North Korean hackers have armed themselves with local AI for attacks on the crypto industry.

An analysis of the latest cyber threats reveals a troubling trend: the North Korean group Kimsuky, known for its operations against the financial sector, is actively integrating local artificial intelligence systems into its attack chains. This is no longer just experimentation, but a full-scale rearmament of the hacker arsenal.
Offline AI in the hands of attackers
My research, based on data from South Korean cybersecurity experts, has revealed that Kimsuky's infrastructure hosts local environments for large language models (LLMs) built on platforms such as Ollama, GPT4All, and Msty. The key feature of these tools is full autonomy. They operate offline, using the Retrieval-Augmented Generation (RAG) method, allowing hackers to process and generate data without relying on cloud services. This is critical: it eliminates the risk of leaking operational information through third-party channels and reduces the likelihood of detection.
In addition to LLMs, their arsenal includes libraries and frameworks for embedding models into their own software, as well as the AI programming assistant Cursor and speech recognition tools. Such a set points to deep automation of processes, from writing malicious code to analyzing large volumes of stolen data.
From phishing to attack automation
What draws particular attention is that Kimsuky appears to have moved from the AI testing stage to practical integration. Priority is given to using ready-made open-source models rather than training their own, which saves resources and speeds up the development cycle. This is no longer a "trial run," but preparation for large-scale campaigns.
It is also worth noting the continued use of generative AI to create phishing documents. Generated materials about digital assets, investment strategies, and fintech services look alarmingly natural. Some of them mimic documents from a Korean AI investment platform, featuring professional formatting and flawless language, making them nearly indistinguishable from legitimate ones.
It is worth recalling that in August, the cryptocurrency exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, underscoring the seriousness of the threat posed by North Korean hackers to the entire crypto industry.
My verdict: The use of local LLMs is a paradigm shift in cybercrime. Previously, attacks depended on templates and manual work; now we are seeing personalized and automated campaigns that can adapt in real time. Crypto companies need to rethink their defense mechanisms, betting on behavioral analysis and AI-based protection rather than just signature-based methods.