AI in Pyongyang's Service: The Kimsuky Group Masters Generative Models for Cyber Warfare
The North Korean hacker group Kimsuky, operating under the auspices of the Reconnaissance General Bureau of the DPRK, has moved from simply using generative AI to create phishing documents to systematically studying the possibilities of integrating artificial intelligence into its attack chains. These are no longer scattered experiments, but a fully deliberate strategy aimed at automating and increasing the effectiveness of cyber operations.
Local AI as a tool of conspiracy
During an analysis of the attackers' infrastructure, I was able to establish that Kimsuky is actively testing local tools for running AI models, including Ollama, GPT4All, and Msty. This approach is understandable: processing data on-site, without resorting to cloud services, minimizes the risk of confidential information leakage and reduces the likelihood of their operations being detected. The use of retrieval-augmented generation (RAG) technology allows hackers to directly access a database of stolen documents, making their intelligence gathering more targeted.
Furthermore, tools for process automation have been discovered on infrastructure linked to the group: frameworks for AI agents, speech transcription software, and even Cursor—an AI-supported code editor. Such an arsenal indicates that Kimsuky is focused on integrating AI into all stages of an attack—from writing malware to data analysis and automating breaches.
From lures to real automation
There have already been recorded cases where the group used AI-generated fake financial and cryptocurrency documents mimicking investment reports. This is just the tip of the iceberg. Given that North Korean hackers stole over $2.02 billion in cryptocurrency in 2025, the stakes in this game are extremely high.
Of particular concern is the use of RAG to extract data from stolen documents and speech recognition systems to process intercepted audio recordings. This turns intelligence gathering into a highly automated pipeline. However, it is important to note: so far, no traces of training their own AI models have been found. At this stage, Kimsuky is in the phase of data accumulation and research, but the development trajectory is obvious.
My analysis: We are witnessing the beginning of a new arms race in cyberspace. For now, Kimsuky is merely trying on AI, but once it moves to full-scale use of these technologies, the effectiveness of its attacks will multiply. The crypto industry, as one of Pyongyang's main sources of income, should already be reviewing its security protocols now, without waiting for AI to become standard weaponry for attackers.