AI as tradecraft: How threat actors operationalize AI
2026-03-07T14:52:18Z•a055155536c829db349ee665c82bb5c0671ccbbe602ce1284cea93ec2deab755
AI operationalizationAI threat modelingAiTM phishingCoral SleetEV certificate theftJasper SleetLLM data exfiltrationMicrosoft DefenderNext.js malicious reposOAuth redirection abuseRCE-to-C2RMM backdoorsTycoon2FAautonomous defensedeveloper supply chainmalicious browser extensionsphishing deliveryphishing-as-a-servicesecurity exposure managementsecurity operationsthreat actorsthreat modeling
What happened
Microsoft posts highlight a wave of high‑impact, AI‑enabled and supply‑chain attacks that scale threat actor tradecraft and expand exposure across enterprises. Key incidents include North Korean groups (Jasper Sleet/Coral Sleet) operationalizing AI, malicious “AI assistant” browser extensions that harvested LLM chat histories and browsing data ( ~900,000 installs; activity across >20,000 enterprise tenants), the Tycoon2FA AiTM phishing‑as‑a‑service platform (reaching >500,000 organizations monthly), signed malware using a stolen EV certificate to deploy legitimate RMM tools for persistent back
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- a055155536c829db349ee665c82bb5c0671ccbbe602ce1284cea93ec2deab755
- Enrichment time
- 2026-03-07T14:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.