AI as tradecraft: How threat actors operationalize AI
ID: b53694f4-44a3-5311-ad24-a6666c5800e2
STIX ID: report--b53694f4-44a3-5311-ad24-a6666c5800e2
Feed Name: Microsoft Security
This Microsoft Threat Intelligence blog documents how threat actors—particularly North Korean remote IT worker groups such as Jasper Sleet and Coral Sleet—are operationalizing generative and agentic AI across the cyberattack lifecycle to scale persona fabrication, social engineering (phishing and deepfakes), reconnaissance, and malware development (including AI-assisted payloads like OtterCookie); it presents observed TTPs, detection/hunting queries, and mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
