Will it run?
Security

AI becomes core component of state-sponsored attacks, TrendAI report finds

By Ilse Brandt Clawpit staff
AI becomes core component of state-sponsored attacks, TrendAI report finds

TrendAI division of Trend Micro released its semi-annual APT report for the first half of 2026, concluding that AI-generated tools are no longer experimental aids but integral to nation-state attack teams. Robert McArdle, head of cybercrime research at the firm, says state actors now delegate information-gathering and lateral movement to autonomous AI agents and employ generative models to develop malware at the same pace as they release code updates.

According to the report, actors linked to Beijing have embedded GenAI to refine existing campaigns and iteratively develop malware through wave coding. In one documented case an AI agent operated independently to collect data and conduct lateral movement inside an unnamed victim network. Concurrently, groups associated with the Kremlin opened the year by exploiting a zero-day vulnerability in Microsoft Office, then continued to focus attacks on Ukraine, its partners, government and security bodies, and humanitarian organizations operating in conflict zones.

North Korean hackers incorporated commercial AI tools into operations and injected malware into a widely used software package to compromise developers along the supply chain. On the Iranian side, the Earth Vetala group began renting attack tools from criminal-as-a-service platforms, a move that blurs attribution to a specific state. Researchers also note Iranian proxies targeting U.S. operational-technology (OT) infrastructure exposed to the internet, causing fuel-meter disruptions by exploiting vulnerabilities in legacy fuel-management systems. Critical infrastructure, government entities and security organizations remained primary targets, alongside location-data harvesting from digital advertising footprints.

A cross-industry finding shows attackers quickly exploit newly disclosed, publicly known weaknesses, while supply-chain attacks remain a principal intrusion vector. An emerging attack channel is advertised intelligence (ADINT), where adversaries harvest location and device information from online ad auctions without needing to deliver malware. At the same time, command-and-control (C2) traffic is increasingly masqueraded within cloud services and legitimate platforms, and Malware-as-a-Service continues to obscure the source of attacks.

McArdle stresses that offensive strategies rely on abusing familiar services—cloud platforms, blockchain and development tools—to hide hostile activity. The operational takeaway for defenders, he says, is to assume the opposite side operates an autonomous system executing a predefined plan rather than a human manually issuing commands. Consequently, cybersecurity is no longer solely an IT department issue but a central element of business resilience.