A new era of cyber threats has emerged. Today’s “enterprising adversaries” operate with calculated, business-like efficiency – bypassing traditional perimeters by exploiting human vulnerabilities, unmanaged endpoints, and cloud environments.
The CrowdStrike 2025 Threat Hunting Report delivers critical insights into evolving adversary tradecraft, cross-domain attack trajectories, and the weaponization of Generative AI.
Key Findings & Intel Inside the Report:
-
Hands-on-Keyboard Growth: Interactive intrusions grew 27% year-over-year, with 81% of intrusions leveraging malware-free techniques to evade legacy defenses.
-
Massive Cloud Surge: Cloud intrusions skyrocketed 136% in the first half of 2025 compared to all of 2024, with China-nexus actors driving a 40% increase.
-
GenAI Weaponization: How adversaries like DPRK-nexus FAMOUS CHOLLIMA use GenAI and real-time deepfakes to execute deceptive insider threat schemes.
-
Vishing & Social Engineering: Voice phishing attacks exploded, while actors like SCATTERED SPIDER accelerated account takeover to ransomware deployment in just 24 hours.
-
Real-World Case Studies: In-depth breakdowns of cross-domain hunts disrupting BLOCKADE SPIDER, OPERATOR PANDA, GLACIAL PANDA, and zero-day exploit campaigns.
Disrupt Threats Before They Escalate with Brilyant
Defending against stealthy, multi-domain attacks requires uniting telemetry across endpoints, identity, and cloud. Brilyant, in partnership with CrowdStrike, equips enterprise security teams with AI-powered threat hunting, Falcon Next-Gen SIEM, and real-time adversary intelligence to stop breaches before impact.
Download the 2025 Threat Hunting Report today!











