Crypto news

10.08.2026
15:16

Kimsuky masters offline AI: a new attack vector on the crypto industry

Lazarus Group КНДР хакеры

The North Korean hacker group Kimsuky, known for its attacks on the financial sector, is moving to a new level of technological sophistication. During an analysis of their infrastructure, I discovered the use of local environments based on large language models (LLMs)—specifically, the Ollama, GPT4All, and Msty frameworks. This fundamentally changes the threat landscape for cryptocurrency companies.

The key feature of these tools is their complete autonomy. Operating offline, they use the Retrieval-Augmented Generation (RAG) method, which allows them to process requests without transmitting data to cloud services. For hackers, this means not only increased stealth but also the impossibility of traffic interception by security systems that monitor outbound connections.

Integration of AI into Combat Scenarios

My analysis shows that the group is not just experimenting with the technology. Their arsenal includes libraries for embedding language models into their own software, as well as the AI programming assistant Cursor and speech recognition tools. This indicates a systematic approach: LLMs are being integrated into malware development processes, vulnerability analysis, and attack automation.

What is particularly concerning is that Kimsuky is betting on ready-made open-source solutions rather than training their own models. This sharply lowers the barrier to entry and accelerates the cycle of creating new attack vectors. The group has already moved from the testing stage to the practical application of AI in real operations.

Next-Generation Phishing

Special attention should be paid to the use of generative AI to create phishing materials. I have identified documents that mimic Korean digital asset investment platforms. They stand out not only for their natural language but also for their professional design, making them nearly indistinguishable from legitimate ones. This is a serious challenge for spam filtering systems and staff training.

Against this backdrop, I would like to remind you that in August, the exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, which underscores the scale of the threat posed by North Korean groups.

My expert assessment: Kimsuky's transition to local LLMs is a marker of a global trend. Crypto companies should reconsider their threat models, paying special attention not only to network anomalies but also to content filtering at endpoints. Offline AI makes attacks less predictable, and preventive protection is now more important than ever.