Crypto news

11.08.2026
08:10

North Korean hackers from Kimsuky have armed themselves with local AI for attacks on the crypto industry.

Lazarus Group КНДР хакеры

Analysts at the South Korean company Genians have recorded a worrying trend: the Kimsuky group, operating in the interests of North Korea, has moved from experimenting with artificial intelligence to its practical application in cyberattacks on cryptocurrency and financial organizations. This is not just another leak, but a systemic shift in the tactics of North Korean hackers, who are actively integrating local language models into their arsenal.

Offline Tools: A New Degree of Stealth

Local LLM environments based on the open platforms Ollama, GPT4All, and Msty have been discovered in Kimsuky's infrastructure. The key feature of these solutions is full autonomy. Using the Retrieval-Augmented Generation (RAG) method, hackers process requests without accessing cloud services, which minimizes the risk of detection and data interception. This means that North Korean operatives can analyze stolen information and prepare attacks in a fully isolated environment.

In addition, the group's infrastructure contains libraries and frameworks for embedding language models into their own software, as well as the Cursor AI assistant for programming and speech recognition tools. This combination indicates that Kimsuky is not just using AI to generate texts, but is building a full automation pipeline—from data analysis to writing malicious code.

Next-Generation Phishing

Of particular note is the use of generative AI to create phishing materials. According to my research, the group generates documents about digital assets, investment strategies, and fintech services that are almost indistinguishable from legitimate ones. Some of these materials imitated documents from a Korean AI investment platform—with natural language and professional formatting. This is no longer mass mailing, but targeted, high-quality phishing campaigns designed to deceive even experienced professionals.

Genians emphasizes that Kimsuky is no longer testing AI but preparing it for combat use. Priority is given to using ready-made technologies rather than training their own models, which allows the group to scale attacks quickly. I recall that in August, the Bybit cryptocurrency exchange already filed a civil lawsuit against North Korea and the Lazarus Group, highlighting the growing threat from North Korean hackers.

My expert assessment: The use of local LLMs is an evolutionary step that makes Kimsuky's attacks significantly more resilient to traditional cybersecurity methods. Financial and crypto companies should reconsider their security protocols, paying particular attention to behavioral analysis and anomaly monitoring, rather than just signatures of known threats.