
⚡ TL;DR — Key Takeaways
- The 2026 CrowdStrike Threat Hunting Report confirms that intrusion volume has plateaued (a 4% increase, down sharply from 27% the prior year), signaling a maturing threat landscape where adversaries invest in sophisticated, trust-based campaigns rather than high-volume opportunistic attacks.
- Identity and SaaS have become the primary battlefield: vishing-based intrusions surged 134% year-over-year, and OAuth 2.0 device code phishing attempts increased 15x in the last six months alone.
- Cloud-conscious escalation is accelerating: cloud-conscious eCrime activity increased 171% over the past 12 months, with attackers hijacking compute resources, harvesting cloud secrets, and pivoting into cryptocurrency and payment infrastructure.
- AI is simultaneously a weapon and a target: a 42% year-over-year increase in zero-day exploitation, 88% of public PoC exploits weaponized within 48 hours, and adversaries now actively compromising AI development environments and LLM access (LLMJacking) for direct financial theft.
Table of Contents
The 2026 CrowdStrike Threat Hunting Report documents frontline observations from CrowdStrike OverWatch’s managed threat hunting operation, drawing on activity from July 1, 2025, to June 30, 2026. CrowdStrike maintains detailed intelligence on more than 290 attributed eCrime, nation-state, and hacktivist adversaries, alongside more than 150 active malicious activity clusters not yet formally named, with 10+ new adversaries named in 2026, including eCrime adversary ALTERED SPIDER.
Operational scale: CrowdStrike OverWatch analyzes 7 trillion events daily across endpoint, identity, cloud, and next-gen SIEM telemetry, surfacing more than 14 million daily detection leads, producing more than 36,000 annual customer notifications and alerts, and feeding more than 1 million new detections and prevention opportunities back into the Falcon platform over the past 12 months.
Macro intrusion trend: This year’s data reveals an approximate 4% increase in overall intrusion activity, a sharp deceleration from the 27% year-over-year surge reported the prior year. The report characterizes this plateau as reflecting a maturing threat landscape, not reduced adversary intent — adversaries are investing in complex, trust-exploiting campaigns rather than high-volume opportunistic attacks.
Motivation split: Of tracked intrusions, 56% were attributed to eCrime actors and 44% to nation-state actors.
The report explicitly cites one external figure from its sister publication: “AI-enabled adversary activity surged 89% in 2025… The CrowdStrike 2026 Global Threat Report showed [this].” This is the only Global Threat Report statistic directly quoted within this document; it is repeated here strictly because the Threat Hunting Report itself states it, not because it was independently verified within this file.
AI agent detection volume: CrowdStrike OverWatch has observed AI agent-triggered detection leads now tracking at 2.5x the rate of human-triggered leads.
From a board-level risk reporting perspective, this sharp deceleration from a 27% year-over-year surge down to a plateaued 4% increase in overall intrusion volume marks a critical psychological shift for modern GRC frameworks. Executive boards frequently look at flat volume metrics and falsely assume their security boundaries are achieving containment. The 2026 dataset proves the exact opposite: adversaries have simply abandoned low-yield, loud, opportunistic botnet sweeps in favor of highly targeted, silent, trust-exploiting access campaigns. Risk officers must immediately pivot their executive dashboards away from vanity ‘blocked attack volume’ graphs and instead track identity-perimeter resilience, internal access control drift, and active multi-domain compromise windows.
SECTION 1: INTRUSION TRENDS BY ADVERSARY & SECTOR TARGETING
Sector Targeting Overview
Technology retained its position as the most targeted sector for the ninth consecutive year, recording a 5% increase in intrusion activity, targeted by nation-state (59%) and eCrime (41%) actors in near-equal measure. FAMOUS CHOLLIMA’s operations alone accounted for 55% of all nation-state intrusions and 44% of all intrusions targeting the technology sector during the reporting period — the single most active adversary targeting the sector. Almost 54% of all technology sector targeting impacted North American institutions.
Financial Services saw an 11% increase in intrusion activity — the largest sector increase in the prior comparison period — with 57% of intrusions from eCrime and 43% from nation-state actors. Nation-state intrusion volume targeting financial services specifically surged 29%, the largest nation-state increase of any sector. 48% of financial sector targeting impacted North American institutions.
