North Korean hackers build advanced AI tools to support cyberattacks: report
Findings indicate that hacking group 'Kimsuky' uses local AI models to automate cyberattacks, analyze stolen data and create sophisticated phishing campaigns
According to recent cybersecurity findings, North Korean state-sponsored threat groups are actively building, configuring, and deploying localized artificial intelligence (AI) tools to scale and automate cyberattacks, espionage, and financial crimes.
As reported by Reuters, South Korean cybersecurity firm confirmed on Monday a North Korean hacking group built large language model (LLM) tools and collected software that could help automate cyberattacks, analyse stolen material and produce more convincing phishing campaigns.
Genians said it found evidence that kimsuky had set up tools for running and managing AI models locally, including Ollama, GPT4All and Msty, alongside document search technology known as retrieval augmented generation (RAG).
According to the company, the tools could allow operators to process documents without sending sensitive information to outside AI services.
The findings suggest the hacking group is moving beyond using generative AI to create phishing lures and is building capacity to integrate existing AI models into malware development, data analysis and attack automation.
Rather than limiting AI usage to basic phishing text, threat groups are integrating AI agent development frameworks, speech-to-text software, and AI-assisted coding tools such as "Cursor" as this allows operators to accelerate malware development, analyze exfiltrated data, and automate various stages of the cyberattack lifecycle.
As reported, the groups are leveraging generative AI to build highly convincing, finance and cryptocurrency-themed decoy documents, fake military/government credentials, and deepfake imagery.
The advanced tools are designed to easily bypass traditional detection and trick targets into executing malicious software disguised as routine updates or official communications.
According to U.S. and South Korean authorities and cybersecurity experts, North Korea has for years used state-linked cyber units for espionage, financial theft and revenue generation.
Major tech watchdogs like Microsoft and CrowdStrike have previously highlighted North Korea as one of the most GenAI-proficient adversaries.
Operatives routinely leverage generative AI as a "force multiplier" to manage fake remote-work personas, craft resumes, pass technical interviews using deepfakes, and write code to maintain multiple illicit overseas jobs simultaneously to fund the regime.
The U.S. Treasury in 2023 also sanctioned "Kimsuky," as a North Korean government-controlled cyber-espionage group, saying it gathered intelligence in support of Pyongyang's strategic objectives.
-
Amazon may know more about you than you think: Here’s how
-
Can you get banned for insulting Claude? Here’s what policy says
-
SpaceX vs. Telecom: Elon Musk's Starlink enters mobile market—What to know
-
OpenAI explains why it fired 3 researchers amid ‘suspicious’ exit claims
-
Is Gemini a downgrade from Google assistant? Users split
-
US launches cybersecurity operation to disrupt China-linked hacking network
-
Meta blocks ByteDance, TikTok Ads on Facebook and Instagram: Here's why
-
Fired OpenAI researchers warn of ‘suspicious’ dismissals after AI safety warnings