News

CrowdStrike: Cloud Crime Surges as Attackers Turn Trust Against Defenders

Cyberattackers are increasingly turning the technologies and relationships enterprises trust most -- including cloud identities, AI tools, software dependencies and legitimate authentication processes -- into paths for intrusion, according to CrowdStrike's latest threat-hunting research.

The CrowdStrike 2026 Threat Hunting Report, based on activity observed from July 1, 2025, through June 30, 2026, documents a 171% increase in cloud-conscious eCrime activity as financially motivated adversaries pursued credentials, cryptomining capacity, large language model access and digital financial assets.

The cloud finding is part of a broader shift running through the 59-page report. Rather than simply breaking through an external perimeter and moving laterally across endpoints, adversaries are increasingly entering through trusted accounts, tokens, applications and software components. Once authenticated, they can operate inside cloud and software-as-a-service (SaaS) environments using mechanisms that resemble legitimate business activity.

To demonstrate the difference in focus since last year, here is the company's 2026 highlight infographic:

2026 Report Highlights
2026 Report Highlights (source: CrowdStrike).

Here is the company's 2025 highlight infographic:

Highlights
[Click on image for larger view.] 2025 Report Highlights (source: CrowdStrike).

AI Becomes Tool, Target and Attack Surface
Artificial intelligence appears throughout the report in several distinct roles. Adversaries used generative AI to produce commands, payloads, reconnaissance scripts and credential-harvesting tools. Other attackers targeted AI infrastructure itself to steal access, consume computing resources or obtain sensitive configuration information.

CrowdStrike OverWatch found that AI agent-triggered detection leads were appearing at 2.5 times the rate of human-triggered leads. The finding does not compare the accuracy or effectiveness of AI agents with human hunters. Instead, CrowdStrike presents it as evidence that AI-generated activity is increasing the volume and speed of signals that defenders must investigate.

One financially motivated attacker used a compromised cloud identity and long-term access key to target a cloud service providing access to foundation models. After testing account permissions and creating temporary credentials, the attacker flooded the service with nearly 200,000 application programming interface requests in two minutes.

CrowdStrike characterizes such activity as "LLMJacking," in which an adversary obtains unauthorized access to an organization's large language model resources. The resulting harm can include service charges, exhausted quotas and operational disruption even if the attacker does not steal conventional enterprise data.

The report also found AI-related infrastructure becoming an initial-access route. AI Model Access techniques accounted for 16% of the MITRE ATLAS techniques CrowdStrike observed during the reporting period, while Impact techniques accounted for 8%. The most common Impact technique was "cost harvesting," in which attackers deliberately drive up a victim's AI-service consumption and resulting expense.

Exploitation Windows Contract to Hours
The speed of vulnerability exploitation emerged as another major finding. From January through June 2026, 88% of the exploitation CrowdStrike observed involving a publicly available proof of concept occurred within 48 hours of the proof of concept's release.

China-nexus adversaries VAULT PANDA and GENESIS PANDA moved faster, launching deliberate attacks within 24 hours of public disclosure of a critical web application vulnerability. Following disclosure of React2Shell, CrowdStrike generated more than 800 hunting leads across more than 80 victims in four days.

CrowdStrike timelines show how quickly adversaries exploited the React2Shell and CopyFail vulnerabilities after disclosure.
[Click on image for larger view.] CrowdStrike timelines show how quickly adversaries exploited the React2Shell and CopyFail vulnerabilities after disclosure. (source: CrowdStrike).

The report stops short of attributing all of that speed to AI. CrowdStrike says the pattern of rapid exploitation predates frontier AI, but expects advanced models to compress the interval further by accelerating vulnerability discovery, exploit development and attack-path identification.

Supply-Chain Attacks Follow AI into Development
Attackers are also exploiting trust upstream in the developer ecosystem, targeting continuous integration and continuous delivery pipelines, container registries, package registries and integrated development environment extensions.

