North Korean hackers Kimsuky have armed themselves with local AI to hunt for crypto companies.

An analysis of the infrastructure of the North Korean group Kimsuky has revealed a troubling trend: hackers are actively integrating local large language models (LLMs) into their attack chains targeting cryptocurrency and financial organizations. This is no longer experimentation but systematic preparation for a new generation of cyber threats.
Offline AI as a Weapon
During technical reconnaissance, I managed to discover that Kimsuky has deployed environments based on Ollama, GPT4All, and Msty. The key feature of these tools is full autonomy. They operate offline, using the Retrieval-Augmented Generation (RAG) method, which allows processing requests without transmitting data to cloud services. This is critically important for attackers: in this way, they avoid exposing their operational details and traces through public APIs.
The group's arsenal also includes libraries and frameworks for embedding language models into their own software, the Cursor programming assistant, and speech recognition tools. Such a set indicates that AI is being used not pointwise but as a foundation for automating the entire attack cycle—from writing malicious code to analyzing data and generating phishing scenarios.
Next-Generation Phishing
Special attention deserves the use of generative AI to create phishing documents. Kimsuky continues to generate convincing materials about digital assets, investment strategies, and fintech services. Some of them imitate documents from a Korean AI investment platform, featuring natural language and professional formatting. These are no longer just emails with errors but high-quality forgeries capable of deceiving even experienced employees.
Notably, the group is betting on ready-made technologies rather than training its own models. This lowers the entry barrier and accelerates adaptation to new defensive measures. Let me remind you that in August, the cryptocurrency exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, underscoring the scale of the threat posed by North Korean hackers.
My conclusion: The use of local LLMs is a strategic shift in Kimsuky's tactics. The industry must prepare for phishing to become even more personalized and malware more adaptive. Companies should reconsider their security protocols, paying particular attention to behavioral analysis and training employees to recognize synthetic but impeccably crafted threats.