TechForge

August 6, 2025

  • Hackers now use AI to speed up and automate attacks.
  • Over 80% of intrusions are malware-free, CrowdStrike finds.

Cybercriminals are becoming more organised and efficient, increasingly running their operations more like businesses. According to CrowdStrike’s 2025 Threat Hunting Report, “enterprising adversaries” use well-planned, scalable tactics to hit their targets quickly and effectively.

Basic security tools are no longer enough to stop them. Many attackers look for gaps that traditional systems miss – often focusing on devices outside of IT’s control or tricking people through increasingly convincing social engineering. AI is making such tactics more effective.

One example from the report involves a North Korea-linked group that poses as remote software developers. It uses generative AI to craft fake résumés, apply deepfake tech during interviews, and complete technical tasks while remaining undercover – giving them access to sensitive systems and data.

The report highlights that defenders need more than static defences, facilities that CrowdStrike happens to sell. Active threat hunting and real-time intelligence are now ‘critical’, the company says, in spotting early signs of an intrusion – especially in areas like cloud infrastructure, identity systems, and unmanaged endpoints, where attackers often operate unnoticed.

The adversaries use different strategies depending on their goals, where some act quickly, moving from initial access to ransomware in just hours. Others stay quiet for months, collecting information or preparing for larger attacks. For instance, a China-linked group has targeted telecom networks by establishing long-term access and conducting stealthy reconnaissance while blending in with normal network activity.

Cloud environments are increasingly under pressure. In the first half of 2025 alone, cloud intrusions rose by 136% compared to all of 2024, with many cases tied to state-linked actors. The groups have become skilled at navigating cloud systems, prompting defenders to shift their detection strategies in cloud services, accounts, and management tools.

Another fast-growing threat is voice phishing, or “vishing.” The attacks use phone calls to trick support staff into giving up access. One group named in the report returned in 2025 with help desk scams that enabled them to deploy ransomware more quickly – cutting their timeline by nearly a third compared to the previous year.

Initial access remains a major focus, and CrowdStrike found that over half of all vulnerabilities observed in 2024 were tied to entry points into systems, including exposed applications. Even in cases where attackers use zero-day exploits, threat hunters can still disrupt operations by watching for suspicious post-access behaviour.

From July 2024 through June 2025, CrowdStrike threat hunters observed:

  • 81% of hands-on intrusions didn’t use malware.
  • The intrusions increased 27% from the prior year.
  • 73% were tied to financially motivated groups.
  • Cloud breaches more than doubled in the first half of 2025.
  • Suspected China-linked intrusions into cloud systems rose 40%.
  • Vishing attacks in 2025 has already exceeded 2024’s total.
  • Government agencies experienced a 71% rise in interactive intrusions and a 185% jump in targeted attacks.
  • Over 320 companies were infiltrated by insiders linked to North Korea – a 220% increase in a year.
  • Some adversaries went from account takeover to ransomware in under 24 hours.

The report also found that tech companies continue to be the most frequent targets – a trend that’s now held for eight straight years. Their central role in supplying hardware, software, and services in industries makes them valuable targets. Government and telecom sectors also saw a rise in intrusions, driven mostly by nation-state groups.

Generative AI is playing a growing role in all types of attacks. State-linked groups – including those associated with Iran and North Korea – use public AI tools to boost reconnaissance and create payloads, among other activities.

Want to learn more about cybersecurity and the cloud from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London. The comprehensive event is co-located with other leading events including Digital Transformation Week, IoT Tech Expo, Blockchain Expo, and AI & Big Data Expo.

Explore other upcoming enterprise technology events and webinars powered by TechForge here.

Author

  • As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

    View all posts

About the Author

Muhammad Zulhusni

As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

Related

August 11, 2026

August 10, 2026

August 5, 2026

July 30, 2026

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Popular

12345 view(s)
11326 view(s)
7643 view(s)
6152 view(s)

Subscribe

All our premium content and latest tech news delivered straight to your inbox

This field is for validation purposes and should be left unchanged.
Name(Required)