North Korean hackers have armed themselves with local AI: a new threat for the crypto industry

The North Korean hacker group Kimsuky, notorious for its cyberattacks on financial institutions, has reached a new level of technological evolution. My analysis of the latest intelligence shows that the attackers are actively integrating local artificial intelligence systems into their attack chains targeting cryptocurrency and fintech companies.
Offline AI as a New Weapon
Local large language model (LLM) environments, deployed on the open-source platforms Ollama, GPT4All, and Msty, have been discovered in the group's infrastructure. The key feature of these tools is their complete autonomy: they operate offline, using the Retrieval-Augmented Generation (RAG) method. This allows hackers to process sensitive data without the risk of leakage through cloud services, significantly complicating their tracking.
In addition, libraries and frameworks for embedding language models into their own malware, as well as the AI programming assistant Cursor and speech recognition tools, have been found in Kimsuky's arsenal. This is direct evidence that the group has moved from experimentation to the practical use of AI to automate exploit development and analyze large datasets.
Next-Generation Phishing
Of particular concern is the use of generative AI to create phishing documents. The generated materials mimic official documents from Korean investment platforms dedicated to digital assets and strategies. These emails feature flawless natural language and professional formatting, making them nearly indistinguishable from legitimate correspondence. It is extremely difficult for victims to spot the deception, which increases the effectiveness of the attacks.
Notably, Kimsuky is betting on ready-made technologies rather than training its own models from scratch. This is a pragmatic approach that allows for quickly scaling attacks and adapting to new defense mechanisms.
My expert assessment: The current trend is just the tip of the iceberg. The use of local LLMs opens up opportunities for hackers to create fully autonomous attack systems that can independently adapt to their environment. Crypto companies urgently need to review their security protocols, focusing on behavioral analysis and multi-factor authentication, to counter this new generation of threats. In August, the crypto exchange Bybit already filed a civil lawsuit against North Korea and the Lazarus Group, but legal proceedings are unlikely to stop this technological progress.