The North Korean hacker group Kimsuky is reportedly employing local AI systems to target cryptocurrency and financial companies, as revealed by South Korean cybersecurity analysts from Genians.
Researchers discovered that Kimsuky has implemented local large language model (LLM) environments utilizing platforms such as Ollama, GPT4All, and Msty. These tools operate offline and utilize a Retrieval-Augmented Generation method, allowing for queries without transmitting data to cloud services.
AI-assisted attack scheme. Source: Genians.Within the group's infrastructure, analysts also found libraries and frameworks designed for embedding language models into their software, an AI programming assistant named Cursor, and various speech recognition tools.
Genians linked this activity to the integration of open-source LLMs into the development of malware, data analysis, and attack automation.
According to the firm, Kimsuky is no longer merely "testing AI" but is actively preparing to incorporate it into real attack tools, focusing on utilizing existing technologies rather than developing their own models.
Additionally, Genians pointed out that the group continues to leverage generative AI for crafting phishing documents related to digital assets, investment strategies, and fintech services. Some of these materials mimicked documents from a Korean AI investment platform, featuring natural language and professional formatting.
Phishing email generated by AI. Source: Genians.It is worth noting that in August, the cryptocurrency exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group.
