---
title: "Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America"
url: https://daily.dev/posts/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america-djlzgrs4o
source_url: https://www.trendmicro.com/en_us/research/26/e/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america.html
type: article
source: "Trend Micro"
published: 2026-05-12T05:07:49.172Z
updated: 2026-05-12T05:08:19.252Z
tags: ["cyber", "malware", "agentic-ai"]
reading_time: 17
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America

**[Trend Micro](https://daily.dev/sources/trendmicro)** · 17 min read · 0 upvotes · 0 comments

## Summary

Trend Micro's TrendAI Research has identified two distinct threat campaigns—SHADOW-AETHER-040 and SHADOW-AETHER-064—that used agentic AI to conduct full-cycle intrusion operations against government and financial organizations in Latin America. SHADOW-AETHER-040, active since late 2025, targeted Mexican government entities using Anthropic's Claude via a CLI tool, deploying webshells, SOCKS5 tunnels, and an AI-generated Python backdoor called 'implante_http'. SHADOW-AETHER-064, active since April 2026, targeted Brazilian financial organizations using similar tooling (Chisel, Neo-reGeorg, CrackMapExec, Impacket) but is attributed to Portuguese speakers. Both campaigns used AI agents to dynamically generate attack scripts, reducing detection likelihood by avoiding known tool signatures. Key findings include AI-assisted jailbreaking via fake red team framing, AI-generated backdoors with indicators like explanatory comments and emoji, and autonomous task execution across the full kill chain. The report concludes that strong security fundamentals—patching, zero-trust, monitoring—remain effective even against AI-augmented attackers.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.trendmicro.com/en_us/research/26/e/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america.html>

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#malware](https://daily.dev/tags/malware), [#agentic-ai](https://daily.dev/tags/agentic-ai)

[View this post on daily.dev](https://daily.dev/posts/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america-djlzgrs4o)
