North Korean hackers have armed themselves with local AI: a new era of cyberattacks on the crypto industry

Analysis of the latest data from South Korean cybersecurity experts has revealed a troubling trend: the Kimsuky group, operating in the interests of North Korea, has shifted from experimenting with artificial intelligence to its full-scale combat deployment. This is not about simply using cloud-based ChatGPT-like services, but about deploying local LLM environments based on open platforms such as Ollama, GPT4All, and Msty.
The key advantage of this approach is full autonomy. Local models operate offline, which eliminates data leakage through cloud requests and makes attacks virtually invisible to traditional monitoring systems. Using the Retrieval-Augmented Generation method, hackers can process stolen information and generate content without leaving external traces.
Next-Generation Infrastructure
In Kimsuky's infrastructure, not only the models themselves were discovered, but also an entire arsenal of supporting tools: libraries for embedding AI into their own software, the Cursor programming assistant, and speech recognition systems. This points to a systematic approach: AI is being integrated into the chain of malware development, intelligence analysis, and attack automation.
Of particular concern is that the group is betting on off-the-shelf technologies rather than training its own models. This significantly lowers the barrier to entry and accelerates the cycle of creating new threats. In essence, we are witnessing the industrialization of state-scale cybercrime.
Phishing on Steroids
Of special note is the use of generative AI to create phishing documents. Kimsuky generates materials about digital assets, investment strategies, and fintech services that are nearly indistinguishable from legitimate ones. Some samples imitated documents from a Korean AI investment platform—with natural language and professional formatting, which significantly increases the chances of successful social engineering.
This is not just evolution—it is a qualitative leap. Previously, phishing emails could be recognized by grammatical errors or template phrases. Now, AI neutralizes these markers, making attacks personalized and convincing.
Notably, in August, the cryptocurrency exchange Bybit already filed a civil lawsuit against North Korea and the Lazarus Group. But, as practice shows, legal measures rarely stop such actors. The industry urgently needs to rethink its security protocols, considering that the adversary is now armed not only with code but also with artificial intelligence.
My conclusion: the integration of local AI models into Kimsuky's arsenal is a signal for the entire crypto industry. Traditional defense methods based on signatures and behavioral analysis are becoming outdated. We need to think about AI-driven defense, where machine learning is used to detect anomalies rather than generate threats. Otherwise, we will forever be chasing a moving train.