Historical intelligence backfill. This assessment covers reporting originally published on 2026-03-06 and was added to the RWP archive on 2026-09-07.
Microsoft's AI-as-tradecraft brief is mostly a productivity story — with DPRK IT-worker fraud as the serious case
Microsoft says most attacker AI use is still lure-writing, translation, and malware debugging; Jasper Sleet and Coral Sleet show the higher-impact pattern — AI-scaled identity fraud for long-term remote work.
Bottom line up front
CONFIRMED On 6 March 2026 Microsoft Threat Intelligence published "AI as tradecraft." The evidenced core is not autonomous malware. Most observed abuse is generative: phishing text, translation, summarizing stolen data, debugging code, scaffolding infra. Humans still pick targets. The case that should move a CISO budget is DPRK remote-IT-worker fraud — Jasper Sleet and Coral Sleet (Coral formerly Storm-1877) — using models to fabricate identities, tailor résumés to scraped job posts, and sustain long-term insider access. Microsoft says large-scale agentic attacker AI is not yet observed at scale; reliability, not intent, is the brake.
Historical backfill of 6 March 2026 reporting; added 7 September 2026.
What happened
Microsoft split "AI as accelerator" from "AI as weapon." Accelerator is the common mode. Weaponized/agentic loops (plan, tool, adapt) are early signals. Jailbreaks against safety filters are in the mix. Secondary coverage sometimes oversells "full kill chain AI"; Microsoft's own framing keeps human control of objectives.
The September 2025 SVG phishing post in this archive is a small exhibit of accelerator-mode obfuscation. This March paper is the strategy note.
Why it mattered
Two budget errors: (1) buying "detect AI malware" while hiring still cannot spot a deepfake interview; (2) ignoring DPRK IT-worker programs because they are not a CVE. The second is a payroll, IP, and sanctions problem.
Who / what was affected
Any org that hires remote developers through marketplaces. Horizontal phishing victims of better lures. OT not claimed.
Technical context
Defender opportunities Microsoft points at: secure your own AI (keys, jailbreak, data) and hunt fabricated-identity artifacts in HR. Detection of "LLM-written phishing" is a weak primary control — we already said that in the SVG piece.
Exploitation / threat status at the time
CONFIRMED Microsoft-observed generative use; DPRK clusters named.
ASSESSED (moderate): agentic offense still limited.
UNKNOWN share of global phishing that is model-written.
What defenders should have done
- HR: liveness, device, and payroll-destination checks on remote engineering hires.
- Treat AI API keys as production secrets (see SesameOp).
- Do not staff a "was this email written by ChatGPT" queue as the main detection.
RWP assessment
Confidence: High that Microsoft's "mostly accelerator" line matches public evidence. Moderate on any one DPRK hiring anecdote in secondary press.
Defensive actions
- Remote-hire integrity controls.
- AI-secret inventory.
- Keep phishing-resistant MFA; prettier lures do not beat FIDO2.
Sources
- Microsoft Threat Intelligence — AI as tradecraft: How threat actors operationalize AI
- SecureWorld — AI is now a full-lifecycle weapon — and North Korea is leading
- Microsoft Threat Intelligence — Bluesky summary of the report