A North Korean-linked hacking group has reportedly begun developing an AI-enabled toolkit that could help automate cyberattacks, analyse stolen information and create more convincing phishing campaigns, according to South Korean cybersecurity company Genians.
The findings suggest that the group, identified as Kimsuky, may be moving beyond the basic use of generative AI for creating phishing content and is exploring ways to integrate AI directly into different stages of cyber operations.
AI Models Being Run Locally
According to Genians, infrastructure linked to the campaign contained tools for running and managing large language models (LLMs) locally.
These included:
- Ollama
- GPT4All
- Msty
- Retrieval-Augmented Generation (RAG) technology
- AI-agent development frameworks
- Speech-to-text software
- Cursor, an AI-assisted coding tool
Running AI models locally could allow operators to analyse sensitive or stolen information without sending the material to external AI platforms.
This could be particularly useful for processing large amounts of documents obtained during cyber espionage operations while reducing the risk of exposing that information to third-party services.
AI Could Automate Multiple Stages of Attacks
Genians said the findings indicate that Kimsuky could be attempting to integrate existing AI models into malware development, stolen-data analysis and attack automation.
Generative AI has already made it easier for attackers to produce convincing emails and other social-engineering material. The latest findings point towards a broader use of AI across cyber operations.
Instead of using AI only to write individual phishing messages, attackers could potentially use AI systems to process information gathered from victims, generate targeted content and assist with other technical tasks.
The cybersecurity firm also found evidence of AI-generated finance and cryptocurrency-themed documents being used as decoys.
These documents reportedly resembled legitimate investment reports and workplace materials, potentially helping attackers make malicious files or communications appear more credible.
Local AI Reduces Dependence on External Services
One of the notable aspects of the activity is the apparent use of locally hosted AI models.
Tools such as Ollama, GPT4All and Msty can allow users to run AI models on their own infrastructure rather than relying entirely on cloud-based AI services.
For malicious actors, this could offer an advantage because sensitive documents can be processed internally without being uploaded to an external AI provider.
The combination of local LLMs with RAG technology could also allow AI systems to search and analyse large collections of documents, potentially making it easier to extract useful information from stolen data.
Kimsuky’s Longstanding Cyber Activity
Kimsuky has been associated with North Korean cyber operations for years.
The group has been linked to activities involving cyber espionage, intelligence collection and financial operations, with targets including governments, organisations and individuals.
The U.S. Treasury Department sanctioned Kimsuky in 2023, describing it as a North Korean government-controlled cyber-espionage group involved in gathering intelligence supporting Pyongyang’s strategic objectives.
The latest findings suggest that AI could become another capability incorporated into the group’s existing cyber toolkit.
AI Increasingly Becomes a Cybersecurity Concern
The reported activity reflects a broader trend in which AI is becoming increasingly relevant to both cybersecurity defenders and attackers.
AI can help legitimate security teams analyse large amounts of data, identify vulnerabilities and respond to threats. At the same time, the same technologies can potentially help malicious actors automate certain tasks and produce more sophisticated social-engineering campaigns.
The development of locally operated AI systems could make the issue more difficult to control because attackers do not necessarily need access to commercial cloud-based AI platforms.
Genians cautioned that its findings could not be independently verified. Nevertheless, the report highlights the growing concern that state-linked cyber groups may increasingly incorporate AI agents, local language models and AI-assisted development tools into their operations.
As AI capabilities continue to improve, cybersecurity experts and governments are increasingly focused on preventing the technology from lowering the cost and complexity of sophisticated cyber operations.
