[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fcQz4BrXeHp9-jkJ5uNARAPzeftpzy4z-KESOdpVMaFI":3},{"article":4,"iocs":37,"watch_terms":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":10,"url":11,"image_url":12,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":17,"category":18,"article_tags":21},"98808fc3-d0ef-4cfe-9470-de296b81c233","AI as tradecraft: How threat actors operationalize AI","ai-as-tradecraft-how-threat-actors-operationalize-ai","Threat actors are operationalizing AI to scale and sustain malicious activity, accelerating tradecraft and increasing risk for defenders, as illustrated by recent activity from North Korean groups such as Jasper Sleet and Coral Sleet (formerly Storm-1877). The post AI as tradecraft: How threat actors operationalize AI appeared first on Microsoft Security Blog.","Threat actors are increasingly operationalizing AI to scale malicious activities and accelerate attack tradecraft, creating heightened risks for defenders. Recent activity from North Korean APT groups Jasper Sleet and Coral Sleet (formerly Storm-1877) demonstrates this trend of AI-enabled cyber operations.",null,"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F03\u002F06\u002Fai-as-tradecraft-how-threat-actors-operationalize-ai\u002F","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002Fwp-content\u002Fuploads\u002F2026\u002F03\u002FThreat-actors-operationalize-AI-social.png","2026-03-06T17:00:00+00:00","2026-03-15T06:36:25.716027+00:00",8,[],"839da5c1-3c34-47e2-9499-f7201640e3ac",{"id":17,"icon":10,"name":19,"slug":20},"AI Security","ai-security",[22,27,32],{"category":23},{"id":24,"icon":10,"name":25,"slug":26},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":28},{"id":29,"icon":10,"name":30,"slug":31},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":33},{"id":34,"icon":10,"name":35,"slug":36},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[38,42],{"type":39,"value":40,"context":41},"mitre_attack","Jasper Sleet","North Korean APT group operationalizing AI for malicious activities",{"type":39,"value":43,"context":44},"Coral Sleet","North Korean APT group (formerly Storm-1877) operationalizing AI for malicious activities",[]]