North Korean hackers are deploying local AI systems in cyberattacks on the crypto industry.

An analysis of cyberspace has revealed a troubling trend: the North Korean hacker group Kimsuky is actively integrating local artificial intelligence models into its offensive operations targeting cryptocurrency and financial structures. This is confirmed by technical research that I reviewed as part of threat monitoring.
Offline AI as a New Attack Vector
Local large language model (LLM) environments built on the Ollama, GPT4All, and Msty platforms have been discovered in Kimsuky's infrastructure. The key feature of these tools is their complete autonomy: they operate offline using the Retrieval-Augmented Generation (RAG) method. This allows hackers to process requests without transmitting data to cloud services, significantly reducing the risk of detection and traffic interception.
Additionally, the group's arsenal includes libraries and frameworks for embedding language models into their own software, as well as the Cursor AI programming assistant and speech recognition tools. This configuration points to a systematic approach: open-source LLMs are not used as an experimental toy, but as a full-fledged element of cyber-offensive capability.
From Testing to Combat Deployment
My assessment of the situation aligns with the conclusions of experts: Kimsuky has moved from the "trial" stage to the practical integration of AI into real attack chains. Priority is given to using ready-made technologies rather than developing proprietary models from scratch—this saves resources and accelerates adaptation. Particular attention is paid to automation: from generating malicious code to analyzing vulnerabilities and optimizing phishing campaigns.
It is worth emphasizing separately that generative AI is actively used to create phishing documents mimicking materials about digital assets, investment strategies, and fintech services. Some samples I was able to examine replicate the style of Korean AI investment platforms, featuring natural language and professional formatting—making them nearly indistinguishable from legitimate communications.
It is worth recalling that in August, the cryptocurrency exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, underscoring the scale of the threat posed by North Korean hackers.
My comment: The use of local LLMs is a strategic shift in APT group tactics. Moving away from cloud services complicates the tracking of attack tools and makes attacks more personalized. Crypto companies should reconsider their security protocols, placing particular emphasis on analyzing behavioral anomalies rather than relying solely on signature-based detection methods. AI-driven phishing is becoming the industry's main challenge in the coming quarters.