Academic institutions recorded the largest year-over-year increase of any sector: a 17% surge, split 55% eCrime / 45% nation-state. VICE SPIDER, excluding FAMOUS CHOLLIMA’s sector-agnostic activity, accounted for more than one-fifth of remaining academic-sector intrusions. 60% of academic targeting impacted North American institutions, followed by Southeast Asia (11%) and the Middle East (8%).
Other sector year-over-year changes reported: Consulting and Professional Services +4%, Manufacturing +2%, Retail +8%, Healthcare +5%, Government +7%, Telecommunications +23%, Industrials and Engineering +8%.
Adversary Geographic Footprint
Report maps named adversary disruptions across every major world region between July 1, 2025, and June 30, 2026, spanning North America, Western/Southern Europe, South Asia, East Asia, Southeast Asia, Oceania, the Middle East, and South America. Adversaries named across this global map include FAMOUS CHOLLIMA, STARDUST CHOLLIMA, PUNK SPIDER, PLUMP SPIDER, SLIM SPIDER, HERALD SPIDER, MUSTANG PANDA, CASCADE PANDA, GENESIS PANDA, SCION SPIDER, ETHEREAL PANDA, WARLOCK SPIDER, SPECTRAL KITTEN, STATIC KITTEN, and KRYPTONITE PANDA, each concentrated against sector combinations spanning Technology, Financial Services, Manufacturing, Government, Consulting, Healthcare, Retail, Logistics, and Media.
SECTION 2: MITRE ATT&CK AND MITRE ATLAS TECHNIQUE ANALYSIS
MITRE ATT&CK: Top Post-Exploitation Tactics
The most frequently observed post-exploitation activity clusters around Discovery, Execution, and Stealth. The top three individual techniques are Command and Scripting Interpreter (T1059), System Owner/User Discovery (T1033), and Masquerading (T1036). Per MITRE’s April 2026 framework revision, the broad “Defense Evasion” tactic was retired in favor of two distinct categories: Stealth (blending into legitimate activity) and Defense Impairment (actively disabling security controls).
MITRE ATLAS: AI-Specific Threat Technique Analysis
The top three MITRE ATLAS tactics observed were Resource Development, Initial Access, and AI Model Access.
- Resource Development: The most common AI adoption method is “Obtain Capabilities: Generative AI” (AML.T0016.002) — using generative AI to produce payloads or commands. FAMOUS CHOLLIMA demonstrated the most advanced usage, creating entire fake companies with AI-generated websites, GitHub accounts, and email infrastructure to support insider threat placements.
- Initial Access: Valid Accounts (AML.T0012) was the top technique; AI Supply Chain Compromise (AML.T0010) was the second most common — uniquely tracked under ATLAS.
- AI Model Access techniques accounted for 16% of total MITRE ATLAS techniques observed over the past 12 months.
- Impact techniques accounted for 8% of total MITRE ATLAS techniques, with Cost Harvesting (AML.T0034) — deliberately driving a victim’s AI service costs upward to cause financial harm — the most common Impact technique, commonly referred to as LLMJacking.
CASE STUDY — FAMOUS CHOLLIMA Software Supply Chain Attack (Jan–Feb 2026)
DPRK-nexus FAMOUS CHOLLIMA executed a targeted supply chain campaign against cryptocurrency and blockchain companies by weaponizing an AI-centric IDE, distributing trojanized GitHub repositories (and at least one shared directly via Telegram) with hidden malicious scripts in package.json, .vscode/settings.json, or post-install hooks that auto-executed via the IDE’s built-in terminal, requiring zero further victim interaction.
CASE STUDY — LLMJacking (May 2026)
A financially motivated actor using a cloud identity with a long-term access key ran a large-scale LLMJacking campaign: enumerating account permissions via GetCallerIdentity and DryRun calls, escalating via GetFederationToken with an AdministratorAccess policy attached to a session masquerading as a legitimate login (console-session), then submitting the required AI use-case form and invoking InvokeModelWithResponseStream/InvokeModel hundreds of thousands of times. During an initial two-minute flood, the actor sent nearly 200,000 API requests before throttling engaged.
