North Korean hackers are integrating local AI into attacks on the crypto industry.

Analysts from the South Korean company Genians have identified a troubling trend: the hacker group Kimsuky, operating in the interests of North Korea, is actively adopting local large language models (LLMs) to conduct cyberattacks on cryptocurrency and financial organizations. This is no longer just experimentation, but systematic preparation for integrating AI into real combat tools.
Local environments based on Ollama, GPT4All, and Msty have been discovered in the attackers' infrastructure. The key feature of these solutions is full autonomy: they operate offline and support the Retrieval-Augmented Generation (RAG) method, allowing queries to be processed without transmitting data to cloud services. This approach radically reduces the risk of detection and traffic interception.
Technical Arsenal and New Capabilities
In addition to LLM environments, the group's arsenal includes libraries and frameworks for integrating language models into their own software, as well as the AI programming assistant Cursor and speech recognition tools. This indicates that Kimsuky is not just using ready-made solutions but adapting them to their tasks—from automating data analysis to generating malicious code.
Particular attention is drawn to the use of generative AI to create phishing materials. Genians specialists note that generated documents about digital assets, investment strategies, and fintech services exhibit a high degree of realism: natural language, professional formatting, and imitation of documents from a Korean AI investment platform. This makes phishing attacks significantly more convincing and dangerous for unprepared users.
Strategic Shift in Tactics
According to experts, Kimsuky has already moved from the AI testing stage to practical preparation for integrating it into attack tools. Priority is given to using ready-made technologies rather than training their own models, which significantly accelerates the development cycle and reduces costs. This trend raises serious concerns, given that the group has historically specialized in highly targeted attacks against the financial sector and crypto exchanges.
It is worth recalling that in August, the crypto exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, highlighting the scale of the threat posed by North Korean hackers.
My analysis: The use of local LLMs is an evolutionary step in cybercrime that fundamentally changes the rules of the game. Offline mode makes it impossible to monitor activity through cloud providers, and the RAG method allows hackers to quickly adapt attacks to specific targets. The industry urgently needs to rethink its defense approaches, focusing on behavioral analysis and multi-factor authentication to counter AI-enhanced threats.