For years, the question about AI and offensive security was speculative: what happens when attackers get good at this? In 2025, the speculation ended. According to the CrowdStrike 2026 Global Threat Report, attacks by AI-enabled adversaries rose 89% year-over-year. AI did not invent a new class of attack so much as it compressed the time between intent and execution — and that compression is the story.
AI as an accelerant, not an invention
The most important framing in CrowdStrike's data is also the most easily missed. AI's current impact primarily enhances established tactics, techniques, and procedures rather than creating novel attack vectors. Adversaries used it to accelerate, optimize, and troubleshoot the things they were already doing: phishing, reconnaissance, social engineering, and influence operations.
What changes when you accelerate an existing playbook? The economics. AI elevated less sophisticated threat actors who previously lacked the technical skill to execute certain attacks, and it amplified the most advanced ones who could now operate at a tempo previously out of reach. The middle of the market — moderately resourced actors — likely benefits the most.
The kill chain, measured
CrowdStrike mapped AI-enabled activity across the kill chain and compared 2024 to 2025 incident volumes. The increases are not uniform, and the distribution is itself informative. The heaviest growth, per CrowdStrike Intelligence, clusters around the phases where speed and volume matter most:
PUNK SPIDER's 134% increase in AI-generated scripts during attacks is the clearest signal: the adversary is using AI not to think of new things to do, but to generate the operational tooling to do known things faster. (RENAISSANCE SPIDER's GenAI-translated ClickFix lures rose a more modest 16% over the same period, per CrowdStrike.)
The DPRK case: AI as an employment engine
The single most instructive example is FAMOUS CHOLLIMA, the DPRK-nexus cluster behind fraudulent IT-worker schemes. Its 2025 activity doubled compared to 2024. The adversary integrated multiple AI tools — image manipulation to create fake personas, messaging services to manage multiple accounts simultaneously, and AI coding assistants to perform the legitimate job functions of the roles its operators had fraudulently obtained.
Read that last part again. The AI is not breaking into anything. It is helping a fraudulent employee do their job convincingly enough to keep it — and to evade the detection that would otherwise expose the scheme. This is social engineering at organizational scale, and AI is what makes it sustainable.
Translation, credibility, and the social-engineering edge
RENAISSANCE SPIDER used GenAI to translate ClickFix lures into Ukrainian, increasing their credibility and enticing victims to download JavaScript downloaders delivering NetSupport RAT and RMS payloads. Chinese intelligence services have used AI to create credible-looking consulting firms to target former U.S. government employees on job-recruitment platforms.
The common thread is credibility. The hard part of social engineering has always been sounding native, sounding legitimate, sounding like someone the target should trust. AI collapses that barrier — across languages, across personas, across the volume of simultaneous conversations a single operator can sustain.
What defenders should take from this
The 89% figure is not an argument for panic. It is an argument for cadence. If the techniques are familiar but the speed has changed, the defensive gap is no longer knowledge — it is validation frequency. Knowing that AiTM phishing exists does not help if your last test of email defenses was two quarters ago and the adversary now iterates lures in hours.
Continuous adversarial validation exists for exactly this gap: testing known techniques, repeatedly, at the speed adversaries now operate, so that the window between a defense degrading and a defender noticing closes from quarters to days.
See what continuous testing finds in your environment.
Tadpole deploys autonomous agents that simulate real adversaries — 24/7, across your entire attack surface.
Request early access →