Separately, CrowdStrike’s honeypot infrastructure detected an exploit payload containing a malicious Model Context Protocol (MCP) server configuration designed to harvest and exfiltrate environment variables to an external webhook, and a distinct actor exploited AI-related server software to deliver a cryptomining payload (a binary named gmon) via a VPN exit on port 4000.
SECTION 3: THREAT HUNTING IN THE AI ERA — VULNERABILITY WEAPONIZATION
CrowdStrike Intelligence recorded a 42% year-over-year increase in zero-day exploitation from 2024 to 2025. From January to June 2026, 88% of CrowdStrike-observed exploitation of public-PoC vulnerabilities occurred within 48 hours of PoC release.
CASE STUDY — React2Shell (CVE-2025-55182)
A critical insecure deserialization vulnerability enabling unauthenticated RCE in React Server Components/Next.js, disclosed December 3, 2025. Within 24 hours, multiple working PoC exploits circulated, and China-nexus adversaries VAULT PANDA and GENESIS PANDA were both observed exploiting it within roughly a day (VAULT PANDA: +21h53m; GENESIS PANDA: +23h12m post-disclosure). In the first four days, CrowdStrike OverWatch responded to more than 800 hunting leads at more than 80 different victims. VAULT PANDA deployed its “GoneDoor” implant; GENESIS PANDA deployed VShell and SempathyRAT alongside the FScan reconnaissance tool.
CASE STUDY — CopyFail (CVE-2026-31431)
A Linux local privilege escalation zero-day disclosed April 29, 2026 (patched upstream but unpatched across many distributions like Ubuntu). By April 30, approximately 94% of first-24-hour events were legitimate PoC testing, but Belarus-nexus UMBRAL BISON was identified exploiting it against a Ukrainian government entity just over 20 hours after disclosure, deploying a Mythic C2 Poseidon agent (terminated by the Falcon platform). Alongside a related exploit, Fragnesia (CVE-2026-46300), the report states both were “allegedly discovered using AI or AI-assisted research.”
SECTION 4: SOFTWARE SUPPLY CHAIN ATTACKS
Malicious npm packages comprised 87% of all identified malicious software registry packages over the first half of 2026. A single malicious package “can reach millions of users a week.”
Five defining 2026 trends identified:
- Developer ecosystems are the new targets — CI/CD infrastructure (GitHub Actions), container registries, and IDE extensions (VS Code, Open VSX) have become delivery mechanisms, not just package dependencies.
- Attacks are more automated and scalable — ALTERED SPIDER’s self-propagating TeamPCPCloudStealer malware autonomously published infected package versions; during May 2026 campaigns, ALTERED SPIDER compromised more than 300 software dependencies in a single day.
- Identity remains the critical entry point — STARDUST CHOLLIMA compromised dYdX’s Python/Node.js clients (PricePilot malware, Jan 2026), the Axios npm package via stolen maintainer credentials (ZshBucket malware, Mar 2026), and injected a malicious package into at least 131 Mastra AI framework packages (Jun 2026) via a LinkedIn social-engineering operation against a Mastra employee (delivering TeaBundle malware).
- CI/CD pipelines are under attack — ALTERED SPIDER compromised Trivy’s
trivy-actionGitHub Action repository (March 2026) via Git tag poisoning, silently compromising every downstream organization pulling the affected release.
- Adversaries are pivoting into the cloud — TeamPCPCloudStealer specifically targeted cloud access keys, Azure credentials, Google Cloud tokens, Kubernetes service account tokens, SSH keys, CI/CD secrets, container registry credentials, and cryptocurrency wallet keys.
SECTION 5: VISHING AS AN IDENTITY-BASED INITIAL ACCESS VECTOR
CrowdStrike OverWatch detected a 134% increase in vishing intrusions between 2024 and 2025. The first half of 2026 already saw twice the vishing-related intrusions of the second half of 2025.
CASE STUDY — CORDIAL SPIDER and SNARKY SPIDER
Both adversaries vish targets to adversary-in-the-middle (AiTM) SSO pages on personal mobile devices, then log in via residential proxy/VPN services (Mullvad, NSOCKS, VyprVPN), enrolling attacker-controlled MFA devices (CORDIAL SPIDER: consumer mobile brands; SNARKY SPIDER: the Genymobile Android emulator or Windows QEMU) for persistence. In one incident, SNARKY SPIDER moved from account takeover to data exfiltration in under five minutes.
