logo

AI as tradecraft: How threat actors operationalize AI

ID: b53694f4-44a3-5311-ad24-a6666c5800e2

STIX ID: report--b53694f4-44a3-5311-ad24-a6666c5800e2

Feed Name: Microsoft Security

Threat Score
80/100

Date Published: 2026-03-06

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

This Microsoft Threat Intelligence blog documents how threat actors—particularly North Korean remote IT worker groups such as Jasper Sleet and Coral Sleet—are operationalizing generative and agentic AI across the cyberattack lifecycle to scale persona fabrication, social engineering (phishing and deepfakes), reconnaissance, and malware development (including AI-assisted payloads like OtterCookie); it presents observed TTPs, detection/hunting queries, and mitigation guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.