Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

securitybrief+1smbtech+1securitybrief+1Nation-state cyber groups aligned with China, Russia, North Korea and Iran have moved generative AI from the margins of their operations into the core of how they discover vulnerabilities, build malware and navigate compromised networks, according to a report released Tuesday by TrendAI, the enterprise cybersecurity unit of Trend Micro .
The company's H1 2026 APT Activity Roundup, covering activity observed between January and June, found that advanced persistent threat actors used AI in more stages of the intrusion lifecycle than in any prior half-year period the firm has tracked.securitybrief+2
Among the report's most striking findings, China-aligned threat actors used generative AI to iteratively refine malware through what TrendAI calls "vibe coding" — building and improving code through conversational prompting rather than traditional development methods. In at least one documented case, an AI agent independently conducted reconnaissance and lateral movement inside a target network without direct human instruction during those phases.smbtech+1
"Artificial intelligence has stopped being a side tool for attackers and has become a teammate embedded in the operation itself," Robert McArdle, Director of Cybercrime Research at TrendAI, said in the company's press release. "Defenders now have to assume the adversary on the other end of an intrusion may not be a person typing commands, but a system executing a plan."newsroom.trendmicro
Russia-aligned group Pawn Storm opened the year by exploiting an Office zero-day vulnerability and sustained pressure on Ukraine and organisations tied to government, defence and wartime aid throughout the period. North Korean actors folded commercial AI tools into their campaigns and poisoned a widely used software package in a supply-chain attack aimed at downstream developers.securitybrief+1
Iran-aligned group Earth Vetala scanned for a newly disclosed Ivanti vulnerability within days of its release. Other Iran-linked actors attacked internet-exposed operational technology, tampering with fuel-tank gauges at sites in the United States — a reminder that state-backed groups remain willing to interfere with systems that carry real-world safety implications.smbtech+1
The report also flags the growing use of trusted cloud platforms, developer tunnels, blockchains and paste sites to conceal command-and-control infrastructure, complicating network-level detection. A surveillance technique called ADINT, which harvests location and device data from online advertising auctions without deploying malware, adds another layer of concern.securitybrief+1
With the spread of malware-as-a-service and shared tooling blurring the lines between state-sponsored and criminal activity, the findings land as governments in Australia, New Zealand and elsewhere have issued repeated warnings about state-backed intrusion attempts targeting critical infrastructure. The compressed timeline between vulnerability disclosure and exploitation means organisations relying on standard patching cycles face exposure before fixes can be applied.securitybrief+1