Threat Actors Weaponized AI Tools to Gain Full Domain Access within 30 Minutes
In 2025, artificial intelligence tools were repurposed by threat actors for executing swift and precise network intrusions. The 2026 Global Threat Report by CrowdStrike recorded an 89% rise in attacks by AI-enabled adversaries. Automation and…
In 2025, artificial intelligence tools were repurposed by threat actors for executing swift and precise network intrusions. The 2026 Global Threat Report by CrowdStrike recorded an 89% rise in attacks by AI-enabled adversaries. Automation and machine-generated scripts reduced the time between initial entry and full domain access to under 30 minutes.
The prominence of intrusion speed characterized the threat landscape in 2025. The average eCrime breakout time, the interval between gaining initial access and moving laterally to other systems, decreased to 29 minutes, marking a 65% speed increase over 2024. The fastest recorded breakout occurred in 27 seconds, with data exfiltration commencing within four minutes of first access in some instances, allowing minimal time for organizations to respond.
According to CrowdStrike analysts , this acceleration is closely linked to AI exploitation. Adversaries employed custom malware and malicious prompts within legitimate AI tools operational in victim environments.
In August 2025, attackers embedded malicious JavaScript in Node Package Manager (npm) packages, compromising local AI tools such as Claude and Gemini to exfiltrate authentication credentials and cryptocurrency assets. CrowdStrike Services and OverWatch addressed over 90 affected customer cases.
In 2025, artificial intelligence tools were repurposed by threat actors for executing swift and precise network intrusions.
One notable incident involved CHATTY SPIDER, an eCrime adversary that targeted a U.S. law firm through voice phishing. The group persuaded an employee to grant remote access via Microsoft Quick Assist and attempted to transmit stolen files to attacker-controlled infrastructure using WinSCP within four minutes. Although the firewall blocked the attempt, the attacker switched to Google Drive, but CrowdStrike OverWatch halted the exfiltration before any data leakage.
Beyond individual operations, threat actors like FAMOUS CHOLLIMA constructed AI-assisted attack pipelines spanning multiple phases. They utilized tools such as ChatGPT, Gemini, GitHub Copilot, and VSCodium to craft fake personas, manage multiple accounts, and execute technical job tasks under fraudulent identities. Their activities doubled in 2025 compared to 2024, demonstrating how AI decreased the effort required for large-scale deceptive operations.
How Threat Actors Weaponize AI Across the Kill Chain
PUNK SPIDER, the most active ransomware adversary in 2025 with 198 documented intrusions, used Gemini-generated scripts to extract credentials from Veeam Backup & Replication databases and likely employed DeepSeek-generated scripts to terminate services and erase forensic evidence.
Russia-nexus actor FANCY BEAR deployed LAMEHUG malware, which queried the Hugging Face LLM Qwen2.5-Coder-32B-Instruct via hardcoded prompts, performing reconnaissance and document collection before exfiltration. This approach replaced rigid coding with AI-generated outputs, circumventing static security tools. Notably, 82% of 2025 detections were malware-free, indicating that most attacks leveraged authorized pathways rather than traditional malicious software.
Organizations are advised to monitor AI tool usage on endpoints, promptly patch AI platforms , audit npm dependencies, and maintain cross-domain visibility across identity, cloud, and SaaS environments to detect rapid intrusions before breakout.
Based on reporting by Cyber Security News.
