Kim Sung reaches a new level: North Korean hackers have armed themselves with local AI for strikes on the crypto industry.

The North Korean hacker group Kimsuky, known for its years-long cyber operations against the financial sector, is radically modernizing its arsenal. Instead of traditional phishing schemes and manual vulnerability analysis, the attackers are now actively deploying local artificial intelligence systems to target cryptocurrency companies and fintech platforms. This is confirmed by data from an independent analysis of the group's infrastructure conducted by cybersecurity experts.
During the technical investigation, it was discovered that Kimsuky has deployed offline environments based on popular open-source LLM models, including Ollama, GPT4All, and Msty. The key feature of these solutions is full autonomy. They operate without connecting to cloud services, allowing hackers to process data through the Retrieval-Augmented Generation mechanism without risking exposure of their operations through external requests. This approach makes their activity virtually invisible to traditional traffic monitoring systems.
The group's arsenal also includes libraries and frameworks for integrating language models into their own malware, the programming AI assistant Cursor, and speech recognition tools. This indicates that North Korean specialists are not just experimenting with the technology but are preparing it for combat use. They are systematically embedding AI into exploit development processes, attack automation, and analysis of large volumes of stolen data.
Of particular concern is the use of generative AI to create phishing materials. The generated documents, imitating reports on digital assets and investment strategies, are crafted so convincingly that they replicate the style of legitimate Korean AI investment platforms. Natural language and professional formatting make such emails nearly indistinguishable from real ones, which multiplies the chances of successful social engineering.
It is telling that Kimsuky is betting on ready-made open-source technologies rather than training its own models. This is a pragmatic and dangerous approach that allows for rapid scaling of attacks without significant resource costs. Recall that in August, the cryptocurrency exchange Bybit already filed a civil lawsuit against North Korea and the Lazarus Group, underscoring the growing legal and operational threat posed by North Korean hackers.
My comment: Kimsuky's shift to local AI models is an alarming signal for the entire industry. Offline LLMs strip defenders of a key advantage—the ability to intercept requests to cloud AI services. Crypto companies should reconsider their security protocols, focusing on behavioral analysis and verification of document origins rather than relying solely on technical indicators of compromise.