Crypto news

10.08.2026
20:11

North Korean hackers have armed themselves with local AI to attack the crypto industry.

Lazarus Group КНДР хакеры

Analysis of recent cyber threats shows that the North Korean group Kimsuky, known for its targeted attacks on the financial sector, has moved to a new level of technological sophistication. Instead of traditional phishing schemes, attackers are now actively integrating local large language models (LLMs) into their attack infrastructures, targeting cryptocurrency companies and fintech services.

Offline AI: A New Threat Vector

During a technical investigation, I managed to identify that Kimsuky's arsenal now includes local AI environments based on platforms such as Ollama, GPT4All, and Msty. The key feature of these tools is full autonomy: they operate offline, using the Retrieval-Augmented Generation (RAG) method. This allows hackers to process and generate data without sending requests to cloud services, making them virtually invisible to traffic monitoring systems and cloud security providers.

Additionally, the group's infrastructure contains libraries for embedding language models into their own malware, as well as the AI programming assistant Cursor and speech recognition tools. Such a set indicates that Kimsuky is not just experimenting with the technology but is systematically preparing to automate all stages of an attack—from writing code to social engineering.

From Tests to Combat Deployment

Based on the collected data, the group has already passed the "trial" stage of AI usage. Currently, there is a transition to the practical integration of open LLMs into real combat tools. Priority is given to using ready-made solutions rather than training their own models from scratch—this significantly saves resources and accelerates attack deployment.

Of particular concern is the use of generative AI to create phishing documents. The generated materials about digital assets, investment strategies, and fintech services exhibit a high degree of realism. Some of them mimic documents from Korean AI investment platforms, with natural language and professional formatting, making them virtually indistinguishable from legitimate ones.

In the context of these events, it is worth recalling that in August, the crypto exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, highlighting the growing legal and operational tension surrounding North Korean cyber operations.

My comment: The integration of local LLMs is a worrying signal for the entire industry. Offline AI makes attacks more personalized and harder to detect, and the use of RAG allows hackers to quickly adapt malicious campaigns to specific targets. Crypto companies need to reconsider their security protocols, paying special attention to behavioral analysis and monitoring of internal systems, rather than just the network perimeter.