North Korean Hackers Build Custom AI Arsenal for Cyber Operations
South Korean cybersecurity firm Genians reports North Korea's Kimsuky group has built local AI tools for phishing, data analysis, and malware development.
A South Korean cybersecurity firm has uncovered evidence that a North Korean state-linked hacking group is building its own artificial intelligence infrastructure to supercharge cyber operations.
Genians, a Seoul-based security company, said on Monday that it found traces of the group known as Kimsuky setting up systems to run and manage large language models locally. The setup included open-source tools such as Ollama, GPT4All, and Msty, along with retrieval augmented generation (RAG) technology used for searching and processing documents.
Running these models on their own infrastructure allows operators to analyze stolen files without sending sensitive data to external AI services, the firm noted. Genians also discovered AI agent development frameworks, speech-to-text software, and Cursor, an AI-assisted coding tool, on servers linked to the campaign.
The findings indicate that Kimsuky is moving beyond simply using generative AI to craft phishing lures. The group now appears capable of integrating existing AI models into malware development, data analysis, and automated attack workflows, according to the report.
Genians also flagged finance and cryptocurrency-themed decoy documents that appear to have been generated with AI. These files were crafted to look like legitimate investment reports and workplace materials, likely to trick targets into opening them.
The company's findings could not be independently verified. However, U.S. and South Korean authorities, along with cybersecurity experts, have long documented North Korea's use of state-linked cyber units for espionage, financial theft, and revenue generation.
The U.S. Treasury sanctioned Kimsuky in 2023, designating it as a North Korean government-controlled cyber-espionage group that gathers intelligence to support Pyongyang's strategic goals.