Node Package Manager (npm) packages accounted for 87% of the malicious software-registry threats CrowdStrike identified during the first half of 2026. The report attributes that concentration to JavaScript's scale, extensive dependency chains and automatic installation scripts, which can allow one compromised component to spread into numerous downstream environments.

ALTERED SPIDER compromised more than 300 software dependencies in one day, using the access to harvest credentials and pivot into cloud environments. North Korea-nexus STARDUST CHOLLIMA separately injected a malicious dependency into at least 131 packages associated with the Mastra AI framework.

Another North Korea-nexus group, FAMOUS CHOLLIMA, weaponized AI-centric development environments to target cryptocurrency and blockchain companies. Its campaign placed malicious scripts in otherwise legitimate-looking project repositories. Opening the project in the targeted development environment could cause its terminal or task runner to execute the commands without further interaction.

The pattern places AI development at the intersection of two established risks. AI applications depend heavily on externally maintained packages and frameworks, while their development environments may also hold source code, cloud credentials, model access and connections to production infrastructure.

Overall Volume Stabilizes, but the Measurement Changes
CrowdStrike recorded an approximate 4% increase in overall intrusion activity, far below the 27% year-over-year increase reported in the 2025 edition. That contrast requires an important qualification: CrowdStrike expanded the 2026 report's analytical scope beyond interactive, hands-on-keyboard intrusions to include automated attacks.

The company therefore describes the apparent plateau as evidence of a maturing threat landscape rather than declining adversary intent. Its hunters observed attackers devoting more effort to complex campaigns and innovative initial-access techniques instead of relying as heavily on opportunistic, high-volume attacks.

The changing methodology also makes a simple multiyear intrusion-growth chart inappropriate. Sector-level data within the current report, however, provide a direct comparison between the July 2024-June 2025 and July 2025-June 2026 reporting periods.

CrowdStrike compared intrusion frequency by sector between its July 2024-June 2025 and July 2025-June 2026 reporting periods.
[Click on image for larger view.] CrowdStrike compared intrusion frequency by sector between its July 2024-June 2025 and July 2025-June 2026 reporting periods. (source: CrowdStrike).

Technology remained the most frequently targeted sector for the ninth consecutive year. Most sector rankings and intrusion volumes were relatively stable, but financial services increased 11% and the academic sector increased 17%, the two largest gains in the comparison.

The mix also differed by attacker motivation. Nation-state activity was concentrated most heavily in technology, financial services and government, while eCrime activity favored technology, consulting and professional services, and manufacturing.

Identity Abuse Moves from Theme to Operating Model
Earlier CrowdStrike reports documented the growing importance of identity compromise. The 2023 Threat Hunting Report found that 62% of interactive intrusions involved compromised identities and recorded a 583% increase in Kerberoasting, a technique for obtaining service-account credentials.

The 2024 report advanced that theme into cross-domain attacks. CrowdStrike reported a 55% increase in hands-on-keyboard intrusions and a 70% rise in abuse of legitimate remote monitoring and management tools. It described attackers using valid credentials to move between cloud environments and endpoints while leaving limited evidence in any single security domain.

By 2025, the emphasis had expanded to AI, unmanaged systems and cloud control planes. As Virtualization & Cloud Review reported, CrowdStrike observed a 136% increase in cloud intrusions during the first half of 2025 compared with all of 2024, along with a 40% year-over-year increase in cloud intrusions attributed to suspected China-nexus actors.

That 136% figure is not directly comparable with the new 171% statistic. The earlier measurement covered cloud intrusions and used an unusual half-year-versus-full-year comparison, while the new figure specifically measures cloud-conscious eCrime activity over the report's 12-month period. Together, however, they support a broader conclusion: cloud-specific proficiency is spreading across both nation-state and financially motivated groups.

