Kimsuky takes cyberattacks to a new level: North Korean hackers have armed themselves with local AI

The North Korean hacking group Kimsuky, known for its attacks on the financial sector, is radically modernizing its arsenal. Instead of traditional phishing schemes and exploits, the attackers are now actively integrating local artificial intelligence systems into their operations against cryptocurrency and financial companies. This is not just experimentation—it is a transition to autonomous and highly adaptive cyber threats of a new generation.
Offline AI: A New Frontier of Defense and Attack
My analysis shows that Kimsuky has deployed full-fledged LLM environments based on open platforms like Ollama, GPT4All, and Msty. The key feature is that these systems operate completely offline. Using the Retrieval-Augmented Generation (RAG) method, hackers can process and generate data without sending requests to cloud services, making them virtually invisible to traditional monitoring systems and sandboxes.
The group's infrastructure contains not only ready-made models but also libraries for embedding language algorithms into their own malware. Of particular note is the use of Cursor—an AI assistant for programming—as well as speech recognition tools. This indicates that Kimsuky is automating not only code writing but also social engineering, making its attacks more personalized and convincing.
From Tests to Combat Deployment
It is important to emphasize that the group has already moved beyond the "trial and error" stage. Based on the collected data, Kimsuky is transitioning to the practical integration of AI into real attack chains. Priority is given to using ready-made technologies rather than training their own models from scratch—this saves resources and allows for rapid adaptation to new defensive mechanisms.
Of particular concern is the quality of the generated content. AI-crafted phishing documents mimic official papers from Korean investment platforms, including materials on digital assets and fintech services. They feature natural language and professional formatting, making them nearly indistinguishable from legitimate ones. This confirms that the threat is shifting toward highly precise, targeted attacks where the human factor becomes the primary vulnerability.
My expert opinion: the integration of local LLMs into Kimsuky's arsenal is an alarming signal for the entire industry. Traditional detection methods based on network traffic analysis or cloud requests are becoming useless. Crypto companies need to reassess their threat models, focusing on behavioral analysis and training employees to recognize hyper-realistic phishing attacks, especially in the context of growing pressure on digital assets.