AI as tradecraft: How threat actors operationalize AI

2026-03-08T02:52:25Z80cc3dc83cc1e536b571245885d3fc22f1b163c63d88e2ca0aba2bcfba6f3775
AIAiTMCoral SleetJasper SleetLLMNext.jsNorth-KoreaOAuth-redirection-abuseRCERMMTycoon2FAbackdoorcommand-and-controldata-exfiltrationdeveloper-targetingexposure-managementmalicious-browser-extensionsphishingphishing-as-a-serviceprivacysecurity-operationssigned-malwarestolen-EV-certificatesupply-chainthreat-modeling

What happened

Collection of Microsoft Security Blog posts (Feb–Mar 2026) describing how adversaries are operationalizing AI and abusing common trust mechanisms to scale attacks. Key items: threat actors (including North Korean groups Jasper Sleet and Coral Sleet) are using AI to accelerate tradecraft; malicious AI browser extensions harvested LLM chat histories and browsing data across ~900k installs and >20k enterprise tenants; Tycoon2FA — a large AiTM phishing-as-a-service — enabled campaigns impacting hundreds of thousands of organizations and was targeted for disruption; signed malware using a stolen EV

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
80cc3dc83cc1e536b571245885d3fc22f1b163c63d88e2ca0aba2bcfba6f3775
Enrichment time
2026-03-08T02:52:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.