Quick Take
  • The group appears to have used generative AI to create decoy documents.
  • Genians said Kimsuky is developing capabilities to incorporate existing AI models into its attack activities.
  • Kimsuky is a threat group operating under North Korea’s Reconnaissance General Bureau.
  • The US Treasury sanctioned it in 2023 as a state-controlled espionage unit.

What Happened

North Korea’s Kimsuky hacking group has established and tested local artificial intelligence (AI) tools as it researches ways to integrate the technology into malware development and attack techniques, South Korean cybersecurity firm Genians said Monday.

Investigators found evidence that Kimsuky had installed and configured several tools for running AI models locally, including Ollama, GPT4All, and Msty.

“Based on these findings, the threat actor associated with the state-sponsored hacking group Kimsuky is assessed to have continuously researched ways to actively incorporate AI technologies into actual threat activities, including malware development and the advancement of attack techniques, rather than merely experimenting with them,” the report read.

The group reportedly used financial and cryptocurrency decoy documents that appeared to be AI-generated. The files mimicked investment reports.

Nonetheless, Genians assessed that Kimsuky’s local AI efforts remained focused on research and acquiring knowledge about how the technology could support its operations. The researchers found no evidence that the group had trained its own AI models.

The post North Korean Hackers Test AI to Advance Their Cyberattacks appeared first on BeInCrypto.

Market Context

The group appears to have used generative AI to create decoy documents. Genians said Kimsuky is developing capabilities to incorporate existing AI models into its attack activities.

Why It Matters

Genians said local processing could reduce the risk of sensitive or stolen material being sent to external AI services. The researchers also identified retrieval-augmented generation, or RAG, which allows AI models to retrieve information from selected documents.

Genians also identified AI-agent frameworks, speech-to-text software, and Cursor, an AI-assisted coding tool, on related infrastructure. The company said the collection could support efforts to integrate AI into malware development, data analysis, and attack automation.

Genians identified two potential risks. RAG could help retrieve useful information from stolen documents, while speech-to-text tools could convert stolen audio into searchable text.

Details

Inside Kimsuky’s Local AI Tools

Kimsuky is a threat group operating under North Korea’s Reconnaissance General Bureau. The US Treasury sanctioned it in 2023 as a state-controlled espionage unit.

Follow us on X to get the latest news as it happens

From Crypto Decoys to Automation

Other North Korea-linked operations have paired AI with crypto-focused attacks on executives and engineers. Such groups stole a reported $2.02 billion in crypto during 2025, according to one industry estimate on theft.

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights