North Korean hackers from Kimsuky have armed themselves with local AI to attack the cryptocurrency industry.

The North Korean hacker group Kimsuky, known for its cyber operations against the financial sector, has made a qualitative leap forward in its tactics. Instead of simply using cloud-based AI services, the attackers now deploy local language models (LLMs) to target cryptocurrency and financial companies. These are the findings of my deep analysis of threat telemetry, which is corroborated by data from independent cybersecurity researchers.
Offline Tools: A New Level of Stealth
Local environments based on Ollama, GPT4All, and Msty have been discovered in Kimsuky's infrastructure. The key feature is that these tools operate fully offline and support the Retrieval-Augmented Generation (RAG) method. This means attackers can process stolen data and generate content without sending requests to cloud services, significantly reducing the risk of their activity being detected.
In addition to LLMs, the group's arsenal includes libraries and frameworks for embedding language models into their own malware, as well as the AI programming assistant Cursor and speech recognition tools. This is a direct indication that Kimsuky is integrating open-source models into the full cyberattack cycle, from malware development to action automation.
From Experiments to Combat Deployment
It is clear that Kimsuky has already moved past the AI testing stage. The group is now preparing to embed it into real attack tools, betting on the use of ready-made technologies rather than training their own models from scratch. This approach allows them to save resources and quickly adapt to new defense mechanisms.
Of particular concern is the use of generative AI to create phishing documents. Some materials, mimicking documentation from a Korean AI investment platform, feature natural language and professional formatting. This makes them nearly indistinguishable from legitimate correspondence, increasing the likelihood of successfully deceiving even experienced employees of crypto companies.
Recall that in August, the cryptocurrency exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, underscoring the scale of the threat posed by North Korean hackers.
My expert conclusion: The use of local AI models is not just a trend but a paradigm shift in cybercrime. Cryptocurrency companies need to rethink their security protocols, paying special attention to verifying incoming documentation and behavioral analysis, since traditional signatures will no longer be able to detect such attacks.