Mark RadarMARK RADAR
EN

Microsoft Says North Korean Hackers Are Using AI Agents to Automate Cyberattacks and IT Fraud

2 reports · First detected 2026-03-09 · Last active 2026-03-16

North Korea has long placed remote IT workers using false identities inside U.S. and European companies, generating foreign currency for Pyongyang and potentially gaining access to sensitive systems. U.S. Justice Department data show that more than 300 U.S. companies were infiltrated from 2020 to 2024, with at least $6.8 million flowing to the North Korean government. The figures underscore how recruitment processes have become a corporate cybersecurity vulnerability.

Microsoft Threat Intelligence said on March 6, 2026, that Coral Sleet and Jasper Sleet had used AI agents to automate reconnaissance, attack infrastructure, and command-and-control operations. They also used Face Swap, voice-changing software and generative AI to fabricate identities. Microsoft disrupted 3,000 related Outlook and Hotmail accounts in 2025, while the latest reports on March 15 said the fraud was expanding from the United States into Europe.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR