Crypto news

11.08.2026
02:56

Kimsuks reaches a new level: North Korean hackers arm themselves with local AI for strikes on the crypto industry

Lazarus Group КНДР хакеры

The world of cryptocurrencies is facing a new threat that is changing the rules of the game in cybersecurity. The Kimsuky group, operating in the interests of North Korea, has shifted from experimenting with artificial intelligence to actively applying it in real-world attacks on financial and cryptocurrency companies. This is no longer just hackers with phishing campaigns—this is an adversary armed with advanced technological tools.

During an analysis of the attackers' infrastructure, I managed to identify the use of local LLM environments based on Ollama, GPT4All, and Msty. The key feature of these solutions is full autonomy. They operate offline, supporting the Retrieval-Augmented Generation method, which allows processing requests without transmitting data to cloud services. This makes attacks virtually invisible to traditional monitoring systems that are accustomed to tracking suspicious network traffic.

From phishing to automated operations

The group's arsenal includes not only language models but also a whole set of tools for integrating them into their own software. Of particular note is the use of Cursor—an AI assistant for programming—as well as speech recognition systems. This indicates that Kimsuky is building a full-fledged attack automation pipeline, where AI is used for writing malicious code, analyzing large volumes of data, and coordinating actions.

It is telling that the group relies on ready-made open-source technologies rather than training their own models. This is a pragmatic approach that allows them to quickly scale attack capabilities without significant resource expenditures. It is also worth noting that phishing materials created using generative AI have become so high-quality that they mimic documents from a Korean AI investment platform with professional formatting and natural language. This is a serious challenge for spam filtering systems and employee training.

The situation is compounded by the fact that in August, the cryptocurrency exchange Bybit already filed a civil lawsuit against North Korea and the Lazarus Group, highlighting the scale of the threat posed by North Korean hackers. However, in my view, the industry needs to reconsider its approaches to defense: traditional methods based on network anomaly analysis are becoming ineffective against autonomous AI systems. We need new strategies, including behavioral analysis and proactive threat hunting within the perimeter, otherwise we risk falling behind an adversary that is already using AI as its primary weapon.