Rogue Agent Watch › Records › coral-sleet-agentic-ai-workflow

Coral Sleet (North Korea) operationalizes agentic AI tools across its attack workflow

Disclosed · added to the index · last updated

Grades

Verification status
Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Significant — AI materially enabled or accelerated the operation, but was one of several important components.
Severity
Medium — Limited or contained harm, or high-signal capability demonstration.

Summary

In its 2026-03-06 report "AI as tradecraft", Microsoft Threat Intelligence described how Coral Sleet, a North Korean state actor formerly tracked as Storm-1877, has adopted agentic AI tools across its operations: lure development including fake company websites, remote infrastructure provisioning, and rapid payload testing and deployment. Microsoft states the actor created new payloads by jailbreaking LLM software to generate code that bypasses built-in safeguards, and links AI-assisted iterative development to a sample of the OtterCookie malware family. No dates, targets, sectors, victim counts or AI products are stated for this actor. Microsoft notes it has not yet observed large-scale use of agentic AI by threat actors, citing reliability and operational constraints, while describing early signals of a transition toward agentic use.

Facts as stated by sources

Actor
Coral Sleet (North Korean state actor, formerly Storm-1877, per Microsoft Threat Intelligence) (Nation-state)
Category
AI-orchestrated campaign
Models named
not named by sources
Model families
Other / unspecified
Agentic autonomy level
Unknown
Guardrail bypass
Jailbreak, Legitimate tool abuse
Attack lifecycle phases
Resource development, Deception / social engineering
Target sectors
not stated
Target countries
not stated
Organisations affected
not stated
Records exfiltrated
not stated

Framework mappings

None recorded upstream.

Mitigations as stated

  • Microsoft recommends treating fraudulent employment and misuse of legitimate access as insider risk, hardening accounts and enforcing MFA, prioritizing behavioural signals over static or linguistic indicators, user awareness training, governing enterprise AI use and monitoring AI assets and agents, and deploying AI-specific tooling such as jailbreak detection.

Map points

  • origin: North Korea (state sponsor, per Microsoft Threat Intelligence) (illustrative, country-level centroid; sponsor attribution, per Microsoft Threat Intelligence; KP)

Related records

Sources (1)

  1. AI as tradecraft: How threat actors operationalize AI
    Microsoft Threat Intelligence · Vendor report · · no archive recorded

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "coral-sleet-agentic-ai-workflow". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/coral-sleet-agentic-ai-workflow.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction