Microsoft Says North Korean Hackers Are Using AI Agents to Automate Cyberattacks and IT Fraud
North Korea has long placed remote IT workers using false identities inside U.S. and European companies, generating foreign currency for Pyongyang and potentially gaining access to sensitive systems. U.S. Justice Department data show that more than 300 U.S. companies were infiltrated from 2020 to 2024, with at least $6.8 million flowing to the North Korean government. The figures underscore how recruitment processes have become a corporate cybersecurity vulnerability.
Microsoft Threat Intelligence said on March 6, 2026, that Coral Sleet and Jasper Sleet had used AI agents to automate reconnaissance, attack infrastructure, and command-and-control operations. They also used Face Swap, voice-changing software and generative AI to fabricate identities. Microsoft disrupted 3,000 related Outlook and Hotmail accounts in 2025, while the latest reports on March 15 said the fraud was expanding from the United States into Europe.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.