Kimsuky: North Korean hackers have armed themselves with local AI to strike the crypto industry

Analysis of recent cyber threats shows that the North Korean group Kimsuky has shifted to a new tactic: integrating local large language models (LLMs) into its attack chains. The focus is on cryptocurrency exchanges, fintech platforms, and investment companies where significant liquid assets circulate. This is not just reconnaissance, but systematic preparation for high-precision operations.
During a technical investigation of the attackers' infrastructure, isolated LLM environments based on open-source solutions Ollama, GPT4All, and Msty were discovered. A key feature is full autonomy: the models operate offline, using the Retrieval-Augmented Generation (RAG) method. This allows hackers to process stolen data and generate phishing content without the risk of leakage through cloud services, significantly complicating their tracking.
In addition to the models themselves, the group's arsenal includes libraries for integrating AI into their own software, the Cursor programming assistant, and speech recognition tools. This configuration indicates a mature approach: Kimsuky is not experimenting but actively embedding AI into malware development processes, attack automation, and analysis of large data sets.
Of particular concern is the use of generative AI to create phishing documents. The discovered materials mimic official documentation of South Korean investment AI platforms, featuring natural language and professional formatting. This means that even a sophisticated user may not distinguish a fake from the original, increasing the effectiveness of social engineering by an order of magnitude.
In my assessment, this trend is a logical response to the strengthening of protective measures in the crypto industry. The shift to local LLMs allows North Korea to bypass traffic monitoring systems and cloud filters, making attacks less predictable. The industry urgently needs to revise protocols for verifying incoming documentation and implement behavioral analysis, rather than relying solely on threat signatures. Notably, Bybit has already filed a lawsuit against North Korea and the Lazarus Group — now we see that other North Korean clusters, including Kimsuky, are expanding their technological capabilities.