Crypto news

10.08.2026
22:11

North Korean hackers have armed themselves with local AI: a new era of attacks on the crypto industry

Lazarus Group КНДР хакеры

A landmark shift has occurred in the world of cybersecurity: the North Korean hacker group Kimsuky, known for its audacious operations against the financial sector, has moved to a new level of technological sophistication. My analysis of the latest data shows that these attackers are actively integrating local artificial intelligence systems into their attack chains targeting cryptocurrency companies and fintech platforms.

Offline AI as a New Generation Weapon

Local environments based on Ollama, GPT4All, and Msty have been discovered in Kimsuky's infrastructure. These are not just experiments—this is a strategic choice. By operating offline and using the Retrieval-Augmented Generation method, hackers completely eliminate data leaks through cloud services, making their operations virtually invisible to traditional monitoring systems. This approach allows them to process confidential information about targets without the risk of interception.

Of particular concern is the presence of libraries for embedding language models into their own software, as well as tools like Cursor and speech recognition systems. This indicates that Kimsuky is not just testing AI but preparing it for full-scale combat use: from automating phishing to analyzing vulnerabilities in code.

Phishing That Is Impossible to Distinguish from Reality

Special attention should be paid to the use of generative AI to create phishing documents. This is not about template emails with errors, but professionally crafted materials imitating documents from Korean investment platforms. The natural language and flawless structure of such files make them deadly dangerous for cryptocurrency company employees, who may mistake them for legitimate correspondence from partners.

The group's priority is using ready-made open-source models rather than training their own. This makes the process cheaper and faster, allowing quick adaptation to new targets.

My expert assessment: This move by Kimsuky is just the tip of the iceberg. In the next 12-18 months, we will see the widespread proliferation of such tactics among other APT groups. The crypto industry urgently needs to review its security protocols, betting on behavioral analysis and multi-factor authentication, since traditional antivirus solutions are no longer capable of countering AI-assisted attacks of this level.