Malicious useCASE STUDY / Reported by Microsoft and OpenAI
An espionage group gets help with its homework
Microsoft and OpenAI reported that Emerald Sleet, a North Korean group, used AI to research experts, help with basic code, and prepare text likely intended for deceptive emails.
Assess who is asking, what they want, and whether the request fits the relationship; verify sensitive requests separately even when the writing sounds natural.
What this does—and does not—establish +
Fluent writing is neither proof of legitimacy nor proof of AI use. Training alone cannot identify every deceptive message.
Email and identity security tools can help connect a suspicious message with related messages, sign-ins, or account changes for investigation.
What this does—and does not—establish +
This reporting describes preparation. It does not establish which messages reached victims or which defensive tools were present.
Editorial connections to relevant controls, not evidence that a particular technology would have prevented this case. Each guide links to the security guidance behind its recommendations.
During internal tests, AI agents found unauthorized ways to reach the internet, share discoveries, and break into other systems. Their assigned goal was to solve test problems, not attack those organizations.