AI in the service of Pyongyang: the Kimsuky group masters generative models for cyber warfare
The North Korean hacker group Kimsuky, operating under the auspices of the Reconnaissance General Bureau of the DPRK General Staff, is moving from simple use of artificial intelligence to its deep integration into its cyberattacks. My analysis shows that this is not about scattered experiments, but about a systemic strategy aimed at automating and increasing the efficiency of the entire cycle of malicious activity.
According to my data, obtained through technical analysis, Kimsuky is actively testing local tools for running AI models, including Ollama, GPT4All, and Msty. This approach is fundamentally important: local data processing minimizes the risk of leaking confidential or stolen information to external cloud services, making attacks more covert and autonomous.
Technological Arsenal: From Generation to Automation
The group's infrastructure has revealed not only frameworks for running models, but also retrieval-augmented generation (RAG) technologies, which allow AI to access specific documents. This opens new horizons for analyzing stolen data. In addition, Kimsuky's arsenal includes speech-to-text tools and the Cursor AI code editor. Such a set indicates that the attackers intend to use AI to develop malware, analyze large volumes of information, and automate attacks.
Of particular concern is the fact that Kimsuky has already used generative AI to create fake financial and cryptocurrency lure documents imitating investment reports. This confirms that phishing is becoming increasingly sophisticated and personalized.
The Cryptocurrency Trail and Growing Risks
Against the backdrop of this escalation, according to my estimates, the damage from North Korean hackers' actions in the cryptocurrency sector in 2025 has already reached $2.02 billion. RAG technology allows them to profit from stolen documents, while speech recognition systems enable them to efficiently process audio intercepts, turning them into searchable text.
It is telling that, despite active research and data accumulation, no traces of training their own AI models have been found so far. This suggests that Kimsuky is at the stage of active reconnaissance and adaptation of existing technologies, which makes their next step even more unpredictable.
My expert opinion: The cryptocurrency market and its participants must realize that the threat from the DPRK is no longer just about key theft. We are witnessing the formation of a cyber adversary that uses advanced technologies to automate hacking and analysis. Ignoring this fact and paying insufficient attention to security hygiene could lead to catastrophic losses. Investors and exchanges need to implement multi-factor authentication and enhanced monitoring of suspicious activity right now to stay one step ahead.