Threat actors increasingly abused legitimate AI tools and automation to accelerate intrusions, with CrowdStrike reporting an 89% YoY increase in AI-enabled adversary activity and an average eCrime breakout time dropping to 29 minutes (fastest observed 27 seconds). CrowdStrike also described attackers poisoning or hijacking local AI tooling via malicious JavaScript embedded in npm packages targeting tools such as Claude and Gemini to steal credentials and crypto assets, and highlighted a CHATTY SPIDER intrusion that began with voice phishing and remote access via Microsoft Quick Assist, followed by attempted exfiltration using WinSCP and a fallback to Google Drive when blocked.
Separate reporting detailed additional active campaigns and exploitation trends consistent with faster initial access and persistence: UAC-0050 (DaVinci Group / “Mercenary Akula”) used spear-phishing with spoofed Ukrainian judicial themes and multi-layer archives (ZIP→RAR→passworded 7z) to deliver an *.pdf.exe dropper that installed Remote Manipulator System (RMS) for remote control and file transfer against a European financial institution. UnsolicitedBooker shifted targeting to telecoms in Kyrgyzstan and Tajikistan, using phishing documents that prompt “Enable Content” to run macros that drop loaders (e.g., LuciLoad, MarsSnakeLoader) and deploy LuciDoor and MarsSnake backdoors. Vulnerability intelligence for January 2026 also warned of active exploitation including APT28 use of a Microsoft Office zero-day (CVE-2026-21509) via weaponized RTFs to deliver implants (e.g., Covenant), alongside multiple critical authentication-bypass and RCE issues affecting enterprise platforms—reinforcing that adversaries are combining rapid social engineering, supply-chain style delivery, and exploited vulnerabilities to compress dwell time and speed lateral movement.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
BlueVoyant observed the Russia-aligned UAC-0050 cluster targeting an unnamed European financial institution involved in regional development and reconstruction. The campaign used a spoofed Ukrainian judicial domain and a multi-stage archive chain hosted on PixelDrain to install Remote Manipulator System (RMS) on a senior legal and policy advisor's system.
Positive Technologies reported that the China-aligned cluster UnsolicitedBooker moved from targeting Saudi Arabian entities to telecommunications organizations in Kyrgyzstan and Tajikistan, using phishing-led intrusion chains. The activity involved malicious Office documents with macros and LNK-based execution chains to deploy the LuciDoor and MarsSnake backdoors.
Recorded Future reported that all 23 high-impact vulnerabilities it highlighted for January 2026 were actively exploited during the month. The activity included exploitation of flaws affecting Microsoft, SmarterMail, Ivanti Endpoint Manager Mobile, and the WordPress Modular DS plugin, with public proof-of-concept code available for 14 of them.
During January 2026, APT28 conducted "Operation Neusploit," exploiting the Microsoft Office zero-day CVE-2026-21509 via weaponized RTF files. The campaign deployed tooling including MiniDoor, PixyNetLoader, and a Covenant Grunt implant for collection and backdoor access.
CrowdStrike's 2026 Global Threat Report said AI-enabled attacks rose 89% year over year in 2025, with adversaries using automation, machine-generated scripts, and legitimate AI tools to accelerate compromise. The report also noted rapid breakout and exfiltration behavior, including average eCrime lateral movement in 29 minutes and one case beginning exfiltration within four minutes of initial access.
In August 2025, attackers used malicious JavaScript in npm packages to hijack local AI tools such as Claude and Gemini to steal credentials and cryptocurrency. CrowdStrike said the incident affected more than 90 customers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcethehackernews.com
Open sourcerecordedfuture.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.