Crypto news

11.08.2026
01:31

North Korean hackers have armed themselves with local AI to attack the crypto industry.

Lazarus Group КНДР хакеры

Analysis of new data shows that the North Korean group Kimsuky, known for its cyber operations against the financial sector, has moved to a qualitatively new level of technological sophistication. Instead of traditional phishing schemes, hackers are now actively integrating local large language models (LLMs) into their attack chains targeting cryptocurrency exchanges and fintech companies.

During a technical investigation of the group's infrastructure, isolated AI environments based on open platforms—Ollama, GPT4All, and Msty—were discovered. The key feature of these tools is full autonomy: they operate offline, without contacting cloud servers, making traffic invisible to traditional monitoring systems. Of particular interest is the use of the Retrieval-Augmented Generation (RAG) method, which allows hackers to process stolen databases and internal company documents without the risk of leakage to the public cloud.

AI as a weapon: from reconnaissance to malicious code generation

In addition to the LLMs themselves, Kimsuky's arsenal includes libraries for embedding neural networks into their own software, as well as specialized developer tools—in particular, the AI assistant Cursor and speech recognition systems. This indicates that the group is not just experimenting with the technology but actively using it to automate the entire attack cycle: from vulnerability analysis to generating phishing emails and malicious scripts.

Notably, Kimsuky is betting on ready-made open-source models rather than training their own. This approach sharply lowers the entry barrier and accelerates adaptation to new defense methods. It has already been observed that AI-generated phishing documents mimic legitimate materials from Korean investment platforms—with natural language and professional formatting, making their detection by an average employee practically impossible.

Escalation of threats and industry response

This activity is unfolding against the backdrop of legal pressure on Pyongyang. Recall that in August, the crypto exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, which operates in conjunction with Kimsuky. However, judging by current data, North Korean hackers have no intention of winding down operations—they are only strengthening their technological base.

My comment: The use of local LLMs is a troubling signal for the entire industry. Previously, AI threats were considered the prerogative of states with developed IT infrastructure, but now any sufficiently motivated collective can arm itself with autonomous models. Crypto companies should reconsider their security protocols, focusing not only on network traffic analysis but also on behavioral anomalies within the systems themselves, where AI tools can operate undetected.