In a February incident, CrowdStrike OverWatch detected CORDIAL SPIDER’s malicious activity and alerted the customer within four minutes of the adversary registering a rogue MFA device — before data exfiltration occurred. Full documented timeline: T+0:00 vishing/AiTM credential capture; T+0:01 authentication via residential proxy; T+0:04 rogue MFA device registered, triggering OverWatch investigation; T+0:10 customer notified; T+0:16 malicious MFA device removed; T+0:19 malicious sessions revoked.
SECTION 6: CLOUD BEYOND THE PERIMETER — CLOUD-CONSCIOUS ADVERSARIES
Cloud-conscious eCrime activity increased 171% over the past 12 months. Since at least February 2025, state-nexus adversaries (including Russia-nexus COZY BEAR) have abused OAuth 2.0 device authorization code flows to phish Entra ID accounts. Device code phishing attempts increased 15x over the last six months, driven partly by new commodity phishing-as-a-service platforms EvilTokens and Kali365.
CASE STUDY — COZY BEAR OAuth Phishing (April 2026)
Targeted a U.K.-based think tank via WhatsApp contact impersonating German ambassador staff, leading to OAuth 2.0 authorization code theft. The critical transition from initial code theft to full compromise took under four hours. CrowdStrike OverWatch and Falcon Complete detected and evicted the adversary within days via behavioral analytics on residential proxy logins.
CASE STUDY — SLIM SPIDER Targeting Brazilian Financial/Crypto Infrastructure (March 2026)
Brazil-based eCrime adversary SLIM SPIDER used custom Bash scripts querying cloud instance metadata services via raw sockets to harvest temporary credentials, extracted at least six secrets from a cloud secrets manager, derived an Ethereum wallet address using the Foundry toolkit’s cast utility, and deployed an implant named “spi” — referencing Brazil’s Central Bank Pix instant payment system — across a managed Kubernetes cluster reached via compromised Azure DevOps pipelines. SLIM SPIDER’s exposed C2 panel included “NEXUS // Scanner” (an Ollama-AI-powered endpoint classifier sorting targets into 16 categories including fintech and banking) and “Painel Pix” (a bulk unauthorized Pix transfer tool).
CASE STUDY — Cloud Resource Hijacking (January 8, 2026)
An eCrime actor at a U.S. technology company pursued three parallel vectors simultaneously (compute instances across multiple regions, a malicious Docker image mikifas474/web:server with 1M+ downloads, and Jupyter Notebook OnCreate lifecycle script abuse), establishing cross-account persistence via a backdoored admin identity and modified trust policies. The deployed XMRig cryptominer extracted 88.89 XMR (approximately $41,000 USD).
This section exposes a critical engineering blind spot that continues to devastate modern SaaS environments: the failure of single-alert monitoring signatures to intercept chained cloud API abuses. When analyzed in complete isolation, an instance metadata service query, a routine secrets manager access request, or an automated pipeline deployment modification look like completely benign, everyday engineering operations. However, when an adversary like SLIM SPIDER chains these exact actions together across a four-hour window to pivot from Azure DevOps straight into a live Kubernetes cluster, it represents a catastrophic infrastructure compromise. Cloud architects must replace primitive threshold-based alerts with cross-domain behavioral logging layers that can track multi-vector API interactions as a single, coordinated behavioral threat trail.
SECTION 7: OVERCAST PANDA — CLOSE ACCESS OPERATIONS
China-nexus OVERCAST PANDA uniquely relies on physical proximity rather than remote exploitation, deploying its proprietary FlowCloud backdoor (and, historically, LookBack) via direct physical device access during business travel to China, identified and disrupted by CrowdStrike OverWatch between March and May 2026.
Methodology: boots the target device from a bootable USB drive, bypassing the host OS entirely, installs FlowCloud, then allows normal restart — the victim resumes work unaware. One March 2026 case targeted a U.S. agricultural biotechnology company’s employees at a Hainan province conference, with compromises timed at 19:52 and 21:57 China Standard Time (dinner-hour windows). A mid-2026 intrusion against a U.S. media entity employee confirmed USB insertion immediately preceding compromise.
