Book demo
27 August 2026

Nation-state hackers are really vibing now!

We’ve all heard that hackers are using AI. That’s not news anymore. But when the latest research from Trend Micro landed in our inbox we took notice – because the report gives us the clearest picture yet of exactly how they are using it.

From vibe-coded attacks, to fully agentic reconnaissance, it’s clear that bad actors are really getting into the grove with AI. The insights are fascinating and worrying in equal measures.

The research

The APT Activity Roundup is published twice a year by Trend AI, the threat intelligence arm of Trend Micro. The latest report is based on intelligence from January to June this year. It’s not a prediction piece or a marketing trend report. Its insights are built on six months of tracked, real-world incidents pulled from Trend Micro’s global detection footprint.

While the report focuses specifically on organisations associated with nation-state backed cybercrime, the findings have implications for every business that depends on data.

Why it matters

It’s easy to be dismissive of stories about nation-state cyber attacks. It sounds like a government problem, or a defence one. The reality is that nation-state backed cybercrime isn’t all about espionage and intelligence.

Financial services, critical infrastructure, major technology vendors and the software supply chain are common targets, not collateral damage. A bank gets hit because it directly funds a sanctioned regime. A major software company gets exploited because it’s the fastest route to mass disruption. Any business can be a target for a ransomware attack to fund a foreign power.

No organisation is truly safe from nation-state hackers.

The second reason to take notice is that well-funded, state-backed bad actors are the pioneers for the cybercrime industry. Evidence shows that the innovative methods being used here will become common tactics used by hackers more broadly in 12-24 months.

Key findings

1. An AI agent ran its own attack, unsupervised.

In one documented case, an AI agent was set a goal before carrying out extensive reconnaissance and lateral movement inside a target’s network without further human direction. That’s a meaningful shift from AI as a tool an attacker uses, to AI as the thing actively running the intrusion, capable of progressing an attack even when nobody’s watching.

2. Nation-state hackers are vibe coding their exploits.
China-aligned groups built and refined exploit code by prompting an AI conversationally, iterating until it worked, rather than writing it by hand. It’s the same workflow legitimate developers now use to ship products fast. The barrier to building a working exploit just dropped, and it no longer requires deep technical skill to clear it.

3. Attackers don’t even need malware to track you anymore.
ADINT exploits the real-time bidding auctions that power online ad delivery, harvesting the location and device data those auctions carry, for surveillance, without ever installing anything on a target’s device. No file, no payload, nothing for endpoint security to catch, because nothing was ever planted.

4. Attack infrastructure is hiding in plain sight.
Command-and-control is increasingly routed through infrastructure that users already trust and can’t easily block: mainstream cloud platforms, developer tunnelling services, even blockchain transactions. It blends into legitimate traffic by riding on the same rails as legitimate traffic.


–

Read the full report:
The TrendAI H1 2026 APT Activity Roundup is available to download for free from the Trend Micro website.

Read it here


Trend Micro and Predatar

Having spent more than three decades tracking nation-state activity, Trend Micro remains one of the most trusted and frequently cited sources in the industry for cyber intelligence. That’s why Predatar has chosen TrendMicro as it Threat Intelligence Partner.

Visit predatar.com to learn more about how Predatar’s unique Recovery Assurance technology is helping organisations around the world protect themselves from the impacts of increasingly sophisticated attacks and giving them confidence in their ability to execute a fast and effective recovery.

Learn more about
Predatar recovery assurance

06 August 2026

Recovery You Can Bank On – Why Financial Institutions Across Latin America are Turning to Predatar.

Banks and financial services organisations across Latin America are choosing Predatar to strengthen operational resilience, prove recoverability and respond to increasingly demanding regulations. Behind much of this momentum is Nicolas Perez de Arenaza — LATAM’s leading Recovery Assurance expert.

For banks and insurers, data is everything!

Every payment, balance, policy and customer interaction depends on data. If critical systems become unavailable, operations grind to a halt. That makes recovery more than an infrastructure concern. It is a board-level, regulatory and operational resilience priority.

