North Korean hackers develop AI tools to automate cyberattacks
A North Korean-linked hacking group is developing and deploying artificial intelligence tools that could help automate cyberattacks, analyse stolen data and create more convincing phishing campaigns, according to South Korean cybersecurity firm Genians.
Genians said it identified evidence that the group, known as Kimsuky, had installed tools for running and managing AI models locally, including Ollama, GPT4All and Msty. The group also used retrieval-augmented generation (RAG) technology, which can help AI systems search and analyse large collections of documents, Reuters reports.
Running AI models locally could allow hackers to process sensitive or stolen information without sending it to external AI providers, Genians said.
The cybersecurity firm also identified AI-agent development frameworks, speech-to-text software and Cursor, an AI-assisted coding tool, on infrastructure it linked to the campaign.
The findings indicate that Kimsuky may be expanding its use of generative AI beyond creating phishing messages and into areas such as malware development, data analysis and attack automation, Genians said in a report.
The firm also identified finance- and cryptocurrency-themed documents that appeared to have been generated using AI. The materials were designed to resemble legitimate investment reports and workplace documents, according to Genians.
The findings have not been independently verified.
North Korea has long been accused by the United States, South Korea and cybersecurity researchers of using state-linked cyber operations for espionage, financial theft and revenue generation.
In 2023, the U.S. Treasury sanctioned Kimsuky, describing it as a North Korean government-controlled cyber-espionage group that gathered intelligence in support of Pyongyang's strategic objectives.
By Sabina Mammadli







