Crypto news

10.08.2026
15:46

Kimsuky arms itself with local AI: a new era of attacks on the crypto industry

Lazarus Group КНДР хакеры

The North Korean hacker group Kimsuky, known for its cyber operations against the financial sector, has moved to a new level of technological sophistication. My analysis of the latest data from South Korean cybersecurity researchers shows that the group is actively integrating local artificial intelligence systems into its attack chains targeting cryptocurrency companies and financial institutions.

Local AI as a New Generation Weapon

In Kimsuky's infrastructure, deployed environments of large language models (LLMs) based on open platforms—Ollama, GPT4All, and Msty—have been discovered. The key feature of these tools is full autonomy. They operate offline using the Retrieval-Augmented Generation (RAG) method, allowing hackers to process data and generate content without transmitting information to cloud services. This is a critical point: it reduces the risk of traffic interception to zero and makes attacks nearly invisible to monitoring systems based on network anomaly analysis.

In addition to ready-made LLM environments, the group's arsenal includes libraries and frameworks for embedding language models into their own malware. Of particular note is the use of the AI coding assistant Cursor and speech recognition tools. This indicates that Kimsuky is not just experimenting with the technology but is systematically integrating it into the full cycle of cyber operations—from malware development to automating phishing campaigns.

A Pragmatic Approach to AI

It is important to note that North Korean hackers are not spending resources on training their own models from scratch. Their strategy is the pragmatic use of ready-made open-source solutions, which significantly accelerates adoption and lowers the barrier to entry. This is an alarming signal: criminal groups are quickly adapting to advanced technologies, using them to enhance the effectiveness of their attacks.

Of particular concern is the use of generative AI to create phishing documents. The generated materials on digital assets, investment strategies, and fintech services feature natural language and professional formatting. Some of them mimic documents from a Korean AI investment platform, making them nearly indistinguishable from legitimate ones. This confirms that attacks are becoming more personalized and convincing, increasing the likelihood of successfully deceiving even experienced users.

Against the backdrop of these events, it is worth recalling that in August, the crypto exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, underscoring the growing legal and operational threat posed by North Korean hackers.

My expert assessment: Kimsuky's transition to local AI solutions is not just a tactical move but a strategic shift in cybercrime. The use of offline LLMs renders traditional detection methods based on network traffic analysis useless. Crypto companies need to reconsider their security protocols, focusing on behavioral analysis and content verification at the end-user level.