Kimsuky raises the bar: North Korean hackers arm themselves with local AI for strikes on the crypto industry

A troubling trend is brewing in the world of cyber threats for the cryptocurrency sector. My analysis of recent data indicates that the North Korean group Kimsuky, known for its espionage operations, is radically modernizing its arsenal. This is not just about new malware, but about the strategic integration of local artificial intelligence systems into its attack chains.
During a technical analysis of the group's infrastructure, I discovered deployed local environments of large language models (LLMs) built on open-source solutions such as Ollama, GPT4All, and Msty. The key point here is the use of the Retrieval-Augmented Generation (RAG) method. This means hackers can process stolen data and generate content entirely offline, eliminating traffic leakage to cloud services, which significantly complicates their detection.
From experiments to combat deployment
Particularly noteworthy is the fact that the found tools include not only the models themselves, but also libraries for integrating them into custom software, as well as an AI assistant for programming called Cursor and speech recognition modules. This indicates that Kimsuky has moved from the technology testing stage to full-scale attack automation. They are not spending resources on training their own models from scratch, but are effectively adapting ready-made open-source solutions, which accelerates their malware development and data analysis cycle.
Special attention deserves the use of generative AI to create phishing materials. Generated documents imitating investment strategies and fintech services, including a Korean AI investment platform, exhibit a high degree of realism. Natural language and professional design make these traps extremely dangerous for cryptocurrency company employees, increasing the chances of successful compromise.
My comment: This evolution of Kimsuky is a warning signal for the entire industry. The use of local LLMs lowers the entry barrier for sophisticated attacks and makes them less predictable. Cryptocurrency companies urgently need to review their security protocols, focusing on behavioral analysis and training staff to recognize hyper-realistic AI-generated phishing schemes. Traditional defense methods may already prove ineffective here.