Target sectors: Agriculture, Energy, Hospitality, Legal, Logistics, Media, NGO/Nonprofit, Technology, Utilities. Victim nationalities documented: Japan, Taiwan, United States, United Kingdom. FlowCloud enables keylogging, screen capture, file collection, and credential harvesting, with C2 traffic routed through legitimate cloud infrastructure.
EXECUTIVE GRC MITIGATION RULES
| High-Risk Threat Metric | Verified 2026 CrowdStrike Threat Hunting Report Telemetry Hook | Mandatory Executive Control Policy |
| Vishing as a rapidly scaling identity attack vector | 134% YoY increase in vishing intrusions; account-takeover-to-exfiltration in under 5 minutes (SNARKY SPIDER) | Instruct staff to ignore unsolicited IT-support calls to personal devices; enforce phishing-resistant MFA (FIDO2); monitor for atypical MFA device enrollment (e.g., Genymobile, QEMU) |
| OAuth 2.0 device code / consent phishing | 15x increase in device code phishing attempts in 6 months; COZY BEAR compromise-to-full-access in under 4 hours | Restrict or monitor OAuth device code flow usage; alert on anomalous Entra ID application consent grants and session token issuance |
| Cloud-conscious eCrime escalation | 171% YoY increase in cloud-conscious eCrime activity; $41,000 cryptomining incident; multi-million-dollar Pix/crypto theft exposure | Deploy continuous behavioral hunting across the cloud control plane, not just credential-compromise alerting; audit cross-account trust policies and instance-termination-lock modifications |
| Zero-day and n-day weaponization speed | 42% YoY zero-day exploitation increase; 88% of public-PoC exploits weaponized within 48 hours; China-nexus actors exploiting within ~24 hours | Adopt continuous/emergency patching posture for internet-facing and PoC-published vulnerabilities; pair exposure management with managed threat hunting as a fail-safe |
| Software supply chain compromise via developer trust | npm = 87% of malicious registry packages; ALTERED SPIDER compromised 300+ dependencies in one day; 131 Mastra packages compromised via social engineering | Enforce code signing and dependency validation; scan repositories/packages continuously; treat CI/CD pipeline credentials as high-value, tightly scoped assets |
| AI infrastructure as both weapon and target | LLMJacking campaign sent ~200,000 API requests in 2 minutes; malicious MCP server config used for credential harvesting | Inventory all AI applications, model endpoints, API keys, and GPU resources; enforce least-privilege model/API access; monitor for abnormal LLM usage and cost spikes |
| Close-access physical device compromise during travel | OVERCAST PANDA’s FlowCloud deployed via bootable USB during China business travel, bypassing all network-based controls | Require full-disk encryption with pre-boot auth and BIOS/UEFI passwords; prohibit travel with devices containing proprietary IP; enable USB blocking via device control policies for high-risk travel regions |
CONCLUSION
The 2026 CrowdStrike Threat Hunting Report documents a threat landscape defined by cross-domain, trust-exploiting adversary behavior rather than sheer volume growth — overall intrusion activity plateaued at a 4% increase, down from 27% the prior year, even as sophistication and speed both intensified. Vishing-driven identity compromise, OAuth-based SaaS account takeover, cloud resource hijacking, and AI-targeted exploitation are no longer isolated techniques; adversaries increasingly chain them together across endpoint, identity, cloud, and developer-ecosystem boundaries in a single operation.
The report’s own conclusion is direct: “It is not enough to respond; defenders must anticipate, pivot, and relentlessly pursue the adversary.” Every case study in this briefing, from a four-minute vishing detection window to a 20-hour zero-day weaponization timeline, reinforces that continuous, intelligence-driven threat hunting — not static, perimeter-based defense — is what closes the gap between adversary speed and defender response.
Navigating an AI-accelerated and identity-heavy ecosystem requires shifting completely away from passive edge protection and committing to rapid, automated operational deadlines. To actively respond to the aggressive velocity windows documented in this year’s report, our leadership team has formalized three core containment action items with immediate enforcement deadlines: we are mandating the complete implementation of phishing-resistant, hardware-bound FIDO2 authentication keys across 100% of internal SaaS environments, enforcing automated session-token lifetime expirations capped at 60 minutes for high-privilege administrative accounts, and deploying continuous behavioral logging models across our cloud compute instances.
