State-backed actors are no longer using AI solely to develop malware. In the first half of 2026, AI agents began to carry out parts of the attacks, including autonomously mapping networks and moving between systems, according to a new report from TrendAI.
According to the report: How APTs Are Weaponizing Trust in the Age of AI AI has gone from being a single tool to playing a role in multiple parts of the attack chain. Between January and June 2026, the technology appeared in more stages of state-sponsored cyberattacks than in any previous six-month period recorded. TrendAI has followed.
The development is relevant for Swedish organizations, which are dependent on international supply chains, cloud services and connected infrastructure. Attacks against authorities, the defense industry, technology suppliers and critical operations could have widespread consequences in Sweden.
– Artificial intelligence has gone from being a side tool for attackers to becoming a teammate integrated into the operation itself, says Robert McArdle, Director of Cybercrime Research at TrendAI. We see state-backed actors handing over network mapping and movement to an AI agent, using generative models to incrementally evolve malware in the same way a developer releases new code. Defenders must now assume that the adversary on the other side of an intrusion may not be a person typing commands, but a system executing a plan.
The report shows, among other things, that:
- China-linked actors used generative AI to improve their attack methods and develop malware. In one case, an AI agent independently mapped and moved within a compromised network.
- The Russia-linked group Pawn Storm exploited a previously unknown vulnerability in Microsoft Office and continued its attacks against Ukraine and its partners in the public sector, defense, and aid.
- Actors linked to North Korea used commercial AI services and manipulated a common software package to reach developers and businesses further down the supply chain.
- Iran-linked actors searched for vulnerable Ivanti systems just days after a new vulnerability was disclosed. Other actors attacked internet-connected operational technology.
The report also shows that both known and previously unknown vulnerabilities are being exploited shortly after they are disclosed. At the same time, supply chains, cloud platforms and internet-connected industrial systems continue to be attractive targets. In addition, a new method, ADINT, makes it possible to collect location and device data through digital ad auctions without installing malware.
For Swedish businesses, the development underscores the need for rapid vulnerability management, better control over external suppliers, and increased monitoring of identities, cloud environments, and connected systems.








