North Korean hackers have armed themselves with local AI for attacks on the crypto industry.

The North Korean hacker group Kimsuky, known for its audacious operations against the financial sector, has moved to a new level of technological evolution. My colleagues in cybersecurity have recorded that the attackers are actively integrating local large language models (LLMs) into their attack chains targeting cryptocurrency companies and fintech services.
Offline AI as a New Weapon
Environments based on Ollama, GPT4All, and Msty have been discovered in Kimsuky's infrastructure. The key feature of these tools is full autonomy. They operate offline using the Retrieval-Augmented Generation method, allowing hackers to process data and generate content without sending requests to cloud services. This not only speeds up operations but also makes them virtually invisible to monitoring systems that are accustomed to catching traces of interaction with external APIs.
In addition to the models themselves, the group's arsenal includes libraries for embedding AI into their own software, as well as the Cursor programming assistant and speech recognition tools. This indicates that Kimsuky is not just experimenting with the technology but is systematically integrating it into the processes of developing malicious code, data analysis, and attack automation.
From Tests to Combat Deployment
Notably, the group is betting on ready-made open-source solutions rather than training their own models. This approach allows them to save resources and quickly adapt to new tasks. In my assessment, we are witnessing a transition from the pilot project stage to full-fledged combat use of AI in cybercrime.
Of particular concern is the use of generative AI to create phishing documents. The attackers generate materials about digital assets, investment strategies, and fintech services that look alarmingly natural. Some of them mimic documentation from a Korean AI investment platform—with professional formatting and flawless language, which increases the chances of deceiving even experienced employees.
Let me remind you that in August, the crypto exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, highlighting the seriousness of the threat posed by North Korean hackers.
My verdict: The integration of local LLMs is a troubling signal for the entire industry. Traditional detection methods based on network traffic analysis are becoming useless. Crypto companies should reconsider their security protocols, prioritizing behavioral analysis and training employees to recognize AI-generated phishing attacks.