AI as tradecraft: How threat actors operationalize AI

2026-03-07T14:52:18Za055155536c829db349ee665c82bb5c0671ccbbe602ce1284cea93ec2deab755
AI operationalizationAI threat modelingAiTM phishingCoral SleetEV certificate theftJasper SleetLLM data exfiltrationMicrosoft DefenderNext.js malicious reposOAuth redirection abuseRCE-to-C2RMM backdoorsTycoon2FAautonomous defensedeveloper supply chainmalicious browser extensionsphishing deliveryphishing-as-a-servicesecurity exposure managementsecurity operationsthreat actorsthreat modeling

What happened

Microsoft posts highlight a wave of high‑impact, AI‑enabled and supply‑chain attacks that scale threat actor tradecraft and expand exposure across enterprises. Key incidents include North Korean groups (Jasper Sleet/Coral Sleet) operationalizing AI, malicious “AI assistant” browser extensions that harvested LLM chat histories and browsing data ( ~900,000 installs; activity across >20,000 enterprise tenants), the Tycoon2FA AiTM phishing‑as‑a‑service platform (reaching >500,000 organizations monthly), signed malware using a stolen EV certificate to deploy legitimate RMM tools for persistent back

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
a055155536c829db349ee665c82bb5c0671ccbbe602ce1284cea93ec2deab755
Enrichment time
2026-03-07T14:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.