted that Altered Spider “hits the endpoint in seconds and within minutes, they’re inside of the cloud,” underscoring the velocity enabled by AI‑assisted exploitation.

Supply‑Chain Compromise and AI Infrastructure Targeting
A recurring theme in the report is the exploitation of software supply chains to breach AI‑focused development environments. In January and February 2025, Famous Chollima published trojanized repositories on GitHub that appeared to host legitimate blockchain and cryptocurrency projects. Hidden within these repos were malicious scripts that executed automatically when developers cloned or opened the code, granting the attackers immediate access to the victim’s development environment and, by extension, any AI models or data stored there. Meyers warned that “AIs themselves are being targeted through that supply chain and through the CI/CD pipelines that they’re dependent on.” The same pattern emerged in the npm ecosystem, where Amazon attributed four separate package compromises over the previous 18 months to the North Korean crew. These incidents illustrate how attackers are using AI not only to craft convincing lures but also to automate the insertion of malicious code into trusted build pipelines, thereby bypassing traditional perimeter defenses.

Accelerated Exploitation of Vulnerabilities
Perhaps the most alarming trend highlighted by CrowdStrike is the collapse of the conventional patch window. From January to June 2025, 88 % of observed exploits that relied on publicly released proof‑of‑concept code occurred within 48 hours of the code’s disclosure, with China‑linked groups such as Vault Panda and Genesis Panda frequently striking in under 24 hours. Meyers emphasized that AI is now a key driver of this acceleration: “Vulnerabilities are weaponized through the use of AI.” The rapid creation of exploit code shortens the timeline defenders have to assess, test, and deploy patches, rendering the once‑aspirational 30‑day cycle completely obsolete. Concurrently, AI’s proficiency at bug discovery is inflating the volume of disclosed vulnerabilities. In 2025, approximately 48 200 CVEs were registered; by late July 2026, the count had already reached 43 000, with June alone contributing more than 7 600 new CVEs. This deluge forces sysadmins into a relentless race to patch before attackers reverse‑engineer updates and field functional exploits.

Implications for Defenders and Recommendations
The convergence of AI‑powered offense, shrinking exploit windows, and an exploding vulnerability landscape demands a fundamental shift in defensive strategy. Organizations should prioritize continuous monitoring of AI‑service usage, enforce least‑privilege access to model APIs, and implement anomaly‑detection systems capable of spotting abnormal API call patterns—such as the 200 k‑request bursts seen in LLMjacking attacks. Strengthening software supply‑chain integrity is equally critical: enforce signed commits, employ automated dependency‑scanning tools that flag hidden scripts, and harden CI/CD pipelines against unauthorized code injection. Given that exploits now appear within hours of disclosure, adopting a “patch‑as‑you‑go” mindset—leveraging automated patch management, virtual patching, and runtime protection—can help close the gap between detection and remediation. Finally, investing in AI‑driven threat hunting that correlates machine‑generated alerts with contextual threat intelligence will enable security teams to keep pace with the 2.5× increase in AI‑triggered leads and maintain visibility over both human and autonomous adversary activity.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here