North Korea’s Hackers Are Using AI to Strengthen Cyberattacks

North Korea’s Hackers Are Using AI to Strengthen Cyberattacks

North Korean hacking group Kimsuky is increasingly incorporating artificial intelligence into its cyber operations, according to South Korean cybersecurity firm Genians. The group has reportedly moved beyond simply experimenting with generative AI and is building a more integrated AI environment that can help automate attacks, analyze stolen information, and create more convincing phishing material. The development illustrates how AI is becoming a practical tool for sophisticated cyber threat actors.

According to the report, Kimsuky has been using locally operated AI systems and tools including Ollama, GPT4All and Msty, along with retrieval-augmented generation (RAG) technology. Running models locally can allow attackers to process sensitive or stolen documents without sending the information to external AI providers. Researchers also found evidence of AI-related coding and development tools that could potentially assist with malware creation and the automation of cyber operations.

AI is also being used to make phishing and social-engineering campaigns more convincing. Genians identified AI-generated decoy documents designed around subjects such as finance and cryptocurrency, which could be used to make fraudulent communications appear more legitimate. The broader concern is that AI can reduce the amount of manual work required for cyber campaigns, allowing attackers to analyze information, generate customized material, and potentially scale operations much more efficiently.

The development highlights a broader shift in the cybersecurity threat landscape: AI is becoming useful to attackers as well as defenders. Kimsuky's reported use of local AI systems suggests that threat groups may increasingly avoid relying on public AI services and instead build their own infrastructure to bypass commercial safeguards. Although the findings come from a cybersecurity firm's analysis and have not been independently verified, they reinforce the need for organizations to strengthen phishing defenses, monitor unusual AI-assisted activity, secure sensitive data, and treat AI-enabled cyber threats as an increasingly important part of their security strategy.

About the author

TOOLHUNT

Effortlessly find the right tools for the job.

TOOLHUNT

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to TOOLHUNT.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.