Cybersecurity at SMBtech

Nation-State Threat Actors Embed AI Across Attack Chains, TrendAI Report Finds

Surprisingly Useful AI Article Enhancements

Generative AI is no longer an experimental tool for nation-state hackers. It has become a core component of how they discover vulnerabilities, build malware and move through compromised networks.

That is the central finding of TrendAI’s H1 2026 APT Activity Roundup, which compiles six months of research and real-world observations into how advanced persistent threat (APT) groups aligned with China, Russia, the Democratic People’s Republic of Korea (DPRK) and Iran operated between January and June this year.

The report tracks a shift in how nation-state actors use AI. Rather than treating it as a bolt-on capability for isolated tasks, threat groups have woven AI into more stages of the intrusion lifecycle than in any prior half-year period the company has tracked.

The findings reinforce warnings from the Australian Signals Directorate that state-sponsored cyber actors are actively targeting Australian organisations, government entities and critical infrastructure.

AI as a teammate, not a tool

Robert McArdle, Director of Cybercrime Research at TrendAI, described the shift as fundamental.

“Artificial intelligence has stopped being a side tool for attackers and has become a teammate embedded in the operation itself,” he told reporters.

“We are watching nation-state actors hand reconnaissance and lateral movement to an AI agent, and use generative models to iterate on malware the way a developer ships code.”

McArdle warned that defenders can no longer assume a human is directing every intrusion.

“Defenders now have to assume the adversary on the other end of an intrusion may not be a person typing commands, but a system executing a plan,” he added.

The implication for security teams is that the speed and scale of attacks may no longer be limited by the number of human operators a threat group can deploy. An AI agent that handles reconnaissance and lateral movement can operate continuously, probing a target network for weaknesses without fatigue or time-zone constraints.

China-aligned actors turn to vibe coding

Among the most notable findings, China-aligned threat actors used generative AI to sharpen exploits and iteratively build malware through what TrendAI describes as “vibe coding,” using AI to generate and refine code through conversational prompting rather than traditional development methods.

In one case, an AI agent independently ran its own reconnaissance and lateral movement inside a target network, operating without direct human instruction during those phases of the intrusion.

The finding suggests that at least some China-aligned groups are moving beyond using AI as an assistant and toward deploying it as an autonomous operator within compromised environments. If the pattern holds, it could mark a turning point in how cyber operations are conducted, reducing the human labour required to maintain persistence inside a target network.

Russia-aligned Pawn Storm keeps pressure on Ukraine

Russia-aligned group Pawn Storm opened the year by exploiting an Office zero-day vulnerability and maintained persistent pressure on Ukraine and its partners throughout the first half of the year.

The group’s targets spanned government, defence and wartime-aid organisations, consistent with the broader pattern of Russian-aligned cyber operations that have accompanied the conflict in Ukraine.

Espionage and disruption campaigns were directed at both Ukrainian institutions and the governments and aid groups supporting them. The use of a zero-day exploit at the start of the year indicates that Pawn Storm continues to invest in acquiring or developing high-value vulnerabilities to gain initial access to its targets.

DPRK actors poison the supply chain

DPRK-aligned actors folded commercial AI tools into their operations during the period, adopting widely available models to support their campaigns.

In a separate operation, DPRK-linked groups poisoned a widely used software package to reach downstream developers. The supply-chain attack was designed to compromise targets indirectly by inserting malicious code into trusted software dependencies.

The approach reflects a continuing trend among state-backed actors of targeting software supply chains as an efficient way to reach large numbers of victims through a single point of compromise. For defenders, the challenge is that the malicious code arrives through a trusted update channel, bypassing many of the controls designed to catch externally sourced threats.

Iran-aligned groups target physical infrastructure

Iran-aligned group Earth Vetala scanned for a newly disclosed Ivanti vulnerability within days of its release, demonstrating the speed at which nation-state actors now move to weaponise fresh vulnerability disclosures.

