Book demo
27 August 2026

Nation-state hackers are really vibing now!

We’ve all heard that hackers are using AI. That’s not news anymore. But when the latest research from Trend Micro landed in our inbox we took notice – because the report gives us the clearest picture yet of exactly how they are using it.

From vibe-coded attacks, to fully agentic reconnaissance, it’s clear that bad actors are really getting into the grove with AI. The insights are fascinating and worrying in equal measures.

The research

The APT Activity Roundup is published twice a year by Trend AI, the threat intelligence arm of Trend Micro. The latest report is based on intelligence from January to June this year. It’s not a prediction piece or a marketing trend report. Its insights are built on six months of tracked, real-world incidents pulled from Trend Micro’s global detection footprint.

While the report focuses specifically on organisations associated with nation-state backed cybercrime, the findings have implications for every business that depends on data.

Why it matters

It’s easy to be dismissive of stories about nation-state cyber attacks. It sounds like a government problem, or a defence one. The reality is that nation-state backed cybercrime isn’t all about espionage and intelligence.

Financial services, critical infrastructure, major technology vendors and the software supply chain are common targets, not collateral damage. A bank gets hit because it directly funds a sanctioned regime. A major software company gets exploited because it’s the fastest route to mass disruption. Any business can be a target for a ransomware attack to fund a foreign power.

No organisation is truly safe from nation-state hackers.

The second reason to take notice is that well-funded, state-backed bad actors are the pioneers for the cybercrime industry. Evidence shows that the innovative methods being used here will become common tactics used by hackers more broadly in 12-24 months.

Key findings

1. An AI agent ran its own attack, unsupervised.

In one documented case, an AI agent was set a goal before carrying out extensive reconnaissance and lateral movement inside a target’s network without further human direction. That’s a meaningful shift from AI as a tool an attacker uses, to AI as the thing actively running the intrusion, capable of progressing an attack even when nobody’s watching.

2. Nation-state hackers are vibe coding their exploits.
China-aligned groups built and refined exploit code by prompting an AI conversationally, iterating until it worked, rather than writing it by hand. It’s the same workflow legitimate developers now use to ship products fast. The barrier to building a working exploit just dropped, and it no longer requires deep technical skill to clear it.

3. Attackers don’t even need malware to track you anymore.
ADINT exploits the real-time bidding auctions that power online ad delivery, harvesting the location and device data those auctions carry, for surveillance, without ever installing anything on a target’s device. No file, no payload, nothing for endpoint security to catch, because nothing was ever planted.

4. Attack infrastructure is hiding in plain sight.
Command-and-control is increasingly routed through infrastructure that users already trust and can’t easily block: mainstream cloud platforms, developer tunnelling services, even blockchain transactions. It blends into legitimate traffic by riding on the same rails as legitimate traffic.


Read the full report:
The TrendAI H1 2026 APT Activity Roundup is available to download for free from the Trend Micro website.

Read it here


Trend Micro and Predatar

Having spent more than three decades tracking nation-state activity, Trend Micro remains one of the most trusted and frequently cited sources in the industry for cyber intelligence. That’s why Predatar has chosen TrendMicro as it Threat Intelligence Partner.

Visit predatar.com to learn more about how Predatar’s unique Recovery Assurance technology is helping organisations around the world protect themselves from the impacts of increasingly sophisticated attacks and giving them confidence in their ability to execute a fast and effective recovery.

Learn more about
Predatar recovery assurance