Coral Sleet

2026-03-06 • MicrosoftAI as tradecraft: How threat actors operationaliz…

CoralSleet is Microsoft Threat Intelligence's name, formerly tracked as Storm-1877, for a North Korean state actor discussed in a March 2026 Microsoft blog on how threat actors operationalize AI. Microsoft observed Coral Sleet embedding AI across its intrusion lifecycle: using generative AI to shortcut persona-development reconnaissance, researching job postings, in-demand skills, and industry tools to build convincing fraudulent digital-worker personas for social engineering; using development platforms to rapidly build and refresh convincing, high-trust web infrastructure for staging, testing, and command-and-control; and using AI coding tools, including jailbroken LLMs, to accelerate iterative malware development and reimplementation. Microsoft also observed Coral Sleet using agentic AI tooling to automate an end-to-end workflow spanning fake company website creation, remote infrastructure provisioning, and payload testing and deployment, producing code exhibiting AI-assisted traits such as emoji status markers and conversational inline comments describing execution states.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster