North Korean hackers have armed themselves with local AI: a new era of attacks on the crypto industry

The North Korean hacking group Kimsuky, known for its audacious operations against the financial sector, has moved to a new level of technological sophistication. An analysis conducted by my colleagues at the South Korean research center Genians has uncovered a troubling trend: the attackers are actively integrating local artificial intelligence systems into their attack chains targeting cryptocurrency and fintech companies.
The group's infrastructure contains full-fledged large language model (LLM) environments deployed on open-source platforms such as Ollama, GPT4All, and Msty. The key feature of these tools is complete autonomy. They operate offline using the Retrieval-Augmented Generation (RAG) method, allowing them to process queries without transmitting data to cloud services. This makes them virtually invisible to traditional network traffic monitoring systems.
Practical Application of AI in Cybercrime
In addition to the models themselves, Kimsuky's arsenal includes libraries and frameworks for embedding AI into their own malware. Particular attention is drawn to the use of Cursor, an AI programming assistant, as well as speech recognition tools. This indicates that the hackers are not just experimenting with the technology but are building a pipeline to automate their operations.
Genians emphasizes that this is not about test runs. Kimsuky has moved to the practical phase, embedding open-source LLMs into real tools for malware development, vulnerability analysis, and attack automation. The strategy is clearly focused on leveraging ready-made solutions rather than costly training of proprietary models, allowing the group to rapidly scale its capabilities.
Next-Generation Phishing
Special attention deserves the use of generative AI to create phishing materials. The generated documents mimic official paperwork from a Korean AI investment platform, featuring natural language and professional formatting. These materials cover topics such as digital assets, investment strategies, and fintech services, making them highly convincing to victims.
I should note that tensions around North Korean hackers peaked in August when the cryptocurrency exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group.
My analysis: The use of local LLMs is a turning point. Moving away from cloud services deprives law enforcement of the ability to intercept hackers' queries, while phishing automation lowers the barrier to entry for large-scale attacks. Crypto companies will need to rethink their threat models, paying special attention not only to perimeter defense but also to combating AI-enhanced social engineering.