It has come to light that the hacker group “Kimsuky,” believed to have deep ties to the North Korean government, has independently built and is operating a suite of artificial intelligence (AI) tools aimed at streamlining cyberattacks. A research report published on August 10 by South Korean cybersecurity firm Genians suggests the group has established a foundation for running and managing large language models (LLMs) in a local environment and is advancing its ability to integrate AI into malware development, data analysis, and the automation of phishing attacks.
According to the Genians report, traces were confirmed of Kimsuky deploying open-source LLM management tools such as Ollama, GPT4All, and Msty. These are software applications designed to run AI models on a user’s own computer without an internet connection. Furthermore, the group is said to have built a technology known as “Retrieval-Augmented Generation” (RAG), which searches for necessary information from large volumes of documents and has the AI generate answers.
This suite of tools allows attackers to analyze and process stolen classified documents in a closed environment without sending them to external AI services. This means they can leverage the advanced processing power of AI for espionage activities and the preparatory stages of cyberattacks while mitigating the risk of information leaks.
In addition, Genians discovered on servers linked to Kimsuky’s activities a development framework for “AI agents” that autonomously execute tasks, voice recognition software, and the AI-assisted coding tool “Cursor.” Cursor is a tool that allows developers to automatically generate and complete program code by issuing instructions in natural language, potentially increasing the efficiency of malware development significantly.
In its report, the company points out that this discovery is evidence that Kimsuky is moving beyond the stage of simply using generative AI to write phishing emails and into a more advanced “industrialization of attacks.” In fact, decoy documents believed to be AI-generated were also found that closely resemble legitimate investment reports and business documents from the financial and cryptocurrency sectors. These documents are seen as highly convincing “bait” to trick targets into downloading malware.
It should be noted that Genians’ findings have not yet been independently verified by a third-party organization.
North Korea has for many years utilized state-sponsored cyber units as a means of espionage and revenue generation. According to U.S. and South Korean authorities, as well as multiple cybersecurity experts, these units have repeatedly targeted financial institutions and cryptocurrency exchanges worldwide, using the proceeds to fund nuclear and missile development programs under United Nations sanctions.
The U.S. Treasury Department designated Kimsuky in 2023 as a cyber espionage group under North Korea’s Reconnaissance General Bureau, the country’s military intelligence agency, and imposed sanctions. It determined that the group conducts intelligence-gathering activities to support Pyongyang’s strategic objectives. The Genians report highlights how this same Kimsuky group is actively incorporating the latest AI technology to further enhance its cyberattack capabilities.
A key characteristic of the AI tools discovered this time is that they all operate in a local environment. This completely avoids the risks of censorship, account suspension, and usage log tracking that arise when using external commercial AI services like OpenAI’s ChatGPT or Google’s Gemini. Within the cybersecurity industry, there is a growing view that the use of such “offline AI” by state-sponsored hacker groups will become a new threat for defenders going forward.