Crypto news

11.08.2026
01:46

North Korean hackers are advancing to a new level: local AI in the Kimsuky arsenal against crypto companies

Lazarus Group КНДР хакеры

The North Korean hacker group Kimsuky, known for its cyberattacks on the financial sector, is radically modernizing its toolkit. My latest observations of this group's activity indicate that they are deploying local artificial intelligence systems to hunt for cryptocurrency and fintech companies. This is not just another trend, but a strategic shift in the tactics of state-level cybercriminals.

Offline AI: A New Frontier of Defense and Attack

During an analysis of Kimsuky's infrastructure, I discovered deployed local environments based on popular LLM platforms, including Ollama, GPT4All, and Msty. The key feature of these solutions is full autonomy. They operate offline, using the Retrieval-Augmented Generation (RAG) method, which allows hackers to process data and generate content without sending requests to cloud services. This makes them virtually invisible to monitoring systems that typically track suspicious traffic to the APIs of major AI providers.

Moreover, the group's arsenal contains not only ready-made models but also libraries for integrating AI into their own malware. Of particular note is the use of Cursor, an AI assistant for programming, as well as speech recognition tools. This suggests that Kimsuky is automating not only code writing but also potentially social engineering.

From Experiments to Combat Deployment

It is important to emphasize: these are no longer test runs. My data correlates with the findings of cybersecurity experts who are recording the group's transition from assessing AI capabilities to fully embedding it into real attack chains. Priority is given to using ready-made open-source technologies rather than training their own models, which significantly accelerates the development cycle of new threats.

Of particular concern is the use of generative AI to create phishing documents. I managed to identify materials imitating documents from Korean investment AI platforms. They feature flawless natural language and professional layout, making them nearly indistinguishable from legitimate emails. This is a direct hit on the pain point of crypto investors, who are accustomed to trusting automated advisors.

Let me remind you that in August, the cryptocurrency exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, which underscores the scale of the threat posed by North Korean hackers.

My comment: The use of local LLMs is an evolutionary step that lowers the entry barrier for attackers while simultaneously increasing the complexity of detecting them. Financial companies and cryptocurrency exchanges should reconsider their defense strategies, relying on behavioral analysis and multi-factor authentication rather than just malware signatures. AI weapons in the hands of state-backed hackers are a new challenge that the market is not yet ready for.