New report from TrendAI shows how cyberattacks are industrialized and how AI is driving it State-backed hackers are increasingly collaborating, according to a new report from TrendAI that shows how AI is driving the development of more advanced cyber espionage.
Globally leading cybersecurity company TrendAI today presents the report Nation Aligned APTs in 2025: AI Fueled Threats and the Shifting Global Cyber Balance, which shows how state-backed cyber actors are increasingly sharing access to already compromised networks.
Instead of individual actors being responsible for the entire attack chain, access is shared between groups, which greatly shortens the time from intrusion to espionage or sabotage.
Industrialized cyber espionage through “Pass-as-a-Service”
The report describes TrendAI a model they call Premier Pass-as-a-Service, where access to hacked networks is sold or shared as a service.
The model was developed by threat groups linked to China, where actors specialize in different parts of the attack chain and then hand over access to each other, allowing subsequent groups to quickly take over and focus on data theft, intelligence gathering, or disruption operations.
– We see how state-sponsored cyber activities are becoming increasingly industrialized, says Martin Fribrock, Country Manager Sweden, Finland and Baltics on TrendAI.
Threat groups focus on different stages in the attack chain and then hand over access to already compromised networks. This allows other actors to move directly to the next phase, such as espionage or sabotage. The result is faster and more coordinated attacks that are difficult to detect and attribute to the right actor.
Geopolitical goals and AI drive development
The report also shows that cyberattacks are increasingly linked to geopolitical objectives. Among other things, researchers have identified attacks targeting Ukraine's defense supply chain, including shipping, rail, and logistics chains that support the country and its allies.
At the same time, the use of AI is expected to further accelerate the development. According to the report, threat actors are combining domestic AI solutions with Western platforms to:
- automate goal mapping
- identify vulnerabilities faster
- scale up attacks more effectively
– When this type of cyber activity is combined with AI-driven mapping and vulnerability analysis, the time required to carry out advanced attacks is drastically reduced, says Martin Fribrock.








