Crypto news

11.08.2026
00:31

Kimsuky masters offline AI: a new attack vector on the crypto industry

Lazarus Group КНДР хакеры

An analysis of cyberspace has revealed a troubling trend: the North Korean group Kimsuky, known for its attacks on the financial sector, has shifted to using local large language models (LLMs) to enhance the effectiveness of its operations against cryptocurrency and financial companies. This is not just experimentation, but a systemic integration of AI into combat tools.

Local environments based on Ollama, GPT4All, and Msty have been discovered in the attackers' infrastructure. The key feature of these solutions is full autonomy. They operate offline, supporting the Retrieval-Augmented Generation (RAG) method, which allows processing requests without transmitting data to cloud services. This is critical for maintaining operational security: no traces of activity leave the confines of the hacker-controlled infrastructure.

AI Arsenal for Cybercrime

In addition to LLMs, the group's arsenal includes libraries and frameworks for embedding language models into their own software, as well as the Cursor AI assistant for programming and speech recognition tools. This set indicates a comprehensive approach: AI is used not only for content generation, but also for automating malicious code development, analyzing large datasets, and coordinating attacks.

Apparently, Kimsuky has already passed the testing stage. This is about preparing for the real-world application of AI in combat conditions. Priority is given to using ready-made open-source technologies rather than building custom models from scratch—this saves resources and accelerates deployment.

Next-Generation Phishing

Of particular note is the use of generative AI to create phishing materials. The group generates documents about digital assets, investment strategies, and fintech services. Some of them mimic official papers from a Korean AI investment platform, featuring natural language and professional formatting. This makes phishing nearly indistinguishable from legitimate correspondence, significantly increasing the chances of success.

Recall that in August, the crypto exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group. This is just the tip of the iceberg—Kimsuky operates in parallel and, apparently, is technologically evolving faster than many private security organizations.

My conclusion: The use of local AI is a strategic breakthrough for APT groups. It removes the main limitation—dependence on external services that can be tracked. The industry needs to rethink threat models: protection against simple phishing campaigns is no longer relevant; we are now dealing with adaptive, self-learning systems that can generate convincing attacks in real time. This requires crypto companies to implement AI-based defenses, not just manual checks.