Kimsuky used a local AI model to analyze stolen documents, report says

North Korea-linked hacking group Kimsuky built three local AI environments using Ollama, GPT4All and Msty as it prepared cyberattacks targeting cryptocurrency and financial companies, according to new research from South Korean cybersecurity firm Genians. The report said the group was using locally run large language model tools for malware development, data analysis and attack automation, alongside retrieval-augmented generation features, AI agent libraries, the coding assistant Cursor and speech-to-text tools. Genians said the activity appeared to have moved beyond isolated testing and into continuous preparation to integrate AI into operational attack capabilities, though it found no evidence that Kimsuky was developing its own models from scratch. Researchers also found polished phishing documents focused on cryptocurrency, investment strategies and fintech services that appeared to be AI-generated. The findings add to a broader pattern of North Korea-linked operations combining AI, social engineering and infiltration tactics against the crypto sector, which has already suffered an estimated $2.02 billion in stolen cryptocurrency in 2025, including the Bybit hack.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.