Crypto news

10.08.2026
17:31

North Korean hackers have armed themselves with local AI: a new era of cyberattacks on the crypto industry

Lazarus Group КНДР хакеры

An analysis of recent cyber threats has revealed a troubling trend: the North Korean hacker group Kimsuky, known for its attacks on the financial sector, is actively integrating local artificial intelligence systems into its arsenal. This is not just experimentation, but a full-fledged transition to automated and highly adaptive hacking methods targeting cryptocurrency companies.

Offline AI as a New Weapon

Deployed environments of large language models (LLMs) based on open platforms such as Ollama, GPT4All, and Msty have been discovered in the group's infrastructure. The key feature of these tools is complete autonomy. They operate offline using the Retrieval-Augmented Generation (RAG) method, allowing hackers to process and generate data without sending requests to cloud services. This significantly reduces the risk of detection and makes attackers' traffic nearly indistinguishable from legitimate traffic.

In addition to LLMs, Kimsuky's arsenal includes libraries for embedding language models into their own malware, as well as specialized AI assistants for programming and speech recognition tools. Such a set indicates deep integration of AI into the full cycle of cyber operations: from writing code to data analysis and automating attack vectors.

From Tests to Real Operations

It is important to emphasize that this is not about pilot projects. Kimsuky has moved from the "trial and error" stage to the practical application of AI in real attack campaigns. Priority is given to using ready-made, well-established technologies rather than developing their own models from scratch. This allows the group to save resources and quickly scale attacks.

Particular attention is drawn to the use of generative AI to create phishing materials. Generated documents imitating investment strategies and fintech services are highly realistic. Some of them replicate the design of Korean AI platforms for investments, making them nearly indistinguishable from the originals. This confirms that hackers use AI not only for technical attacks but also for social engineering of the highest level.

Against the backdrop of these events, it is worth recalling that in August, the cryptocurrency exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, highlighting the growing legal and operational threat posed by North Korean hackers.

My expert assessment: The use of local LLMs is a turning point. Previously, AI was a tool to enhance attacks; now it is becoming an integral part of them, making cybercriminals more autonomous and elusive. Crypto companies need to rethink their defense strategies, relying not only on traditional tools but also on behavioral analysis and anomaly detection, which can uncover even the "smartest" attacks.