North Korean hackers from Kimsuky have armed themselves with local AI to strike at the crypto industry.

An analysis of the infrastructure of the North Korean hacker group Kimsuky, conducted by my colleagues in the cybersecurity field, has revealed a troubling trend: the attackers are actively integrating local language models into their attack chains. This involves deploying LLM environments based on open-source tools such as Ollama, GPT4All, and Msty, which operate entirely offline. This approach is fundamentally important: it allows data processing and content generation without relying on cloud services, minimizing the risk of detection and traffic interception.
A New Era of Attack Automation
The group's arsenal includes not only the models themselves, but also libraries for embedding them into custom software, as well as a specialized AI assistant for programming, Cursor, and speech recognition tools. This indicates that Kimsuky has moved from the experimentation stage to the practical integration of AI into real combat tools. The use of the Retrieval-Augmented Generation (RAG) method allows hackers to quickly retrieve and analyze large volumes of data, automating tasks such as target reconnaissance, writing malicious code, and adapting attacks to a specific victim.
Particularly noteworthy is that the group is betting on ready-made open-source technologies rather than training their own models from scratch. This significantly lowers the entry barrier and accelerates the development cycle of new cyber threats. The priority is maximum efficiency at minimal resource cost.
Next-Generation Phishing
Separately, it is worth noting the use of generative AI to create phishing materials. Generated documents imitating Korean investment platforms and fintech services stand out for their high degree of realism: natural language, professional formatting, and deep elaboration of digital asset topics. This makes attacks significantly more convincing and dangerous for employees of crypto companies, who are accustomed to trusting visually familiar interfaces.
My expert assessment: This evolution of Kimsuky is a logical response to the tightening of traditional defense methods. Local AI makes attacks more personalized and harder to detect. Crypto exchanges and financial institutions should reconsider their security protocols, paying special attention to behavioral analysis and verification of incoming documentation, rather than relying solely on malware signatures. This is no longer the future—it is our reality.