North Korean hackers have armed themselves with local AI to strike at the crypto industry.

The Kimsuky group, operating in the interests of North Korea, has moved to a new level of technological sophistication. Instead of cloud solutions, hackers are now deploying local environments based on large language models (LLMs)—such as Ollama, GPT4All, and Msty. This fundamentally changes the threat landscape: all data processing occurs offline, which eliminates traffic interception and makes attacks nearly invisible to traditional monitoring systems.
Autonomous intelligence in the hands of attackers
A key feature of the discovered infrastructure is the use of Retrieval-Augmented Generation (RAG). It allows hackers to query information and generate content without sending data to external services, making it harder to detect their activity. The group's arsenal also includes libraries for integrating AI into their own software, the Cursor programming assistant, and speech recognition tools.
These are no longer experimental attempts but systematic preparation for operational use. Kimsuky is clearly betting on embedding open-source LLMs into real attack chains—from phishing automation to data analysis and malicious code development. Priority is given to ready-made solutions rather than building custom models, which reduces preparation time for operations.
Next-generation phishing
Of particular concern is the use of generative AI to create phishing documents that mimic materials about digital assets, investment strategies, and fintech services. Some of these emails are styled as documentation from a Korean AI investment platform—they feature natural language and flawless formatting, making them nearly indistinguishable from legitimate ones.
Recall that in August, the Bybit cryptocurrency exchange filed a civil lawsuit against North Korea and the Lazarus Group, underscoring the scale of the threat posed by North Korean hackers.
My conclusion: Kimsuky's shift to local AI tools is a signal for the entire crypto industry. Traditional defense methods based on network traffic analysis are becoming less effective. Companies need to rethink their cybersecurity strategies, focusing on behavioral analysis and multi-factor authentication, as well as training employees to recognize even the most sophisticated phishing attacks.