A North Korean-linked hacking group has developed artificial intelligence tools that could help automate cyberattacks, analyse stolen information and create more convincing phishing campaigns, according to a report by South Korean cybersecurity firm Genians.
The group, known as Kimsuky, has reportedly established infrastructure for running and managing AI models locally. Investigators identified tools including Ollama, GPT4All and Msty, as well as retrieval-augmented generation (RAG) technology used to search and process documents.
According to Genians, the setup could allow hackers to analyse sensitive documents without sending the information to external AI services.
The cybersecurity firm also identified AI-agent development frameworks, speech-to-text software and Cursor, an AI-assisted coding tool, on infrastructure linked to the campaign.
Genians said the findings indicate that Kimsuky may be expanding its use of generative AI beyond creating phishing messages. The group could potentially integrate AI models into malware development, stolen-data analysis and the automation of cyberattacks.
Investigators also discovered finance- and cryptocurrency-themed documents that appeared to have been generated using AI. The documents were reportedly designed to look like legitimate investment reports and workplace materials, potentially making them more effective as lures for victims.
However, Genians' findings have not been independently verified.
North Korea has long been accused by US and South Korean authorities, as well as cybersecurity experts, of using state-linked cyber units for espionage, financial theft and revenue generation.
In 2023, the US Treasury sanctioned Kimsuky, describing it as a North Korean government-controlled cyber-espionage group involved in gathering intelligence to support Pyongyang's strategic objectives.
The development highlights growing concerns that North Korean cyber groups are increasingly adopting AI technology to make their operations more sophisticated, scalable and difficult to detect.

0 Comment about the Post: