Crypto news

11.08.2026
00:51

Kimsuky deploys local AI systems in attacks on the crypto industry — a new level of threat

Lazarus Group КНДР хакеры

The North Korean hacker group Kimsuky, known for its cyber operations against the financial sector, has made a qualitative leap in tactics: it now actively uses local artificial intelligence models to attack cryptocurrency and fintech companies. This is the conclusion analysts reached during an in-depth study of the attackers' infrastructure.

Offline AI as a New Weapon

Kimsuky's arsenal includes local LLM environments based on open platforms — Ollama, GPT4All, and Msty. The key feature of these tools is full autonomy: they operate offline, and the Retrieval-Augmented Generation method allows processing requests without transmitting data to cloud services. This makes attacks nearly invisible to traditional monitoring systems that focus on tracking network interactions with external AI providers.

In addition to language models, the group's infrastructure contains libraries and frameworks for integrating AI into its own malware, the Cursor programming assistant, and speech recognition tools. Such a set indicates a systematic approach: Kimsuky is not experimenting but preparing full-scale AI integration into its attack chains.

Phishing at a New Level

Of particular concern is the use of generative AI to create phishing materials. The group generates documents about digital assets, investment strategies, and fintech services, with some of them imitating official papers from a Korean AI investment platform. The quality of execution — natural language and professional formatting — makes such emails nearly indistinguishable from legitimate ones.

In my assessment, this is a turning point in cyber warfare. The shift to local LLMs means that traditional detection methods based on analyzing network traffic to known AI services are losing effectiveness. The industry urgently needs to adapt defensive mechanisms, focusing on behavioral analysis and content verification at the end-user level. Kimsuky is clearly betting on ready-made technologies rather than developing its own models, which accelerates their attack cycle and lowers the entry barrier for other malicious actors.