Crypto news

10.08.2026
16:31

Kimsuky integrates local AI models into cyberattacks on the crypto industry

Lazarus Group КНДР хакеры

The North Korean hacker group Kimsuky, known for its attacks on the financial sector, has moved to a new level of technological sophistication. Analysis of the attackers' infrastructure shows that they are actively integrating local large language models (LLMs) into their operations against cryptocurrency and fintech companies. This is not just experimentation—it is a systematic deployment of AI into the cybercriminals' arsenal of combat tools.

Offline AI as a New Weapon

During a technical investigation, I managed to identify that Kimsuky has deployed local environments based on Ollama, GPT4All, and Msty. The key feature of these solutions is full autonomy: they operate offline, using the Retrieval-Augmented Generation (RAG) method. This allows hackers to process data and generate content without sending requests to cloud services, significantly reducing the risk of detection and traffic interception.

Additionally, the group's arsenal includes libraries and frameworks for embedding language models into their own software, as well as the AI programming assistant Cursor and speech recognition tools. Such a set indicates that North Korean specialists are not merely copying ready-made solutions but adapting them to specific tasks—from vulnerability analysis to automating phishing campaigns.

From Tests to Real Attacks

It is important to emphasize that Kimsuky has already moved past the pilot project stage. Based on the collected data, the group is purposefully preparing AI for use in real attack scenarios. Priority is given to using open-source models rather than training their own—this saves resources and accelerates implementation.

Of particular concern is the use of generative AI to create phishing documents. I have recorded cases where attackers generated materials about digital assets, investment strategies, and fintech services, imitating documents from a Korean AI investment platform. These texts feature natural language and professional formatting, making them nearly indistinguishable from legitimate ones.

In the context of the recent Bybit lawsuit against North Korea and the Lazarus Group, it becomes obvious: North Korean groups are ramping up their technological capabilities, and this threat can no longer be ignored. The industry urgently needs to rethink its defense approaches, considering that AI now works on the attackers' side.

My professional opinion: the use of local LLMs is a strategic move that radically changes the threat landscape. Traditional detection methods based on network traffic analysis are becoming less effective. Crypto companies should invest in behavioral analysis and multi-factor authentication, as well as in training staff to recognize AI-generated phishing attacks.