Kimsuky integrates local AI models into cyberattacks on the crypto industry

The North Korean hacker group Kimsuky, known for its attacks on the financial sector, has shifted to using local artificial intelligence systems to hack cryptocurrency companies. This is the conclusion reached by cybersecurity experts from South Korea after analyzing the attackers' infrastructure.
Local LLMs as a New Weapon
During the technical analysis, it was discovered that Kimsuky has deployed offline environments based on open-source language models, including Ollama, GPT4All, and Msty. A key feature of these tools is their operation without cloud services, which allows the use of the Retrieval-Augmented Generation (RAG) method. This means attackers can process data and generate content without sending requests to external networks, significantly complicating their tracking.
In addition, the group's arsenal includes libraries and frameworks for integrating LLMs into their own software, as well as the Cursor AI programming assistant and speech recognition tools. This points to a systematic approach: open-source models are embedded directly into the development process of malicious code, data analysis, and attack automation.
From Experiments to Real Operations
It is important to emphasize that this is not about testing technologies, but about full-scale combat integration. Kimsuky clearly prioritizes the use of ready-made AI solutions rather than training its own models, which reduces preparation time for operations and lowers costs. Of particular concern is the use of generative AI to create phishing materials: documents about digital assets, investment strategies, and fintech services look so natural that they mimic official documents from Korean AI investment platforms with professional formatting and impeccable language.
Recall that in August, the cryptocurrency exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, highlighting the growing legal and operational activity surrounding North Korean hackers.
My expert perspective: The use of local LLMs is a logical step in the evolution of cyber threats. The shift to offline models makes attacks less visible to traditional monitoring systems, and the quality of phishing reaches a new level. Crypto companies should reconsider their security protocols, relying not only on technical barriers but also on training employees to recognize even the most realistic AI-generated emails.