It is also why some of the largest and longest-established financial institutions across Argentina, Colombia, Paraguay, and Mexico have chosen to invest in Predatar this year. These organisations are not implementing Recovery Assurance technology because it is fashionable. They need proof that they can recover when it matters.

Meet a Recovery Assurance trailblazer

Based in Buenos Aires, Founder & CEO at GIUX, Nicolas Perez de Arenaza has established himself as Latin America’s leading Recovery Assurance expert.

We first met Nicolas three years ago, when he flew more than 7,000 miles to join one of Predatar’s very first hands-on technical training workshops in the UK.

Nicolas built his Recovery Assurance Cleanroom, collected his certificate, and then jumped on a motorcycle to explore some of Scotland’s most spectacular landscapes. We knew immediately that we would get along.

That adventurous spirit has shaped Nicolas’s approach to building the Recovery Assurance market. He knew that the infrastructure and cyber security markets were shifting towards a focus on resilience, but he didn’t wait for customers to begin asking for Predatar. He travelled across Argentina, Colombia, Ecuador, Perú and Paraguay, and built relationships remotely in Mexico and beyond – sharing knowledge along the way.

“I spread the word about Predatar in many countries,” Nicolas explains. “GIUX acts as a beacon: we share knowledge, let people know that we can help them move forward with this approach, and show them how to find us when they need help or advice.”

It’s not just financial institutions that have benefited from Nicolas’ expertise. He’s actively speaking with IT, security, and operational resilience leaders across many industry sectors. He has also become the go-to Recovery Assurance expert for other technology businesses in the region – including resellers and service providers.

Nicolas is always keen to point out that his successes are always part of a team effort. In most cases Nicolas and the team at GIUX are providing consultancy and technical services to end customers, working hand-in-hand with the local IBM ecosystem of IBM reps and business partners on each country to provide an exceptional end-to-end customer experience.

Why financial services?

While almost any modern business will benefit from Recovery Assurance technology, the momentum that is building in financial institutions specifically is no coincidence.

The reality is that the financial services sector already has some of the most robust resilience and continuity capabilities in place. But they also carry the biggest risks.

Nicolas explains, “These are the organisations most dependent on the continuity of IT. Banks and insurers face enormous potential costs from downtime. They are also accountable to the board, their customers, the markets – and of course – regulators.”

Supporting regulatory compliance

Financial services regulations around the world are already among the most stringent of any sector, and many are now demanding that institutions must demonstrate their resilience rather than simply document it.

What this means in practice is that recovery plans must be tested comprehensively and regularly. Recovery guarantees and Service Level Agreements (SLAs) from IT vendors must actually be validated. Organisations must demonstrate they can actually meet the targets they set around impact tolerances and Recovery Time Objectives (RTOs).

This is where Predatar delivers real value. By putting AI and automation to work, Predatar continually checks that the data that runs its customers’ most important systems and services is always recoverable and clean – every single day. Putting Predatar to work gives you the certainty that whenever needed, you will be able to recover rapidly, completely and free of malware.

Not only does this provide peace of mind, Predatar provides the evidence of resilience that many regulators now expect.

Getting started with Recovery Assurance

Can your organisation recover the data, systems and digital services it relies on quickly, cleanly and completely? All too often businesses find themselves trying to answer these high-stakes questions for the first time in the middle of a crisis.

That’s why any organisation – whether it’s in the financial services sector or not – can benefit from continuous Recovery Assurance. Download our Recovery Assurance Buyer’s Guide to learn more about this emerging technology market, or find a ‘beacon of knowledge’ in your region by visiting Predatar’s APEX Partner finder.

Predatar works with leading enterprise storage and backup solutions and can even be used to validate recoverability across complex multi-vendor infrastructure environments – making it a perfect fit for many large organisations including banks and other financial services institutions.

Learn more about
Predatar recovery assurance