Crypto news

10.08.2026
21:31

Kimsuky masters offline AI: a new era of cyberattacks on the crypto industry

Lazarus Group КНДР хакеры

The North Korean hacker group Kimsuky, known for its attacks on the financial sector, has reached a new level of technological sophistication. My analysis shows that the attackers are actively integrating local artificial intelligence systems into their operations against cryptocurrency companies and fintech platforms. This is not a simple experiment, but a systematic deployment of AI into combat tools.

Offline LLMs as a Weapon

During my investigation of the group's infrastructure, I discovered deployed local environments based on Ollama, GPT4All, and Msty. The key feature of these tools is full autonomy. They operate offline, using the Retrieval-Augmented Generation (RAG) method, which allows them to process requests without transmitting data to cloud services. This is a critical point: traditional detection methods based on network traffic monitoring are powerless here.

In addition to LLM environments, the group's arsenal includes libraries and frameworks for embedding language models into their own software, as well as the Cursor AI programming assistant and speech recognition tools. This set indicates a serious intention to automate the entire attack cycle—from generating malicious code to analyzing the data obtained.

Next-Generation Phishing

Of particular concern is the use of generative AI to create phishing materials. The discovered documents mimic official paperwork from a Korean AI investment platform. They feature natural language and professional formatting, making them nearly indistinguishable from legitimate ones. These are not just emails asking to "reset your password"—they are high-quality forgeries targeting employees of crypto exchanges and investment funds.

It is worth noting that the group relies on off-the-shelf technologies rather than training their own models. This is a pragmatic approach that reduces development time and lowers the risk of detection.

My commentary: Kimsuky's shift to offline AI is a wake-up call for the entire industry. Traditional security systems focused on cloud-based threats are not prepared for attacks that are completely isolated from the network. Crypto companies need to reconsider their defense strategies, paying special attention to behavioral analysis and counterparty verification at the human factor level. The Bybit lawsuit against North Korea is just the tip of the iceberg, and we will see new lawsuits as the scale of this threat is revealed.