Threat Intelligence, AI/ML

Generative AI tapped to expand North Korean fake IT worker campaign

North Korea digital technology flag cyber background. North Korean banner cyberattack and espionage concept illustration.

CyberScoop reports that North Korean hacking operations Sapphire Sleet, Coral Sleet, and Jasper Sleet have been harnessing generative AI to reinforce Pyongyang's fake IT worker schemes.

Aside from using generative AI to accelerate the creation of counterfeit personas for different job roles, North Korean threat actors have also tapped the technology to develop highly convincing voice and text lures, expedite breached environment analysis, escalate privileges, and evade detection, according to a Microsoft Threat Intelligence analysis. Jasper Sleet, in particular, was observed to have used generative AI for Upwork job posting research, face swapping in stolen identity documents, and post-compromise communications. While malicious use of generative AI remains dominant, threat actors are already exploring agentic AI exploitation, said Microsoft.

"For threat actors, this shift could represent a meaningful change in tradecraft by enabling semiautonomous workflows that continuously refine phishing campaigns, test and adapt infrastructure, maintain persistence, or monitor opensource intelligence for new opportunities," Microsoft added.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds