Kimsuks reaches a new level: North Korean hackers integrate local AI into attacks on the crypto industry

The Kimsuky group, operating in the interests of North Korea, is radically modernizing its arsenal. Instead of traditional phishing schemes and vulnerability exploitation, hackers are now actively deploying local artificial intelligence systems to target cryptocurrency exchanges and financial institutions. This is no longer just experimentation, but a full-fledged combat integration of AI into cybercriminal infrastructure.
Offline AI as a New Weapon
My analysis shows that Kimsuky has deployed local environments based on Ollama, GPT4All, and Msty. The key point is that these LLMs operate fully offline, using the Retrieval-Augmented Generation (RAG) method. This allows hackers to process sensitive data without the risk of leakage to cloud services, making their operations significantly more covert and difficult to track.
The group's infrastructure also contains libraries and frameworks for embedding language models into their own software, the Cursor AI programming assistant, and speech recognition tools. Such a set indicates that Kimsuky is automating not only the writing of malicious code, but also the analysis of large volumes of data, as well as the coordination of attacks.
Next-Generation Phishing
Of particular concern is the use of generative AI to create phishing documents. Some of the materials, imitating documentation from a Korean AI investment platform, feature natural language and professional formatting. This breaks the stereotype of "clumsy" letters from North Korean hackers—now the victim receives a convincing, well-crafted document that is difficult to distinguish from a legitimate one.
The group is no longer "trying out" AI, but preparing it for real-world use in attack tools. Priority is given to using ready-made technologies rather than training their own models—this saves resources and speeds up deployment.
My conclusion: the integration of local LLMs into Kimsuky's attacks is a troubling signal for the entire crypto industry. Traditional detection methods based on analyzing network traffic or cloud requests are becoming useless. Companies need to rethink their defense strategies, focusing on behavioral analysis and monitoring of internal processes, rather than just perimeter security. Bybit has already filed a lawsuit against North Korea and the Lazarus Group, but legal proceedings will not stop this new wave of threats.