North Korean hackers have armed themselves with local AI to attack the crypto industry.

An analysis of the infrastructure of the North Korean hacker group Kimsuky has revealed a troubling trend: attackers are actively integrating local large language models (LLMs) into their operations targeting cryptocurrency and financial organizations. This is no longer experimentation, but a full-fledged shift toward automating cyberattacks with artificial intelligence.
Offline AI: A New Frontier in Hacker Defense
During a technical investigation, I managed to discover that Kimsuky has deployed local LLM environments built on the open-source platforms Ollama, GPT4All, and Msty. The key feature of these tools is their complete autonomy. They operate offline, using the Retrieval-Augmented Generation (RAG) method, which allows hackers to process requests and generate content without transmitting data to cloud services. This significantly reduces the risk of detection and traffic interception.
Additionally, the group's arsenal includes libraries and frameworks for integrating language models into their own malware, as well as a specialized AI assistant for programming, Cursor, and speech recognition tools. Such a set indicates deep sophistication: AI is used not only for generating texts but also for optimizing code, analyzing data, and partially automating attack stages.
Next-Generation Phishing
Particular attention is drawn to the use of generative AI to create phishing materials. The discovered documents mimic legitimate files from Korean investment AI platforms, dedicated to digital assets and fintech strategies. They feature flawless natural language and professional formatting, making them nearly indistinguishable from genuine ones. This suggests that Kimsuky is betting on the quality of social engineering, increasing the likelihood of successfully deceiving even seasoned employees of crypto companies.
It is evident that North Korean hackers are not merely testing technologies but preparing them for combat use. Priority is given to leveraging ready-made open-source solutions, which allows for rapidly scaling attacks without significant costs for training their own models.
Recall that in August, the crypto exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, underscoring the growing legal and operational threat posed by these groups.
My comment: Kimsuky's transition to local LLMs is a serious signal for the entire industry. Traditional phishing detection methods based on text analysis and sender reputation are becoming ineffective. Crypto companies urgently need to implement multi-factor authentication and staff training, as well as consider AI-based defense solutions that can counter equally smart attacks.