Crypto news

11.08.2026
04:26

Kimsuky deploys local AI models in cyberattacks on the crypto industry

Lazarus Group КНДР хакеры

The North Korean hacker group Kimsuky, known for its attacks on the financial sector, has shifted to using local artificial intelligence systems to breach cryptocurrency companies. This discovery was made by Genians cybersecurity experts during an analysis of the attackers' infrastructure.

Offline AI as a New Weapon

Kimsuky's arsenal includes local environments for large language models (LLMs) built on platforms such as Ollama, GPT4All, and Msty. The key feature of these tools is their complete autonomy: they operate without connecting to cloud services, allowing hackers to process data through Retrieval-Augmented Generation (RAG) without the risk of traffic interception or exposing their operations.

Additionally, the group's infrastructure contains libraries and frameworks for integrating language models into their own malware, as well as the Cursor AI programming assistant and speech recognition tools. This indicates a systematic approach: Kimsuky is not just experimenting with the technology but actively embedding it into their attack chains.

Automation and Next-Generation Phishing

Genians analysts emphasize that the group relies on ready-made open-source solutions rather than training their own models. This pragmatism accelerates malware development and automates the collection and analysis of target data.

Of particular note is the use of generative AI to create phishing materials. Kimsuky generates documents about digital assets, investment strategies, and fintech services that mimic official papers from a Korean AI investment platform. These emails feature natural language and professional formatting, making them nearly indistinguishable from legitimate messages.

Recall that in August, the cryptocurrency exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, highlighting the scale of the threat posed by North Korean hackers.

My comment: The use of local LLMs is a troubling signal for the entire crypto industry. Previously, phishing attacks could be identified by language errors or unnatural phrasing, but now AI neutralizes these markers. Companies need to rethink their security protocols, focusing on behavioral analysis and multi-factor authentication rather than simple email filtering.