AI in Pyongyang's Service: The Kimsuky Group Masters Generative Models for Cyber Warfare
The North Korean hacker group Kimsuky, operating under the auspices of the Reconnaissance General Bureau of the DPRK, has shifted from simply using generative AI for phishing to systematically studying and integrating this technology into its attack chains. This is not about isolated experiments, but about building a full-fledged arsenal of next-generation cyber weapons.
My analysis of incidents recorded during recent campaigns shows that Kimsuky is actively testing local tools for running LLM models, including Ollama, GPT4All, and Msty. This approach is not just a nod to trends. Local data processing is critically important for secrecy: it allows attackers to minimize the risk of leaking stolen information to external AI services that may be controlled by Western intelligence agencies.
Technology Stack and New Capabilities
On infrastructure linked to the group, not only platforms for running models have been discovered, but also RAG (Retrieval-Augmented Generation) technology. Its use opens up frightening prospects for hackers: the AI gains direct access to a database of stolen documents, enabling automated search and systematization of valuable data from vast amounts of information.
Additionally, Kimsuky's arsenal includes frameworks for creating AI agents, speech-to-text (STT) software, and the AI code editor Cursor. This set of tools appears to be designed to address three key tasks: automating malware writing, intelligent intelligence analysis, and partial automation of the attacks themselves.
Significantly, the group has already used AI to generate fake financial and cryptocurrency lure documents imitating investment reports. This confirms that North Korean hackers, who in 2025, according to industry estimates, stole over $2.02 billion in cryptocurrency, are focused on automating and increasing the efficiency of their operations.
So far, researchers have not found traces of training their own AI models, which points to a phase of data accumulation and technology study. However, two key risks are already evident: RAG allows extracting data from stolen documents, and STT systems turn intercepted audio recordings into easily searchable text.
My verdict: we are witnessing not just another tactical upgrade, but a fundamental shift in the operational capabilities of one of the most dangerous APT groups in the world. The cybersecurity industry, and especially crypto exchanges, should prepare for attacks where social engineering and data analysis will be perfected with the help of AI.