Kimsuky Develops AI Tools to Automate Cyberattacks, Researchers Say
The group’s latest activity suggests a shift from isolated experiments toward a broader system for turning stolen information into operational advantages.
North Korean hacking group Kimsuky is developing tools based on large language models and collecting software that could help automate cyberattacks, analyze stolen materials, and create more convincing phishing campaigns, a South Korean cybersecurity company reported.
Evidence and Tools
Genians, a South Korean cybersecurity company, found indications that the country-linked Kimsuky group had deployed and was operating local AI models, using Ollama, GPT4All, and Msty tools together with a document retrieval system based on retrieval-augmented generation (RAG) technology.
According to specialists, these tools allow documents to be processed without transmitting sensitive data to external AI services.
The infrastructure linked to the campaign also contained frameworks for developing AI agents, speech recognition software, and Cursor – an AI-powered tool designed to assist with coding tasks, the company said.
A Look at Future Capabilities and Verification
Genians’ findings indicate that Kimsuky is not limiting its use of generative AI to creating phishing lures, but is developing ways to integrate existing AI models into malware development, data analysis, and attack automation.
Documents related to finance and cryptocurrency were also found. According to the company, they may have been created with the help of artificial intelligence and designed to look like legitimate investment reports and other business materials.
The information obtained by the researchers has not been independently verified.
According to the United States and South Korea, as well as cybersecurity experts, North Korea has used state-sponsored cyber units for intelligence gathering, theft, and revenue generation for many years, as confirmed by official statements from both countries and by specialists.
In 2023, the U.S. Treasury Department imposed sanctions on the Kimsuky group, describing it as part of a government cyberintelligence unit and documenting activity aimed at supporting North Korea’s strategic objectives.
Finally, experts point to the growing role of artificial intelligence in cyber threats and emphasize the need for stronger security measures and monitoring to prevent similar attacks in the future.
- North Korean-linked hackers used prolonged social engineering to seize control of popular Axios open-source packages, publishing two malicious releases. Packages were removed, but investigators warn many systems may be exposed.
- AI is accelerating cyberattacks through faster phishing, malware creation and social engineering, but experts say people remain the greatest cybersecurity risk.
- AegisAI uses AI agents to detect AI-generated phishing in emails, closing a $36M Series A led by Battery Ventures as attackers increasingly exploit personalized messages.
