Crypto news

11.08.2026
04:46

Kimsuky arms itself with local AI: a new era of attacks on the crypto industry

The North Korean hacker group Kimsuky, known for its audacious operations against the financial sector, has made a qualitative leap in its tactics. My colleagues at the South Korean analytical center Genians have discovered that the attackers are actively integrating local artificial intelligence systems into their attack chains targeting cryptocurrency and financial companies.

Offline AI as a New Weapon

Full-fledged LLM environments running on open platforms such as Ollama, GPT4All, and Msty were found in the group's infrastructure. The key feature of these tools is complete autonomy. They operate offline and use the Retrieval-Augmented Generation method, allowing hackers to process data and generate content without sending requests to cloud services. This makes their operations virtually invisible to traditional monitoring systems.

In addition to ready-made solutions, Kimsuky's arsenal includes libraries and frameworks for embedding language models into their own malware, as well as the Cursor AI programming assistant and speech recognition tools. This indicates a systematic approach: the group is not just experimenting with the technology but is fundamentally restructuring its technical stack.

From Experiments to Combat Deployment

Genians analysts emphasize that Kimsuky has already passed the AI testing stage. We are now witnessing preparations for the full-scale integration of these technologies into real attack tools. The group's priority is to use ready-made, proven solutions rather than developing their own models from scratch—this saves resources and accelerates the attack cycle.

Of particular concern is the use of generative AI to create phishing materials. The group generates documents that mimic official papers from Korean investment AI platforms. These fakes feature flawless natural language and professional formatting, making them nearly indistinguishable from legitimate ones. The attacks target themes of digital assets, investment strategies, and fintech services.

Threat Context

Let me remind you that in August, the cryptocurrency exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group—a related structure that, according to investigations, is behind a series of high-profile hacks worth billions of dollars. This shows that North Korean cyber operations remain one of the main threats to the global crypto economy.

My analysis: Kimsuky's transition to local AI models is an alarming signal for the entire industry. Traditional detection methods based on analyzing network traffic or cloud interactions are becoming useless. Crypto companies urgently need to revise their security protocols, focusing on behavioral analysis and human factor verification, since phishing remains the primary vector of intrusion. We are entering an era where AI fights against AI, and the stakes in this battle are billions of dollars in user funds.