Crypto news

10.08.2026
23:51

North Korean hackers have armed themselves with local AI: a new threat for the crypto industry

Lazarus Group КНДР хакеры

An analysis of recent cyber threats shows that the North Korean group Kimsuky has advanced to a new level of technological sophistication, integrating local artificial intelligence systems into its offensive operations against cryptocurrency and financial structures. This is no longer experimentation but full-scale combat preparation that is fundamentally reshaping the threat landscape for digital assets.

Offline AI as a Next-Generation Weapon

During a technical examination of the group's infrastructure, local environments based on open-source LLM solutions, including Ollama, GPT4All, and Msty, were discovered. The key feature of these tools is their complete autonomy: they operate offline, using the Retrieval-Augmented Generation method, which allows them to process queries without transmitting data to cloud services. This makes attacks significantly more covert and complicates their detection.

In addition to language models, the hackers' arsenal includes libraries and frameworks for embedding AI into their own software, as well as a specialized programming assistant, Cursor, and speech recognition tools. Such a set indicates a systematic approach: AI is used not only for content generation but also for automating malware development and analyzing large data arrays.

Phishing with a Human Touch

Of particular concern is the quality of the phishing materials produced by the group. Generative AI is used to create documents about digital assets, investment strategies, and fintech services that are nearly indistinguishable from legitimate ones. Some samples mimicked documentation from Korean investment platforms, demonstrating natural language and professional formatting—this significantly increases the chances of successfully compromising even experienced users.

Notably, Kimsuky relies on ready-made technologies rather than training its own models from scratch. This pragmatic approach allows the group to quickly adapt and scale attacks without investing resources in costly research.

My expert assessment: The use of local AI is a strategic breakthrough in APT group tactics. The complete autonomy of such systems means that traditional detection methods based on network traffic analysis and cloud interactions become less effective. The industry needs to reassess its threat models and more actively implement behavioral analysis and AI-driven defense to counter this new generation of cyberattacks.