CrowdStrike and external reporting warn that attackers are increasingly abusing legitimate enterprise AI tools, chatbots, and autonomous agents to conduct stealthy intrusions in a shift described as "living off the AI land." Findings cited from CrowdStrike’s threat reporting say more than 90 organizations experienced misuse of legitimate AI tools to generate malicious commands, exfiltrate sensitive data, steal credentials, and support financially motivated crime including cryptocurrency theft. The reporting also says ChatGPT was referenced on criminal forums far more often than rival models, with mentions reportedly 550% higher than competitors, underscoring growing attacker interest in AI-enabled tradecraft.
Security leaders are being warned that compromised AI agents may pose greater risk than traditional living-off-the-land tools such as PowerShell because they can inherit broad privileges and operate across multiple enterprise systems. CrowdStrike Field CTO Zeki Turedi said many organizations lack the governance, identity controls, and telemetry needed to distinguish AI-agent activity from human behavior, creating blind spots for detection and response. Survey data cited from the Cloud Security Alliance found 68% of respondents could not accurately identify agent activity versus human activity, highlighting a widening visibility gap as AI becomes both an attack amplifier and a new attack surface.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
CrowdStrike's 2026 Global Threat Report stated that more than 90 organizations experienced abuse of legitimate AI tools to generate malicious commands and exfiltrate sensitive data. The report also said ChatGPT was referenced on criminal forums far more often than other AI models, with mentions 550% higher than any competing model.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourcecrowdstrike.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.