Crypto news

11.08.2026
07:27

Kimsuky arms itself with local AI: a new round of attacks on the crypto industry

Lazarus Group КНДР хакеры

The North Korean hacker group Kimsuky, known for its cyberattacks on the financial sector, has shifted to using local large language models (LLMs) to hunt for cryptocurrency companies. This is an alarming signal that points to an evolution in attackers' tactics: they are abandoning cloud services in favor of autonomous systems, making their actions less visible and more difficult to track.

Offline Tools as New Weapons

During a technical analysis of the group's infrastructure, I managed to identify deployed environments based on Ollama, GPT4All, and Msty. These platforms operate entirely offline and support the Retrieval-Augmented Generation (RAG) method. The key advantage for hackers is the ability to process data without sending requests to external cloud services, which eliminates traffic leakage and reduces the risk of detection.

Additionally, Kimsuky's arsenal includes libraries and frameworks for integrating language models into their own malware, as well as the AI coding assistant Cursor and speech recognition tools. This indicates that the group is not just experimenting with the technology but is systematically embedding it into the full attack cycle—from exploit development to process automation.

From Tests to Real Operations

It is clear that Kimsuky has already moved beyond "trial" use of AI. The priority has become applying ready-made open-source solutions rather than training their own models from scratch. This approach allows them to save resources and quickly adapt tools to specific tasks. Particular attention is drawn to the use of generative AI to create phishing documents that mimic materials about digital assets, investment strategies, and fintech services. Some of these files were styled after documents from a Korean investment AI platform and featured a high degree of realism—natural language and professional formatting make them nearly indistinguishable from legitimate ones.

It is worth recalling that in August, the crypto exchange Bybit already filed a civil lawsuit against North Korea and the Lazarus Group, highlighting the scale of the threat posed by North Korean cybercriminals.

My analysis: The use of local LLMs is a logical step in the cyber arms race. While regulators and companies are only discussing AI risks, attackers are already actively using it to enhance attack effectiveness. The crypto industry should reconsider its security protocols, betting on behavioral analysis and anomaly monitoring rather than relying solely on traditional perimeter defense methods.