North Korean hackers build advanced AI tools to support cyberattacks: report
Findings indicate that hacking group 'Kimsuky' uses local AI models to automate cyberattacks, analyze stolen data and create sophisticated phishing campaigns
According to recent cybersecurity findings, North Korean state-sponsored threat groups are actively building, configuring, and deploying localized artificial intelligence (AI) tools to scale and automate cyberattacks, espionage, and financial crimes.
As reported by Reuters, South Korean cybersecurity firm confirmed on Monday a North Korean hacking group built large language model (LLM) tools and collected software that could help automate cyberattacks, analyse stolen material and produce more convincing phishing campaigns.
Genians said it found evidence that kimsuky had set up tools for running and managing AI models locally, including Ollama, GPT4All and Msty, alongside document search technology known as retrieval augmented generation (RAG).
According to the company, the tools could allow operators to process documents without sending sensitive information to outside AI services.
The findings suggest the hacking group is moving beyond using generative AI to create phishing lures and is building capacity to integrate existing AI models into malware development, data analysis and attack automation.
Rather than limiting AI usage to basic phishing text, threat groups are integrating AI agent development frameworks, speech-to-text software, and AI-assisted coding tools such as "Cursor" as this allows operators to accelerate malware development, analyze exfiltrated data, and automate various stages of the cyberattack lifecycle.
As reported, the groups are leveraging generative AI to build highly convincing, finance and cryptocurrency-themed decoy documents, fake military/government credentials, and deepfake imagery.
The advanced tools are designed to easily bypass traditional detection and trick targets into executing malicious software disguised as routine updates or official communications.
According to U.S. and South Korean authorities and cybersecurity experts, North Korea has for years used state-linked cyber units for espionage, financial theft and revenue generation.
Major tech watchdogs like Microsoft and CrowdStrike have previously highlighted North Korea as one of the most GenAI-proficient adversaries.
Operatives routinely leverage generative AI as a "force multiplier" to manage fake remote-work personas, craft resumes, pass technical interviews using deepfakes, and write code to maintain multiple illicit overseas jobs simultaneously to fund the regime.
The U.S. Treasury in 2023 also sanctioned "Kimsuky," as a North Korean government-controlled cyber-espionage group, saying it gathered intelligence in support of Pyongyang's strategic objectives.
-
OpenAI submits EU incident report after rogue AI swarm hijacks German website
-
UN rights chief names 4 AI giants he says hold ‘almost unlimited power’
-
Microsoft finds phishers using AI prompt-injection trick
-
Authors accuse OpenAI of renaming LibGen datasets to hde their origin
-
OpenAI reveals how much researchers spend on AI coding
-
Google urges chrome users to update now after critical security flaw exploited
-
3 Samsung AR apps to be shut down by 2027
-
Google, Cathay Pacific expand AI trials to cut aircraft contrail warming