A North Korean state-backed hacking group is believed to be working undercover and assembling a homegrown AI arsenal. The news comes from new research by South Korean cybersecurity firm Genians. According to Reuters, this is a sign that state-sponsored threat actors are moving beyond using chatbots to write dodgy phishing emails.
Local AI Setup
The firm says it uncovered evidence that Kimsuky, a hacking group long linked to Pyongyang, has been running its own local AI setups. It does not rely on public tools like ChatGPT. Regarding infrastructure tied to the group, Genians found software to run AI models entirely offline. This includes Ollama, GPT4All and Msty, paired with retrieval-augmented generation (RAG) systems that let AI tools search and reason over documents.
The appeal of that setup states the obvious. By keeping everything local, operators can feed sensitive or stolen material into an AI model without it ever touching an external server. This moves sidesteps the kind of oversight that comes with using a commercial AI provider.
The researchers from Genians also found frameworks for building AI agents and speech-to-text tools. They also spotted Cursor, the AI-powered coding assistant popular with developers, all sitting on infrastructure the firm connects to the Kimsuky campaign.
Phishing Lures to Full Attack Automation
Taken together, the findings point to a shift in how the group operates. Genians said Kimsuky appears to be moving beyond simply generating convincing phishing lures with AI. The North Korean hackers are now working to weave existing AI models directly into malware development, data analysis, and the automation of attacks more broadly.
The report also flags a batch of decoy documents themed around finance and cryptocurrency that look to have been AI-generated. According to Genians, they were built to pass as legitimate investment reports and everyday workplace files. This is the kind of thing a target might open without a second thought. Genians' findings haven't been independently verified.
According to assessments from US and South Korean authorities as well as independent cybersecurity researchers, none of this is entirely out of character for Pyongyang. North Korean state-linked cyber units have spent years conducting espionage operations, stealing funds and generating revenue for the regime. Kimsuky specifically has been on Washington's radar for a while. The US Treasury sanctioned the group in 2023, naming it a North Korean government-controlled cyber-espionage operation working to gather intelligence in support of Pyongyang's strategic goals. What stands out isn't that a state-backed group is using AI. Many are. It's how Kimsuky appears to be using it, not just to write phishing emails, but as part of the tools and processes behind its attacks.
Comments ( 0 )