Microsoft Warns Jasper Sleet Uses Fake IT Worker Identities to Infiltrate Cloud Environments
ID: b94f94cd-a4d7-5900-a4d9-dfdfb98eb87d
STIX ID: report--b94f94cd-a4d7-5900-a4d9-dfdfb98eb87d
Feed Name: cybersecurityNews.com
Microsoft observed a North Korea-linked threat actor, dubbed Jasper Sleet, using stolen or fabricated identities and generative AI to secure legitimate remote IT jobs and infiltrate organizations via HR platforms (notably Workday). After onboarding the actor abuses access to cloud services (Teams, SharePoint, OneDrive, Exchange Online) to move laterally, exfiltrate data, and potentially extort victims; Microsoft outlines detection and mitigation steps for security and HR teams to identify suspicious candidate and post-hire behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
