Kimsuky masters local AI: a new attack vector on the crypto industry

The North Korean hacker group Kimsuky, known for its targeted attacks on the financial sector, has moved to a new level of technological sophistication. My analysis of the latest data indicates that the attackers are actively integrating local large language models (LLMs) into their operational processes, targeting cryptocurrency companies and fintech services.
Offline Tools as New Weapons
Local environments based on Ollama, GPT4All, and Msty have been discovered in the group's infrastructure. The key feature of these solutions is full autonomy: they operate offline and use the Retrieval-Augmented Generation method. This allows hackers to process sensitive data without the risk of leakage to cloud services, significantly complicating their tracking by security systems.
In addition, Kimsuky's arsenal includes libraries for embedding language models into their own software, as well as the Cursor AI programming assistant and speech recognition tools. This indicates a systematic approach: this is not about scattered experiments, but about the targeted modernization of the entire attack cycle—from developing malicious code to automating phishing campaigns.
Next-Generation Phishing
The use of generative AI to create phishing materials is particularly alarming. Specialists have recorded documents imitating official papers from a Korean AI investment platform. They feature natural language, professional formatting, and a deep understanding of digital assets. This tactic significantly increases the likelihood of successfully deceiving even experienced employees of financial organizations.
It is important to emphasize that Kimsuky does not spend resources on training its own models but relies on ready-made open-source technologies. This accelerates the integration of AI into real attack tools and lowers the entry barrier for other cybercriminal groups.
My expert assessment: The current trend is just the tip of the iceberg. The use of local LLMs opens up opportunities for attackers to create fully personalized attacks in real time. Crypto companies need to reconsider their security protocols, focusing on behavioral analysis and multi-factor authentication, as traditional anti-phishing filters are becoming increasingly ineffective against AI-generated content. I would like to remind you that in August, the cryptocurrency exchange Bybit already filed a civil lawsuit against North Korea and the Lazarus Group, which underscores the scale of the threat posed by North Korean hackers.