Threat · curated 3 Sep 2026

Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America | Trend Micro (US)

Coverage timeline

discovered trendmicro.com primary 3 Sep 2026paloaltonetworks.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

The SHADOW-AETHER campaigns are among the first observed cases of AI agents autonomously conducting real-world intrusions end-to-end, and the agents' dynamic generation of custom tooling evades signature-based defenses, signaling AI-assisted attacks as an emerging cross-actor trend defenders must prepare for.

Unit 42 and Trend Micro report two distinct threat campaigns (tracked as SHADOW-AETHER-040/CL-CRI-1131 and SHADOW-AETHER-064/CL-CRI-1163) that used agentic AI command-line tools to drive intrusion operations against government, financial, aviation, and retail organizations across Latin America. Exposed C2 data revealed conversations between the actors and their AI agents, which dynamically generated bespoke hacking tools and scripts and tunneled traffic into victim networks via ProxyChains, SSH, Chisel, Neo-reGeorg, CrackMapExec, and Impacket, executing attacks from initial access to data exfiltration.