started · updated
Kimsuky hackers use local AI tools to enhance cyberattacks
North Korean state-sponsored hacking group Kimsuky is developing an arsenal of artificial intelligence tools to enhance cyberattacks, according to a report by the Genians Security Center. Researchers identified that the group, which operates under the Reconnaissance General Bureau, has been building private, offline large language model (LLM) environments on its own attack servers.
To maintain operational security and prevent data exposure to commercial services like ChatGPT, Kimsuky has utilized open-source local AI platforms including Ollama, GPT4All, and Msty. The group has also configured retrieval-augmented generation (RAG) features, which allow AI models to search through and analyze large volumes of stolen documents more efficiently.
Evidence of these activities was uncovered through server leaks that allowed researchers to reconstruct operator keystrokes. These logs revealed North Korean-specific spelling and vocabulary in requests used to check stolen data for cryptocurrency wallet seed phrases, passwords, and Gmail credentials. Since early 2026, Kimsuky has reportedly used generative AI to create phishing documents targeting the financial, virtual asset, and game development sectors.
Entities
Genians Security Center · Kimsuky · Reconnaissance General Bureau