What specific identity vulnerabilities or cloud workload access exposures in this year’s report pose the highest strategic risk to your unique business continuity plans? Drop a comment below and share your infrastructure defense strategy—let’s share our threat intelligence playbooks and build safer perimeters together!
Related: Detecting Prompt Injection Trends in 4 Proven Structural Code Defense Layers – A practical guide to detecting prompt injection through four layered defenses that structurally filter, validate, and monitor malicious inputs before they reach an LLM.
Configuring WireGuard on Ubuntu in 5 Rigid Steps to Isolate Dev Environments – A five-step engineering tutorial on configuring WireGuard on Ubuntu to replace exposed SSH access with a kernel-level encrypted tunnel, covering key generation, server and firewall setup, and zero-trust client peer segmentation.
Analyzing the Stuxnet Exploit Using 5 Rigid Strategic Lessons to Defeat Threats – Stuxnet demonstrated how cyberattacks can cross the digital-physical boundary, turning vulnerabilities in isolated industrial systems into real-world destruction.
Blocking AI Resume Screeners Via 3 Proven Rules to Pass Job Screenings – Beat AI resume screening without gimmicks: optimize for clean ATS-friendly formatting, honest keyword alignment, and stronger privacy protection.
Frequently Asked Questions (FAQ)
Q1. What’s the actual difference between the CrowdStrike Threat Hunting Report and the CrowdStrike Global Threat Report, and which one should my organization be reading?
The Global Threat Report is CrowdStrike’s broader annual analysis of the overall adversary landscape, while the Threat Hunting Report focuses specifically on frontline observations from CrowdStrike OverWatch’s managed hunting operations, including detailed case studies and hands-on-keyboard intrusion detail. Most organizations benefit from reading both, since the Global Threat Report gives strategic breadth while the Threat Hunting Report gives operational depth into how specific intrusions actually unfolded.
Q2. If vishing and OAuth phishing bypass MFA entirely, is MFA still worth enforcing at all?
Yes, but the type of MFA matters significantly. Standard push-notification or SMS-based MFA is exactly what vishing and AiTM phishing techniques are designed to defeat by capturing session tokens after the fact, whereas phishing-resistant methods like FIDO2 hardware keys are specifically resistant to these token-theft techniques since they’re bound to the legitimate origin domain.
Q3. Does the OVERCAST PANDA close-access threat only apply to executives, or should regular employees traveling to China also be concerned?
The report doesn’t limit targeting to executives specifically; it describes deliberate selection based on access to information aligned with Chinese state intelligence priorities, which can include researchers, technical specialists, and media professionals at any seniority level. Any employee traveling with proprietary research, strategic business data, or sensitive credentials on their device should be considered at elevated risk, not just C-suite personnel.
Q4. Why did overall intrusion volume plateau at 4% growth this year after 27% growth the year before; does that mean the threat is actually decreasing?
No, the report explicitly frames this plateau as a sign of adversary maturity, not reduced risk, since attackers are shifting from high-volume opportunistic attacks toward fewer but more sophisticated, resource-intensive campaigns exploiting trust relationships. A slower growth rate in raw intrusion count can still coincide with rising severity and speed, which several case studies (four-minute vishing detection, sub-24-hour zero-day weaponization) demonstrate clearly.
Q5. Is npm inherently less secure than other package registries, given it accounts for 87% of malicious packages?
Not necessarily less secure by design; the report attributes npm’s dominance in malicious package activity to its scale and structural norms, deep dependency trees, automatic install-time script execution, and the sheer popularity of JavaScript for full-stack development, which combine to make it an attractive high-leverage target rather than indicating npm itself is uniquely flawed compared to PyPI or other registries. Organizations using any package registry with similar characteristics (auto-run scripts, deep dependency chains) face comparable structural risk.
DISCLAIMER
Educational Notice: This article is published on AI Security Watch strictly for technical educational and general cybersecurity awareness purposes. The configurations and research discussed are based on public threat intelligence data. This content does not constitute professional IT architecture, legal, or financial advice. Because network configurations vary, always verify settings in an isolated test environment or consult with a qualified engineer before modifying live hardware or registries. AI Security Watch contains informational links to external resources; we are not responsible for third-party site accuracy or platform content.
