Chinese cyberespionage soars 150% as AI powers social engineering attacks

 

The report CrowdStrike Global Threat Report 2025 paints a grim but crucial picture of the current and future state of cybersecurity. This report highlights alarming trends that organizations must take into account to protect their digital assets.

 

Chinese cyberespionage becomes more aggressive

 

One of the most worrying findings is the 150% increase in Chinese state-sponsored digital espionage operations. Attacks targeting critical sectors such as finance, media, manufacturing and industries have seen an increase of up to 300%. This increase underscores the need for heightened vigilance and reinforced security measures to protect the Confidential information and intellectual propertyIn 2024, CrowdStrike identified seven new threat actors linked to China, demonstrating the expansion and diversification of China's cyber capabilities.

 

Generative AI as a double-edged sword

 

The report also highlights the increasing use of generative artificial intelligence (AI) by cybercriminals. Phishing tactics and social engineering powered by generative AI have led to a 442% increase in vishing (voice phishing) attacks in the second half of 2024. Sophisticated groups such as Curly Spider, Chatty Spider and Plump Spider are using social engineering to steal credentials, establish remote sessions, and evade detection. This demonstrates how generative AI is democratising attack capabilities, allowing cybercriminals to create more convincing and harder-to-detect attacks.

 

Furthermore, Iran-linked groups have been observed using generative AI to find and exploit vulnerabilities, as well as patch domestic networks, in line with government-led AI initiatives. This underscores the need for organizations to stay abreast of the latest trends in AI and adapt their security strategies accordingly.

 

Malware-free attacks and identity theft

 

Report reveals that 79% of initial access attacks do not use malware, indicating a shift towards stealthier and harder-to-detect techniques. Cybercriminals are exploiting stolen credentials to infiltrate systems as legitimate users, moving laterally undetected with manual activities. Additionally, advertisements for selling compromised logins have increased by 50% compared to last year, making it even easier to carry out malware-free attacks.

 

North Korean-linked actor Famous Chollima is an example of how insider threats continue to rise. This group was responsible for 304 incidents discovered in 2024, and 40% of these incidents involved insider threats, with criminals infiltrating organizations under the guise of legitimate employees.

 

Record propagation times and attacks in the cloud

 

The average time for cybercriminals to spread an attack after a breach has dropped to 48 minutes, with the fastest recorded instance taking 51 seconds. This leaves security officers with very little time to react and stop attacks.

 

Additionally, cloud attacks have increased by 26% compared to last year. Abuse of valid accounts accounted for 35% of cloud incidents in the first half of 2024, highlighting the need to strengthen security in cloud environments.

 

Vulnerabilities as an entry point

 

52% of observed vulnerabilities are related to initial access, reinforcing the critical need to secure entry points before attackers establish persistence. Organizations must prioritize vulnerability management and patching to reduce the risk of attacks.

 

CrowdStrike Recommendations

In the face of this evolving threat landscape, CrowdStrike recommends that organizations take a proactive, adversary-focused approach to security. This involves:

 

  • Implement a unified platform: A platform that integrates real-time intelligence and threat detection capabilities across identities, clouds, and endpoints is essential to eliminating blind spots and detecting malicious activity.
  • Leveraging Threat Intelligence: Real-time threat intelligence enables organizations to better understand adversaries' tactics, techniques, and procedures (TTPs) and anticipate their moves.
  • Conduct proactive threat huntingProactive threat hunting enables organizations to detect and neutralize attacks before they cause significant damage.
  • Strengthening identity security: Credential protection and access control are critical to preventing non-malware attacks and identity theft.
  • Improving cloud securityOrganizations must implement robust security measures to protect their cloud environments, including account management and access control.
  • Prioritize vulnerability management: Timely patching and vulnerability correction are essential to reduce the risk of attacks.
  • Awareness and training: Employees should be educated to recognize and avoid social engineering attacks.

 

CrowdStrike's Global Threat Report 2025 offers valuable insights into the current cybersecurity landscape and emerging trends. Organizations that take these warnings seriously and adopt a proactive security approach will be better positioned to protect their digital assets and mitigate the risk of cyberattacks. cyber attacks.

 

 

 

Coexia®

AI in the foreign trade

Hi! I'm Coexia. How can I help you today with your internationalization strategy?
Coexia IA