AI as tradecraft: How threat actors operationalize AI

2026-03-08T14:52:25Z59bf618c28200ae427fc455fca52447a7f3f2b5bb783523c8818c204e95304f9
AI tradecraftAiTM phishingCoral SleetJasper SleetLLM chat harvestingMicrosoft DefenderNext.js supply-chainNorth KoreaOAuth redirection abuseRCE-to-C2RMM backdoorsTycoon2FAdeveloper-targetingexposure managementmalicious browser extensionsphishingphishing-as-a-servicesecurity operationssigned malwarestolen EV certificatethreat modeling

What happened

Microsoft Security Blog highlights multiple high-impact adversary techniques and trends: threat actors (including North Korean groups Jasper Sleet and Coral Sleet) are operationalizing AI to scale tradecraft; malicious AI browser extensions have harvested LLM chat histories and browsing data at scale (nearly 900,000 installs, activity across >20,000 enterprise tenants); Tycoon2FA (an AiTM PhaaS) enabled phishing campaigns affecting hundreds of thousands of organizations and was disrupted by industry law‑enforcement actions; signed malware using a stolen EV certificate deployed legitimate RMMs为

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
59bf618c28200ae427fc455fca52447a7f3f2b5bb783523c8818c204e95304f9
Enrichment time
2026-03-08T14:52:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.