CrowdStrike's 2025 Global Threat Report: China's Cyber Espionage Surges Amid Rising AI-Driven Threats

6 Sources

Share

CrowdStrike's latest report reveals a 150% increase in China-linked cyberattacks and a significant rise in AI-powered threats, highlighting evolving cybersecurity challenges for 2025.

News article

China's Cyber Espionage Escalates Dramatically

CrowdStrike's 2025 Global Threat Report has revealed a startling 150% surge in cyberattacks attributed to China-nexus adversaries compared to the previous year

1

2

3

. This significant increase has particularly impacted critical sectors, with financial services, media, manufacturing, and industrial sectors experiencing a staggering 200% to 300% spike in targeted attacks

1

3

.

Adam Meyers, head of counter adversary operations at CrowdStrike, emphasized the gravity of the situation, stating, "China is, I think, the story that everybody needs to be focused on right now"

1

. The report identified seven new China-nexus adversaries in 2024, indicating an expansion of China's cyber capabilities

2

3

.

AI-Powered Threats on the Rise

The report highlights a dramatic increase in AI-driven cyber threats, particularly in social engineering attacks. Voice phishing (vishing) attacks saw a 442% increase in the second half of 2024 compared to the first half

1

2

3

. This surge is attributed to the growing use of generative AI in creating more convincing and sophisticated phishing attempts

4

.

Iran-based threat groups have been particularly aggressive in utilizing AI for vulnerability research and exploit development, aligning with government-led AI initiatives

2

3

. The adoption of AI has significantly lowered the barrier to entry for conducting effective cyberattacks

1

4

.

Shift to Malware-Free and Identity-Based Attacks

A notable trend in 2024 was the shift towards malware-free attacks, with 79% of detected intrusions not involving malware

1

2

3

5

. This shift makes attacks harder to detect as they often appear as legitimate user activities. Concurrently, there was a 50% year-over-year increase in access broker advertisements, facilitating the sale of compromised credentials

2

3

5

.

Cloud Environments Under Increased Threat

The report indicates a 26% year-over-year increase in new and unattributed cloud intrusions

1

2

3

. Valid account abuse emerged as the primary initial access tactic, accounting for 35% of cloud incidents in the first half of 2024

2

3

. This trend underscores the growing vulnerability of cloud environments to sophisticated cyber threats.

Record-Breaking Attack Speeds

CrowdStrike reported a significant decrease in the average "breakout time" – the time it takes for an attacker to move laterally within a compromised network. The average eCrime breakout time dropped to just 48 minutes, with the fastest recorded at a mere 51 seconds

2

3

5

. This rapid progression leaves defenders with very little time to react and contain threats.

Recommendations for Enhanced Cybersecurity

In light of these evolving threats, CrowdStrike recommends several key strategies:

  1. Strengthen identity security through phishing-resistant multi-factor authentication and continuous monitoring of privileged accounts

    5

    .
  2. Implement real-time AI-driven threat detection for rapid response to fast-moving attacks

    5

    .
  3. Fortify cloud security by enforcing least privilege access and monitoring API keys for unauthorized usage

    5

    .
  4. Adopt advanced behavioral analytics and cross-domain visibility solutions to detect stealthy intrusions

    5

    .

As Adam Meyers concludes, "Stopping breaches requires a unified platform powered by real-time intelligence and threat hunting, correlating identity, cloud and endpoint activity to eliminate the blind spots where adversaries hide"

3

. The report serves as a crucial wake-up call for organizations to reassess and strengthen their cybersecurity measures in the face of increasingly sophisticated and AI-driven threats.

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo