AI as tradecraft: How threat actors operationalize AI
2026-03-08T14:52:25Z•59bf618c28200ae427fc455fca52447a7f3f2b5bb783523c8818c204e95304f9
AI tradecraftAiTM phishingCoral SleetJasper SleetLLM chat harvestingMicrosoft DefenderNext.js supply-chainNorth KoreaOAuth redirection abuseRCE-to-C2RMM backdoorsTycoon2FAdeveloper-targetingexposure managementmalicious browser extensionsphishingphishing-as-a-servicesecurity operationssigned malwarestolen EV certificatethreat modeling
What happened
Microsoft Security Blog highlights multiple high-impact adversary techniques and trends: threat actors (including North Korean groups Jasper Sleet and Coral Sleet) are operationalizing AI to scale tradecraft; malicious AI browser extensions have harvested LLM chat histories and browsing data at scale (nearly 900,000 installs, activity across >20,000 enterprise tenants); Tycoon2FA (an AiTM PhaaS) enabled phishing campaigns affecting hundreds of thousands of organizations and was disrupted by industry law‑enforcement actions; signed malware using a stolen EV certificate deployed legitimate RMMs为
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 59bf618c28200ae427fc455fca52447a7f3f2b5bb783523c8818c204e95304f9
- Enrichment time
- 2026-03-08T14:52:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.