Crypto news

10.08.2026
14:15

Kimsuky's AI arsenal: North Korean hackers shift to local language models for attacks on the crypto industry

Lazarus Group КНДР хакеры

A worrying trend has emerged in the world of cyber threats: the North Korean group Kimsuky, known for its attacks on the financial sector, is actively integrating local artificial intelligence systems into its operations. My colleagues at the South Korean analytics center Genians conducted an in-depth study of this hacker group's infrastructure and found that it has moved from simply testing AI to fully deploying large language models (LLMs) in combat conditions.

Offline Tools: A New Level of Stealth

The key finding is the use of local LLM environments based on the open platforms Ollama, GPT4All, and Msty. This approach fundamentally changes the rules of the game in cybersecurity. Instead of turning to cloud services that can be tracked, hackers work entirely offline. Retrieval-Augmented Generation (RAG) technology allows them to process queries and generate content without transmitting data to external networks, making their activities virtually invisible to traditional monitoring systems.

The group's arsenal also includes libraries for embedding language models into their own malware, the programming AI assistant Cursor, and speech recognition tools. This points to a systematic approach: Kimsuky is not just experimenting with AI but is building a pipeline to automate cyberattacks—from writing code to analyzing stolen data.

Next-Generation Phishing

Of particular concern is the use of generative AI to create phishing materials. Genians specialists have found that the group generates documents on topics such as digital assets, investment strategies, and fintech services. Some of them mimic official papers from a Korean investment AI platform. The quality of these materials is striking: natural language, professional formatting, and the absence of grammatical errors typical of phishing. This means that even an experienced specialist may not be able to distinguish a fake from the original.

It is telling that Kimsuky is betting on using ready-made AI solutions rather than training its own models. This is a pragmatic approach that lowers the barrier to entry and allows attacks to be scaled quickly. Given that in August the crypto exchange Bybit already filed a civil lawsuit against North Korea and the Lazarus Group, it is clear that North Korean hackers continue to ramp up pressure on the crypto industry.

My analysis: The use of local LLMs is an evolutionary step that makes Kimsuky's attacks significantly more dangerous. Crypto companies and financial institutions need to rethink their defense strategies, paying special attention to behavioral analysis and training employees to recognize synthetic content. Fighting AI-armed hackers requires no less advanced technology on the defensive side.