INTEL_REPORT
Trend Micro Research · published 5/11/2026, 12:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America TrendAI™ Research has identified two emerging threat campaigns—SHADOW-AETHER-040 and SHADOW-AETHER-064—that use agentic AI to drive intrusion operations against government and financial organizations in Latin America, marking these among the first cases we have observed of AI agents executing attacks from initial access to data exfiltration. Vibe Hacking: Two AI-Augmented Campa…
https://www.trendmicro.com/en_us/research/26/e/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america.html
sha256:ffdee84122eadfe825b88d3f321f36403e254b5d3c2231be44f55099eb507c48
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| 167.172.38.123 |
| Open → |
| ip | 155.133.27.198 | Open → |
| ip | 209.99.185.221 | Open → |
| ip | 209.99.185.223 | Open → |
| ip | 167.148.195.53 | Open → |