Report by CrowdStrike
CrowdStrike 2026 Threat Hunting Report
Key Findings
Vishing intrusions increased by 2x in 1H 2026.
SNARKY SPIDER moved from account takeover to data theft in under five minutes in one incident.
China-nexus adversaries exploited critical vulnerabilities within 24 hours of public proof-of-concept release.
DPRK-nexus adversaries injected malicious packages into AI frameworks, poisoning 131 trusted AI framework packages.
One campaign sent nearly 200,000 AI model requests in two minutes.
AI agent-triggered detection leads grew at 2.5x the rate of human-triggered leads.
In 1H 2026, 87% of identified software registry threats involved malicious npm packages.
eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day to harvest credentials and pivot into cloud environments.
Monthly device code phishing attempts increased 15x in 1H 2026.
Cloud-conscious eCrime activity surged 171% as adversaries executed credential theft, cryptomining, LLM abuse, and digital financial asset theft.
In 1H 2026, 88% of observed exploitation of vulnerabilities with a public PoC occured within 48 hours of release.
China-nexus actors VAULT PANDA and GENESIS PANDA launched deliberate attacks within 24 hours of disclosure.