Coral Sleet — APT Profile
Coral Sleet is a North Korean state-sponsored threat actor formally named by Microsoft Threat Intelligence (formerly Storm-1877), conducting fraudulent IT employment operations and AI-assisted malware development against technology and software targets. The group uses AI coding tools to generate, refine, and redeploy malware components at speed, has been observed jailbreaking LLMs to produce malicious code bypassing built-in safeguards, and leverages agentic AI workflows spanning lure creation, infrastructure provisioning, and payload testing. Microsoft has linked Storm-1877 activity to the malicious npm package campaign targeting software developers reported by Palo Alto Networks Unit 42 as Contagious Interview; Coral Sleet is tracked here as a distinct Microsoft-designated cluster while that overlap is reflected in the Contagious Interview entry. Targeting priorities align with North Korea's dual objectives of revenue generation and long-term insider access to Western organizations.Also tracked as
Storm-1877
IntelFusions coverage (1)
- North Korean IT Workers and the AI-Enabled Attack Chain: Inside Microsoft's Threat Intelligence Report 2026-03-06 · AI Security
Tools & malware
- OtterCookie Backdoor / infostealer (cross-platform, JavaScript-based)
Vendor research
- AI as tradecraft: How threat actors operationalize AI Microsoft
- Microsoft threat actor naming taxonomy mapping (MicrosoftMapping.json) Microsoft (MSTIC)
- OtterCookie, new malware used in Contagious Interview campaign NTT Security Holdings (NTT Security Japan)
- Additional Features of OtterCookie Malware Used by WaterPlum NTT Security Holdings (NTT Security Japan)