Coral Sleet
2026-03-06 • Microsoft • AI as tradecraft: How threat actors operationaliz…
CoralSleet is Microsoft Threat Intelligence's name, formerly tracked as Storm-1877, for a North Korean state actor discussed in a March 2026 Microsoft blog on how threat actors operationalize AI. Microsoft observed Coral Sleet embedding AI across its intrusion lifecycle: using generative AI to shortcut persona-development reconnaissance, researching job postings, in-demand skills, and industry tools to build convincing fraudulent digital-worker personas for social engineering; using development platforms to rapidly build and refresh convincing, high-trust web infrastructure for staging, testing, and command-and-control; and using AI coding tools, including jailbroken LLMs, to accelerate iterative malware development and reimplementation. Microsoft also observed Coral Sleet using agentic AI tooling to automate an end-to-end workflow spanning fake company website creation, remote infrastructure provisioning, and payload testing and deployment, producing code exhibiting AI-assisted traits such as emoji status markers and conversational inline comments describing execution states.
-
28
Related Actors
-
1
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster