North Korean hackers are integrating local AI models into attacks on the crypto industry.

Analysis of recent cyber threats shows that the North Korean group Kimsuky has moved from experimenting with artificial intelligence to practical application of local LLM systems in its operations against cryptocurrency and financial organizations. This is confirmed by technical research that I managed to review as part of threat monitoring.
Offline tools as new weapons
Isolated environments based on Ollama, GPT4All, and Msty have been discovered in the attackers' infrastructure. The key feature of these solutions is full autonomy: they operate without cloud services, which eliminates data leakage through third-party channels. Retrieval-Augmented Generation technology allows hackers to process sensitive information without the risk of interception.
In addition, the group's arsenal includes libraries for integrating language models into their own software, the Cursor programming tool, and speech recognition systems. This indicates serious engineering effort: Kimsuky is not just testing AI but embedding it into real combat scenarios—from generating malicious code to automating phishing campaigns.
Next-generation phishing
Of particular concern is the use of generative AI to create convincing phishing materials. Documents imitating Korean investment platforms look professional and natural—with proper structure, terminology, and formatting. This poses a serious challenge to filtering systems that focus on detecting template-based errors.
Unlike many other groups, Kimsuky relies on ready-made open-source models rather than training their own. This approach accelerates adaptation to new defense mechanisms and lowers the entry barrier for less technically skilled group members.
My expertise: Current dynamics confirm that AI is becoming an integral part of cybercrime. For crypto companies, this means the need to rethink security systems: traditional antivirus solutions are no longer effective against attacks where every phishing document is unique and crafted for a specific target. Investment in behavioral analysis and staff training is no longer an option but a mandatory condition for survival in the current threat environment.