Vishing Shows a Clear Multiyear Rise
Voice phishing provides one of the report's clearest directly plotted trends. CrowdStrike OverWatch detected twice as many intrusions using vishing as the likely initial-access vector during the first half of 2026 as during the second half of 2025.

The underlying chart extends back to 2022 and shows considerable month-to-month variation but a pronounced upward trend, particularly from 2024 onward. Unlike several of the changing cloud measurements, this graphic follows the same basic activity -- detected intrusions in which vishing was the likely initial-access vector -- over time.

CrowdStrike chart showing the trend in intrusions using vishing as the likely initial access vector
[Click on image for larger view.] CrowdStrike observed a rising trend in intrusions where voice phishing was the likely initial-access vector, including a twofold increase in the first half of 2026 compared with the second half of 2025. (source: CrowdStrike).

CORDIAL SPIDER and SNARKY SPIDER used vishing to compromise single sign-on accounts and exfiltrate data from SaaS applications. In one incident, SNARKY SPIDER progressed from account takeover to data theft in less than five minutes.

The report also documents a related fifteenfold increase in monthly device-code phishing attempts over six months. In these attacks, adversaries abuse the OAuth 2.0 device-authorization flow by inducing victims to enter attacker-controlled codes on legitimate authentication pages. Because the victim completes a real authentication process, the resulting token theft can bypass conventional multifactor authentication defenses.

The vishing and device-code findings show how social engineering has evolved beyond obtaining a reusable password. Attackers increasingly manipulate legitimate authentication workflows to acquire tokens, enroll devices or gain access through single sign-on applications.

Cloud Attacks Move Closer to the Money
Once attackers obtain trusted access, the cloud provides multiple paths to monetization. CrowdStrike observed eCrime groups stealing secrets, hijacking computational resources, abusing enterprise LLMs and pursuing cryptocurrency and instant-payment infrastructure.

In one case, Brazil-based SLIM SPIDER used custom scripts and raw socket connections to obtain temporary credentials from a cloud instance metadata service. The group then extracted secrets from a cloud credential manager, targeted cryptocurrency custody credentials and pivoted into Azure DevOps and a managed Kubernetes cluster.

A separate attacker compromised cloud credentials belonging to a U.S. technology company and deployed a cryptomining operation across virtual machines, container clusters and a cloud machine-learning notebook. The operation used cross-account persistence and altered settings to impede resource termination. CrowdStrike said the associated wallet had mined 88.89 Monero, worth approximately $41,000.

Cloud resource hijacking can generate unauthorized computing charges ranging from $10,000 to more than $100,000, according to the report, while compromised payment infrastructure and digital-asset credentials can expose organizations to direct theft measured in millions.

A Trend Years in the Making
CrowdStrike's separate Global Threat Report series provides still earlier evidence of the same broad movement, though its metrics should not be mixed directly with the Threat Hunting Report data.

A 2023 V&CR examination of the Global Threat Report noted that cloud exploitation had increased 95% during 2022 and incidents involving cloud-conscious threat actors had nearly tripled from 2021. That report also found a 112% increase in advertisements from initial-access brokers selling entry into compromised environments.

Across the two report series, the progression is more useful than any attempt to combine their percentages. Earlier findings established the growing value of cloud access and compromised credentials. Subsequent reports documented control-plane exploitation and movement between cloud, identity and endpoint systems. The 2026 Threat Hunting Report shows those developments converging with AI infrastructure, trusted OAuth workflows and developer supply chains.

The result is not simply more cloud attacks. It is an operating model in which adversaries seek to appear legitimate: a valid identity, an authorized token, a trusted package, a familiar development tool or an approved cloud service.

For defenders, that moves the detection problem away from identifying obviously malicious files and toward correlating behavior across identity systems, endpoints, SaaS applications, cloud control planes and development infrastructure. Individual actions may look routine. The intrusion becomes visible only when those actions are connected across domains and examined as a sequence.

Featured

Subscribe on YouTube