North Korean hackers from Kimsuky have armed themselves with local AI to attack the cryptocurrency industry.

An analysis of the infrastructure of the North Korean hacker group Kimsuky, conducted by cybersecurity specialists, has revealed a troubling trend: attackers are actively integrating local large language models (LLMs) into their attack chains targeting cryptocurrency and financial organizations. This is not about experiments, but a full-fledged shift to using offline AI to enhance the effectiveness of malicious operations.
Offline AI as a New Weapon
During the technical investigation, deployed environments based on platforms such as Ollama, GPT4All, and Msty were discovered. The key feature of these tools is their autonomy. They operate without accessing cloud services, making them virtually invisible to traditional network traffic monitoring systems. The Retrieval-Augmented Generation (RAG) method allows hackers to process local data and generate queries without the risk of leaking attack context to external data centers.
In addition to the LLMs themselves, the group's arsenal includes libraries and frameworks for embedding language models into their own software, as well as the AI programming assistant Cursor and speech recognition tools. This is a direct indication that Kimsuky is automating not only the writing of phishing emails, but also the processes of vulnerability analysis and code generation for malware.
A Pragmatic Approach and Next-Generation Phishing
Notably, Kimsuky does not waste resources on training its own models from scratch. Their strategy is a pragmatic use of ready-made open-source solutions, which significantly accelerates the attack development cycle and lowers the entry barrier for creating sophisticated cyber operations. Particular attention is drawn to the use of generative AI to create phishing documents that mimic materials about digital assets, investment strategies, and fintech services. Some samples were styled after documents from a Korean AI investment platform, featuring high-quality language and professional formatting, making them nearly indistinguishable from legitimate correspondence.
This is no longer just email automation, but the creation of targeted, highly personalized traps capable of deceiving even experienced financial department employees. Recall that in August, the crypto exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, highlighting the systemic nature of the threat posed by North Korean state-sponsored hackers.
My comment: Kimsuky's transition to local LLMs is an evolutionary leap in cybercrime. The use of offline AI not only increases stealth, but also makes attacks more adaptive. The industry needs to shift its focus from signature detection to behavioral analysis and monitoring anomalies in the use of computing resources within the perimeter, as traditional sandboxes and cloud scanners are becoming increasingly less effective against such adversaries.