radar

ONE Sentinel

securitySecurity/M365 SECURITY/HIGH

AI as tradecraft: How threat actors operationalize AI

sourceMicrosoft Security Blog
calendar_todayMarch 6, 2026
schedule1 min read
lightbulb

EXECUTIVE SUMMARY

AI in Cybercrime: North Korean Groups Exploit AI for Malicious Activities

Summary

Threat actors are increasingly using AI to enhance and sustain their malicious activities, posing a growing risk to cybersecurity defenses. Recent operations by North Korean groups Jasper Sleet and Coral Sleet exemplify this trend.

Key Points

  • AI is being operationalized by threat actors to scale malicious activities.
  • North Korean groups such as Jasper Sleet and Coral Sleet are actively using AI in their cyber operations.
  • Coral Sleet was formerly known as Storm-1877.
  • The use of AI in cybercrime accelerates tradecraft, making it more challenging for defenders.

Analysis

The operationalization of AI by threat actors marks a significant shift in the cybersecurity landscape. By leveraging AI, these groups can automate and scale their operations, making them more efficient and harder to detect. This development underscores the need for advanced defensive strategies that can counteract AI-driven threats.

Conclusion

IT professionals should prioritize the development and implementation of AI-based defensive measures to effectively counteract the growing threat posed by AI-enhanced cybercrime activities.