Other Iran-aligned actors carried out hands-on attacks against internet-exposed operational technology, tampering with fuel-tank gauges at sites in the United States.

The targeting of physical infrastructure represents a return to a pattern that has long concerned security professionals: the willingness of state-backed groups to interfere with systems that have real-world safety implications. Fuel-tank monitoring systems are designed to prevent overflows, leaks and other hazards, and tampering with them could have consequences beyond the digital realm.

Advertising data weaponised for surveillance

The report highlights a tracking method called ADINT, or advertising intelligence, which harvests location and device data from online ad auctions without deploying any malware.

The technique exploits the real-time bidding process used in programmatic advertising to collect data that can be repurposed for surveillance. Because it relies on the normal functioning of advertising infrastructure rather than malicious software, it sidesteps traditional detection methods that look for malware on target devices.

For intelligence agencies and threat groups, ADINT offers a way to track individuals and map their movements without ever needing to compromise their devices directly. The method raises questions about the extent to which the advertising technology ecosystem can be co-opted for purposes its designers did not intend.

Trusted platforms used to hide command and control

TrendAI’s researchers found that threat actors are increasingly hiding command-and-control infrastructure on trusted cloud platforms, developer tunnels, blockchains and paste sites.

By hosting their infrastructure on legitimate services, attackers make it harder for defenders to distinguish malicious traffic from normal business activity. A connection to a well-known cloud provider looks the same whether it is an employee accessing a work application or a piece of malware phoning home to its operators.

The tactic complicates network-level detection and forces security teams to look beyond simple blocklists. Blocking an entire cloud platform to stop one threat actor’s command-and-control channel would also disrupt legitimate services, making the approach impractical for most organisations.

Attribution grows harder as tooling spreads

The spread of malware-as-a-service offerings and shared tooling across threat groups is making it harder to attribute attacks to specific nation-state actors, according to the report.

While the motives behind nation-state cyber operations remain consistent, the tools used to carry them out are increasingly commoditised and shared across groups, blurring the lines between state-sponsored and criminal activity.

When multiple threat groups use the same malware framework or infrastructure service, traditional indicators of compromise become less useful for pinning an attack on a particular actor. Analysts must increasingly rely on behavioural patterns and strategic objectives rather than technical artefacts alone.

Vulnerabilities weaponised at speed

A recurring theme across the report is the speed at which known and zero-day vulnerabilities are being weaponised after disclosure. In multiple cases, nation-state actors moved to exploit newly published vulnerabilities within days of the information becoming available.

The compressed timeline between disclosure and exploitation means that organisations relying on monthly or quarterly patching cycles are likely to be exposed before they can apply fixes. The report suggests that defenders need to prioritise rapid patching of internet-facing systems and assume that any publicly disclosed vulnerability will be targeted quickly.

The software supply chain also remains a favoured entry point for threat actors. By compromising a single upstream package or service, attackers can gain access to a wide range of downstream targets without needing to breach each one individually.

What it means for Australian organisations

The report’s findings land against a backdrop of sustained warnings from the Australian Signals Directorate about the threat posed by state-sponsored cyber actors to Australian organisations and critical infrastructure.

The integration of AI into nation-state attack operations means that the volume and sophistication of threats directed at Australian targets is likely to increase. Defenders will need to account for adversaries that can operate faster, adapt more quickly and sustain campaigns with fewer human operators than in previous years.

For security leaders, the message from TrendAI’s research is that the rules of engagement are shifting. The adversary is no longer constrained by the number of skilled operators it can recruit and train. With AI handling parts of the intrusion lifecycle, the barrier to conducting complex, multi-stage attacks is falling.

Last Updated on July 30, 2026 by Nick Ross

Surprisingly Useful AI Article Enhancements

Sign-up to the SMBtech Daily Newsletter

We will not spam you. You can easily unsubscribe any time. Read our privacy policy.