Rogue Agent Watch › Records › coral-sleet-agentic-ai-workflow
Coral Sleet (North Korea) operationalizes agentic AI tools across its attack workflow
Disclosed · added to the index · last updated
Grades
- Verification status
- Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Significant — AI materially enabled or accelerated the operation, but was one of several important components.
- Severity
- Medium — Limited or contained harm, or high-signal capability demonstration.
Summary
In its 2026-03-06 report "AI as tradecraft", Microsoft Threat Intelligence described how Coral Sleet, a North Korean state actor formerly tracked as Storm-1877, has adopted agentic AI tools across its operations: lure development including fake company websites, remote infrastructure provisioning, and rapid payload testing and deployment. Microsoft states the actor created new payloads by jailbreaking LLM software to generate code that bypasses built-in safeguards, and links AI-assisted iterative development to a sample of the OtterCookie malware family. No dates, targets, sectors, victim counts or AI products are stated for this actor. Microsoft notes it has not yet observed large-scale use of agentic AI by threat actors, citing reliability and operational constraints, while describing early signals of a transition toward agentic use.
Facts as stated by sources
- Actor
- Coral Sleet (North Korean state actor, formerly Storm-1877, per Microsoft Threat Intelligence) (Nation-state)
- Category
- AI-orchestrated campaign
- Models named
- not named by sources
- Model families
- Other / unspecified
- Agentic autonomy level
- Unknown
- Guardrail bypass
- Jailbreak, Legitimate tool abuse
- Attack lifecycle phases
- Resource development, Deception / social engineering
- Target sectors
- not stated
- Target countries
- not stated
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
None recorded upstream.
Mitigations as stated
- Microsoft recommends treating fraudulent employment and misuse of legitimate access as insider risk, hardening accounts and enforcing MFA, prioritizing behavioural signals over static or linguistic indicators, user awareness training, governing enterprise AI use and monitoring AI assets and agents, and deploying AI-specific tooling such as jailbreak detection.
Map points
- origin: North Korea (state sponsor, per Microsoft Threat Intelligence) (illustrative, country-level centroid; sponsor attribution, per Microsoft Threat Intelligence; KP)
Related records
- North Korean IT-worker remote-employment fraud using Claude
- Microsoft/OpenAI disruption of state-affiliated actors misusing LLMs (2024)
Sources (1)
- AI as tradecraft: How threat actors operationalize AI
Microsoft Threat Intelligence · Vendor report · · no archive recorded
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "coral-sleet-agentic-ai-workflow". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/coral-sleet-agentic-ai-workflow.json — CC BY-SA 4.0.