North Korean hackers have armed themselves with local AI: a new threat for the crypto industry

Analysis of the latest cyber intelligence data has revealed a troubling trend: the North Korean group Kimsuky, known for its attacks on the financial sector, is actively integrating local artificial intelligence systems into its arsenal. This is not about simple experimentation, but about full-scale preparation to use AI in real combat operations against cryptocurrency and fintech companies.
Offline AI as a New Weapon
Local environments based on the open platforms Ollama, GPT4All, and Msty have been discovered in the hackers' infrastructure. The key feature of these tools is full autonomy. They operate offline, using the Retrieval-Augmented Generation (RAG) method, which allows them to process requests and generate content without transmitting data to cloud services. This makes attacks virtually invisible to traditional traffic monitoring systems.
In addition, the group's arsenal includes libraries for embedding language models into their own software, as well as the Cursor AI programming assistant and speech recognition tools. Such a set indicates a systematic approach: the hackers are not just using ready-made solutions, but adapting them to their tasks—from automating phishing to analyzing vulnerabilities and accelerating the development of malicious code.
Next-Generation Phishing
Of particular concern is the use of generative AI to create phishing materials. Kimsuky is already generating documents that mimic official papers from Korean AI platforms for investments. These materials feature natural language, professional formatting, and a high degree of plausibility, which significantly increases the chances of successfully deceiving even experienced employees of crypto companies.
Apparently, the group has bet on using ready-made technologies rather than training their own models from scratch. This is a pragmatic approach that allows them to quickly scale attacks and reduce development costs.
My comment: Kimsuky's transition to local AI systems is a signal for the entire industry. Traditional protection methods based on network traffic analysis are becoming less effective. Crypto companies need to review their security protocols, paying special attention to behavioral analysis and training staff to recognize hyper-realistic phishing attacks. The fact that the group is already using AI to generate documents imitating legitimate platforms is just the tip of the iceberg. In the near future, we may see attacks that are fully automated and adapt in real time.