SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
AI boosts nation-state cyberattacks, TrendAI warns

AI boosts nation-state cyberattacks, TrendAI warns

Thu, 30th Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

TrendAI has released its H1 2026 APT Activity Roundup, which says nation-state cyber activity is increasingly using generative artificial intelligence.

The research covers activity observed over six months across China, Russia, North Korea and Iran-aligned groups. It examines how advanced persistent threat actors are changing their methods as they target organisations, governments and critical infrastructure in Australia, New Zealand and other regions.

Warnings from the Australian Signals Directorate and New Zealand's National Cyber Security Centre have highlighted the risk from state-backed cyber actors. The latest findings add detail on how those groups are operating, including the growing use of AI at several points in the attack chain.

Attackers are now applying AI to exploit discovery, automated reconnaissance, malware development and movement within compromised networks. The technology is no longer limited to experiments or isolated tasks.

The report says China-aligned actors used generative AI to refine exploits and build malware iteratively. In one case it cites, an AI agent independently carried out reconnaissance and lateral movement within a target network.

Russia-aligned group Pawn Storm was identified as opening the year with an Office zero-day vulnerability. The report says the group continued targeting Ukraine and organisations linked to government, defence and wartime aid.

North Korean actors were also described as incorporating commercial AI tools into their operations. One campaign involved poisoning a widely used software package in an effort to reach downstream developers through the software supply chain.

Iran-aligned activity featured rapid exploitation of newly disclosed vulnerabilities. TrendAI says Earth Vetala scanned for an Ivanti flaw within days of its disclosure, while other Iran-aligned actors attacked internet-exposed operational technology and tampered with fuel-tank gauges at sites in the United States.

Attack methods

Known vulnerabilities and zero-day flaws are being weaponised within days, leaving defenders with a shrinking window to respond. The report also points to trusted cloud services, developer tunnels, blockchains and paste sites as places where threat actors are increasingly hiding command-and-control infrastructure.

Another tactic highlighted in the research is ADINT, a tracking method that collects location and device information from online advertising auctions without deploying malware. The approach reflects a broader shift towards methods that gather intelligence or support targeting without relying on traditional malicious software.

Malware-as-a-service and shared tooling are also making attribution more difficult. Even so, the report argues that broader state objectives remain visible despite increasing overlap in the tools and infrastructure used by different groups.

Regional concern

The findings are likely to draw attention in Australia and New Zealand because both governments have recently warned that state-backed cyber groups are actively targeting public and private sector entities. Critical infrastructure operators in particular have faced repeated warnings about persistent intrusion attempts and the risks posed by unpatched internet-facing systems.

Security researchers and officials have increasingly pointed to the convergence of cyber operations and physical systems as a growing concern. The report's reference to tampering with fuel monitoring equipment adds to a broader pattern in which operational technology is again becoming a direct target rather than a secondary concern.

There is also a wider implication for incident response teams. If AI tools are handling reconnaissance or internal network movement, defenders may face attacks that move faster, adapt more quickly and require fewer direct human inputs from the operator.

Robert McArdle, Director of Cybercrime Research at TrendAI, commented on the shift in the threat landscape.

"Artificial intelligence has stopped being a side tool for attackers and has become a teammate embedded in the operation itself. We are watching nation-state actors hand reconnaissance and lateral movement to an AI agent, and use generative models to iterate on malware the way a developer ships code. Defenders now have to assume the adversary on the other end of an intrusion may not be a person typing commands, but a system executing a plan," said McArdle.