Microsoft warns of fake IT worker identities infiltrating cloud environments
ID: 25c3cd61-1b01-5363-ab15-1968be03a4f0
STIX ID: report--25c3cd61-1b01-5363-ab15-1968be03a4f0
Feed Name: GBHackers
Microsoft warns that Jasper Sleet, a North Korea‑aligned actor, is abusing remote hiring processes and HR SaaS APIs (for example, Workday) to place fraudulent IT contractors into organizations by using stolen/fabricated identities, AI‑enhanced resumes, and deep social engineering. Once onboard, these fake workers obtain legitimate access to cloud services (SharePoint, OneDrive, Exchange Online) to exfiltrate data, redirect payroll, and maintain persistence; Microsoft recommends treating recruitment/onboarding as part of the attack surface, integrating HR telemetry with Defender/Defender for Cloud Apps, and investigating anomalous new‑hire activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
