Nation-state hackers from China, Russia, North Korea, and Iran are no longer using AI for isolated experiments. In attacks carried out during the first half of 2026, AI was integrated into multiple phases of the intrusion cycle, from exploitation to autonomous lateral movement.
This is according to TrendAI’s research. AI appears to be shifting from a tool to a full-fledged participant in the operation itself. China-affiliated actors used generative AI to refine exploits and build malware via vibe coding. One AI agent independently conducted reconnaissance and lateral movement within a target network. The Russia-linked Pawn Story group started the year with a zero-day exploit in Office and continued to attack Ukraine and its partners. North Korea integrated commercial AI and compromised a widely used software package to reach downstream developers.
Iran isn’t sitting idle either. The Earth Vetala group scanned for a new Ivanti vulnerability within days of its publication. Other Iranian actors manipulated fuel meters in the United States via internet-accessible operational technology (OT).
“Artificial intelligence is no longer just a tool for attackers, but a full-fledged partner in the operation itself,” says Robert McArdle, Director of Cybercrime Research at TrendAI. According to him, defenders must now assume that the adversary is an autonomous system executing a premeditated plan.
Rapid exploitation and abuse of trust
Known and zero-day vulnerabilities are exploited within days of disclosure, while software supply chains remain a favored entry point. Cybercriminals are increasingly hiding their command-and-control infrastructure within trusted cloud platforms, developer tunnels, blockchains, and paste sites. A newer tracking method, ADINT, collects location and device data from online ad auctions to target specific individuals.
Malware-as-a-Service and shared tooling make it harder to identify a perpetrator, even when a nation-state’s motives are known. “Supply chain breaches, attacks on critical infrastructure, and the abuse of legitimate services demonstrate that organizations must look beyond traditional indicators of compromise,” said Feike Hacquebord, Principal Threat Researcher at TrendAI.
Read also: Trend Micro is monitoring current and future threats