CrowdStrike 2026 
Threat Hunting Report

2.5x
The rate of AI agent-triggered detection leads compared with human-triggered leads
24hours
China-nexus adversaries exploit vulnerabilities after effective PoC disclosure
300+
Software dependencies compromised in a single day by ALTERED SPIDER

Learn how adversaries weaponize trust across domains

  • AI systems have become high-value attack targets
  • Vulnerabilities are being exploited hours after disclosure
  • Identity abuse turns trusted logins into cloud access
AI is a tool, target, and force multiplier for adversaries
2.5x
The rate of AI agent-triggered detection leads compared with human-triggered leads

Threat actors use AI to generate payloads and shell commands, exploit AI infrastructure, and abuse enterprise LLMs

 

200K API requests sent in two minutes during an LLMJacking campaign, exploiting the victim’s AI resources at scale

 

The same AI tools driving modern businesses are creating underdefended attack surfaces that adversaries are already exploiting

The race against time: Exploitation windows collapse

Frontier AI is collapsing exploit windows, enabling adversaries to find vulnerabilities, generate exploits, and map attack paths at speed and scale.

STARDUST CHOLLIMA

24 hours

China-nexus adversaries exploit vulnerabilities after effective PoC disclosure

80+

victims identified in just four days after React2Shell vulnerability disclosure

Supply chain attacks move
upstream

Adversaries are moving deeper into the developer ecosystem, turning one trusted component into a launchpad for downstream and cross-domain compromise.

OPERATOR PANDA

300+

software dependencies compromised in a single day by ALTERED SPIDER

131

AI framework packages poisoned by STARDUST CHOLLIMA

Trusted logins become cloud attack paths

Adversaries are abusing legitimate authentication flows to turn one compromised identity into rapid SaaS and cloud access, often without malware, lateral movement, or privilege escalation.

171%

surge in eCrime cloud-conscious activity

15x

spike in monthly device code phishing attempts

background
Adam Meyers

Adam Meyers

Sr. VP of Counter Adversary Operations, CrowdStrike

Cristian Rodriguez

Cristian Rodriguez

CTO of Americas, CrowdStrike

Virtual Threat Briefing

Weaponized Trust: Inside the CrowdStrike 2026 Threat Hunting Report

CrowdStrike experts uncover the latest frontline intelligence. Learn how adversaries weaponize trust to build connected, cross-domain attack paths and blend into normal activity.

Know them. Find them.
Stop them.


Explore the Adversary Hub to learn how the world’s most dangerous threat actors are targeting organizations like yours.

Don’t let exploited trust turn into a breach

Download report

FAQs

The report is powered by real-world insights from the CrowdStrike OverWatch team. Our expert threat hunters track the world’s most advanced cyber adversaries 24/7. The CrowdStrike 2026 Threat Hunting Report reflects their front-line findings from active investigations conducted between July 1, 2025, and June 30, 2026.

Small and Medium-Sized Businesses (SMBs):
SMBs often lack the resources to build comprehensive in-house security operations. Threat intelligence helps them achieve a level of protection they otherwise couldn't afford, offering insights that allow them to prioritize defenses and mitigate risk.

Enterprises:
For larger organizations with dedicated security teams, threat intelligence reduces costs, minimizes the required skill set for incident handling, and enhances the effectiveness of security analysts by integrating external data into their operations.

While others retrofit AI features onto legacy architectures, the unified and agentic CrowdStrike Falcon® platform combines front-line adversary intelligence; cross-domain visibility across endpoint, identity, and cloud; machine-speed detection and response; and integrated exposure management. These capabilities close the speed gap between modern, AI-accelerated and the organizations defending against them.

Visit CrowdStrike’s Adversary Hub to keep up with the latest adversary activity and find more content from the Counter Adversary Operations team. 

Methodology & Source: All information provided is based on the CrowdStrike Counter Adversary Operations team’s proprietary threat intelligence gathered between July 1, 2025, and June 30, 2026. Stats may include data from the entire period surveyed or excerpts of data from specific date ranges within the period.