Microsoft Digital Defense Report 2024 finds AI increasingly used in nation-state influence and cyber operations
Microsoft said it tracked over 1,500 threat groups and cited specific 2024 cases, including AI-generated audio of Elon Musk narrating a fabricated Russian documentary.
- Security & misuse
- Notable
Microsoft published the 2024 edition of its Digital Defense Report, an annual assessment of the threat landscape drawn from its own telemetry. The report said Microsoft Threat Intelligence tracked more than 1,500 distinct threat groups, including over 600 nation-state actors, roughly 300 cybercrime groups and around 200 groups running influence operations.
Its central claim on AI was that state-linked actors were increasingly folding AI-generated content into influence campaigns to improve productivity and audience reach rather than to introduce fundamentally new tactics. Microsoft gave specific 2024 examples: a Chinese-linked campaign using an AI-generated cartoon character it called “Taizi,” a Russian-linked operation producing AI-generated audio of Elon Musk narrating a fabricated documentary, and Iran or Iran-aligned actors likely using AI-generated video ahead of a military operation. The report also described growing overlap between state actors and cybercrime groups, with some nation-state operations described as enlisting cybercriminals and commodity malware for intelligence collection, partly for financial gain rather than purely strategic ends.
The report sat alongside a broader body of separate industry and government reporting through 2024 that reached similar conclusions: generative AI was lowering the cost of producing convincing fake audio, video and text for influence campaigns, even where the underlying persuasive tactics remained familiar. Microsoft’s report did not claim that AI had yet produced a decisive shift in the effectiveness of influence operations, framing the change primarily as one of scale and production cost rather than of novel capability.
As an annual publication, the report became a recurring benchmark for tracking how nation-state use of generative AI evolved year over year, with subsequent editions published in 2025 and 2026 extending the same threat-tracking methodology.