AI is ‘both the weapon and the target’ in latest wave of cyberattacks

← Back to the feed

AI is ‘both the weapon and the target’ in latest wave of cyberattacks

The Register · 3 hours ago

CrowdStrike's latest annual Threat Hunting Report finds that artificial intelligence has become both a weapon and a target in cyberattacks, with AI-enabled adversary activity surging 89 percent in 2025. The firm's counter adversary chief Adam Meyers said AI is now a high-value attack surface being exploited by an increasing number of state-backed and financially motivated threat actors, spanning credential theft against AI APIs, supply-chain poisoning, and manipulation of AI-dependent development pipelines.

The report highlights techniques such as "LLMjacking", where criminals steal corporate credentials to access frontier-model APIs, and "cost harvesting", which inflates a victim's AI usage bill; one case saw roughly 200,000 API requests sent in two minutes. CrowdStrike, which tracks more than 290 adversary groups, singled out the North Korean-linked Famous Chollima crew for the most advanced AI use, including building entire fake companies with AI-generated websites and staff profiles, while another financially motivated group, Altered Spider, compromised over 300 software dependencies in a single day before pivoting into victims' cloud environments.

  • AI-enabled cyberattacks rose 89% in 2025, CrowdStrike reports
  • North Korea's Famous Chollima built fake AI-generated firms for insider attacks
  • Attackers also target AI infrastructure and poison software supply chains

New here? Start with this

AI-powered cyberattacks have accelerated sharply, according to the security firm CrowdStrike, which monitors hacking groups worldwide through its annual threat report. Rather than AI simply being a tool criminals use to write better phishing emails, the report describes a shift where AI systems themselves, such as the accounts and services that let companies access chatbots and other AI models, have become valuable targets for theft and abuse.

CrowdStrike tracks hundreds of hacking groups, ranging from those working on behalf of governments to those simply after money. Among those named are a North Korea-linked group known for elaborate scams, and a separate financially motivated group that has targeted software supply chains, the network of code and components that businesses rely on to build their own products.

The issue matters because businesses have rapidly adopted AI tools without always securing them as carefully as older systems, leaving a growing and lucrative gap for criminals to exploit, whether by running up victims' AI bills, stealing access credentials, or tampering with the software pipelines that AI development depends on.

AI Business Cybersecurity Markets Technology

Read the full article at the source →