< Back to all clusters
[TECHNOLOGY] · South Korea, North Korea · 13 sources

Kimsuky hacking group integrates local AI models for cyberattacks

North Korean-linked hacking groups, specifically Kimsuky, are increasingly integrating artificial intelligence into their cyberattack methodologies. According to a report from the South Korean cybersecurity firm Genians, Kimsuky has established infrastructure to run large language models (LLMs) locally using frameworks such as Ollama, GPT4All, and Msty.

By utilizing local AI environments and retrieval augmented generation (RAG) technology, these actors can analyze stolen documents and generate sophisticated phishing lures without sending data to cloud-based services, thereby evading detection. The group has also been observed using AI-assisted coding tools like Cursor and creating highly convincing, AI-generated decoy documents related to finance and cryptocurrency.

Other North Korean groups are also adopting AI tactics. APT45 has reportedly used recursive prompting to analyze software vulnerabilities, while the group Famous Chollima has employed AI to generate deepfakes and fake professional profiles for job-related espionage. Additionally, Kaspersky reported that Kimsuky used an LLM to assist in developing the 'HelloDoor' malware strain.

Entities: APT45 · Famous Chollima · GPT4All · Genians · Kimsuky · North Korea · Ollama

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

  • [○ 1 SOURCE] The group Famous Chollima has used AI to generate deepfakes and fake professional profiles for job-related espionage. (CrowdStrike)
  • [● 10 SOURCES] Kimsuky utilized local LLM frameworks including Ollama, GPT4All, and Msty. (Genians)
  • [● 10 SOURCES] Kimsuky utilized retrieval augmented generation (RAG) technology to search documents. (Genians)
  • [○ 1 SOURCE] Kimsuky used a large language model to assist in building the 'HelloDoor' malware strain. (Kaspersky)
  • [● 10 SOURCES] The group used AI-generated decoy documents themed around finance and cryptocurrency to impersonate legitimate reports. (Genians)
  • [● 10 SOURCES] Using local AI models allows threat actors to process sensitive stolen documents without alerting cloud-based monitoring services. (Genians)
  • [● 10 SOURCES] The cybersecurity firm Genians found evidence that the North Korean-linked group Kimsuky set up tools to run and manage AI models locally. (Genians)
  • [● 10 SOURCES] Infrastructure linked to Kimsuky contained AI agent development frameworks, speech-to-text software, and the Cursor coding tool. (Genians)