Kimsuky arms itself with local AI: a new era of attacks on the crypto industry

The North Korean hacker group Kimsuky, known for its audacious operations against the financial sector, has moved to a new level of technological evolution. My analysis of fresh data from South Korean cybersecurity experts shows that the attackers are actively integrating local artificial intelligence systems into their attack chains targeting cryptocurrency companies and fintech services.
Autonomous AI: A Weapon That Leaves No Traces
The key finding is the use of LLM environments based on Ollama, GPT4All, and Msty. These tools operate fully offline, which fundamentally changes the threat landscape. Instead of cloud services that can be tracked or intercepted, Kimsuky employs the Retrieval-Augmented Generation (RAG) method. This allows them to process queries and generate content without transmitting data to external data centers, making operations virtually invisible to traditional monitoring systems.
The group's infrastructure has revealed not only ready-made models but also libraries for embedding them into their own software, as well as the Cursor AI assistant for programming and speech recognition tools. This indicates a systematic approach: the hackers are not experimenting but building a pipeline for automating cybercrime.
From Tests to Combat Deployment
Particularly alarming is the fact that Kimsuky has already moved beyond the pilot project stage. This is not about scattered experiments but about preparing AI for real combat tasks: developing malware, analyzing large datasets, and automating attack vectors. Priority is given to using ready-made open-source technologies, which lowers the entry barrier and accelerates the cycle of creating new threats.
Separately, the phishing component deserves attention. The group generates documents about digital assets and investment strategies that mimic materials from a Korean AI investment platform. These emails feature natural language and professional formatting, making them nearly indistinguishable from legitimate correspondence. This is classic social engineering, but with a new level of execution quality.
Let me remind you that in August, the cryptocurrency exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group, underscoring the scale of the threat from North Korean groups. However, Kimsuky operates more subtly and technologically, which requires a reassessment of defense approaches.
My expert opinion: The use of local AI is not just a trend but a fundamental shift in APT group tactics. Offline generation of content and code deprives defenders of a key advantage—the ability to analyze attackers' cloud queries. Crypto companies should already be implementing behavioral analysis and multi-factor authentication, focusing on scenarios where an attack leaves no digital traces in traditional logs.