North Korean hackers have armed themselves with local AI: a new era of cyberattacks on the crypto industry

Analysis of recent cyber threats shows that the North Korean group Kimsuky, known for its attacks on the financial sector, has made a qualitative leap in tactics. My research indicates that the attackers are actively integrating local language models into their operations targeting cryptocurrency companies. This is not just experimentation, but a full-scale modernization of their attack arsenal.
Offline Tools: The Main Trump Card
Local environments based on Ollama, GPT4All, and Msty have been discovered in the hackers' infrastructure. The key feature of these solutions is full autonomy. Operating offline, they use the Retrieval-Augmented Generation method, allowing them to process requests without transmitting data to cloud services. This makes attacks virtually invisible to traditional monitoring systems that track suspicious network traffic.
Additionally, the group's arsenal includes libraries for embedding AI into their own software, the Cursor programming assistant, and speech recognition tools. This set indicates a systematic approach: hackers are not just using ready-made solutions but adapting them to their tasks—from generating malicious code to automating complex multi-stage attacks.
Next-Generation Phishing
Of particular note is the use of generative AI to create phishing materials. Generated documents about digital assets and investment strategies mimic official papers from a Korean AI platform. They feature natural language and professional formatting, significantly increasing the chances of deceiving even experienced employees of financial organizations.
In my assessment, Kimsuky's shift to using local LLMs is a worrying signal for the entire industry. Unlike cloud services, such models leave no digital traces that could alert analysts. The hackers' priority is applying ready-made technologies rather than building their own models, which accelerates their adaptation to new defense mechanisms.
Recall that in August, the crypto exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, underscoring the seriousness of the threat. However, current findings demonstrate that North Korean groups continue to evolve, and the industry must rethink its cybersecurity approaches in light of new AI risks.