CrowdStrike 2025 Threat Hunting Report: AI Becomes a Weapon and a Target
2025-08-04 • Crowd Strike •
https://www.crowdstrike.com/en-us/blog/crowdstrike-2025-threat-hunting-report-ai-weapon-target/
CrowdStrike reports that DPRK-nexus FAMOUS CHOLLIMA infiltrated more than 320 companies over the past 12 months, a 220% year-over-year increase. The activity centers on North Korean IT workers using generative AI throughout hiring and employment, including polished resumes, possible real-time deepfakes in interviews, and AI coding tools once hired. The broader report notes adversaries using AI for unauthenticated access, persistence, credential theft, malware deployment, phishing lures, and exploitation of AI software, expanding the enterprise attack surface. For DPRK monitoring, the key finding is that AI-enabled identity deception is scaling North Korea's remote-work infiltration model and making hiring, identity, and insider-risk controls more important.