Microsoft Threat Intelligence reported that threat actors are increasingly using generative AI as a “force multiplier” across the cyberattack lifecycle—speeding up reconnaissance, phishing and social engineering, infrastructure setup, malware development/debugging, and post-compromise tasks such as summarizing stolen data and assisting with scripting. The report emphasizes that most observed malicious AI use today centers on language models for producing text, code, and media, reducing technical friction while human operators retain control over targeting and execution.
Microsoft highlighted North Korean activity as a prominent example, stating that groups it tracks as Jasper Sleet (Storm-0287), Coral Sleet (Storm-1877), and Sapphire Sleet are using AI to scale “fake remote worker” operations by rapidly generating realistic personas (names, resumes, communications) tailored to specific job markets and roles. Reported tactics include researching job postings (e.g., on Upwork) to align fabricated profiles with in-demand skills, using AI-generated multilingual lures that mimic internal corporate communications, and employing AI-enabled media manipulation such as Faceswap to insert operatives’ faces into stolen identity documents, alongside AI-driven impersonation and real-time voice modulation to improve social engineering and access persistence.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft said threat actors are increasingly using generative AI as a force multiplier for reconnaissance, phishing, infrastructure development, malware-related tasks, and post-compromise operations. It also warned that while most current use is generative, attackers are beginning to experiment with agentic AI for more autonomous workflows.
Microsoft Threat Intelligence reported that North Korean-linked groups including Coral Sleet, Sapphire Sleet, and Jasper Sleet are using generative AI to scale long-running fake remote worker schemes at global companies. The report said AI is being used to build tailored personas, support hiring deception, maintain access after employment, and assist post-compromise activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
socradar.io
Open sourcebleepingcomputer.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.