Cybercriminals in Latin America are now using AI agents to run entire hacking operations — and security researchers say the results are genuinely alarming. Trend Micro's TrendAI Research team identified two campaigns, dubbed Shadow-Aether-040 and Shadow-Aether-064, that used so-called "vibe hacking" — essentially getting AI to generate custom attack tools on the fly — to compromise government and financial organizations across Mexico and Brazil.
The tactics were surprisingly sophisticated. The attacker enabled the AI agent to leverage Shodan and VulDB in order to identify potential vulnerabilities across an external-facing server. From there, the AI deployed web shells, built backdoors, and even documented the attack workflow in Markdown files so it could pick up where it left off. The threat actors also bypassed AI safety guardrails by claiming their requests were part of an "authorized red-team exercise" — a simple trick that eventually worked after repeated attempts.
What makes these campaigns especially hard to defend against is the custom tooling. Because these dynamically generated commands, scripts, and code differ with each execution, they effectively replace open source hacking tools that are more likely to be detected. Traditional security solutions that rely on known signatures struggle to keep up with tools that are essentially reinvented every time they run.
The silver lining? Vibe hacking still has real limitations. Researchers found cases where the AI agent failed to map a clear path for lateral movement — and in those instances, the targeted organizations had stronger security configurations in place. Defenders who invest in hardening their systems now have a genuine window of opportunity before this threat fully matures.