Crypto news

11.08.2026
10:38

AI in Pyongyang's Service: The Kimsuky Group Masters Generative Models for Cyber Attacks

The North Korean hacker group Kimsuky, operating under the auspices of the DPRK's Reconnaissance General Bureau, has moved to a new level of technical sophistication. My analysis shows that the attackers are actively experimenting with local artificial intelligence tools, seeking to integrate them into their attack chains. This is no longer just scattered attempts, but systematic work to modernize cyber capabilities.

Local AI: A Bet on Stealth

During the investigation of Kimsuky's infrastructure, traces of the deployment and configuration of several frameworks for locally running AI models were found, including Ollama, GPT4All, and Msty. This approach is no accident: processing data on-site, without relying on cloud services, minimizes the risk of leaking confidential information, including stolen data, and reduces the likelihood of detection via network artifacts.

Furthermore, the group's arsenal includes tools for implementing retrieval-augmented generation (RAG) technology, which gives models access to selected documents, as well as AI agent frameworks, speech recognition software, and even Cursor — an AI-assisted code editor. It is obvious that such a set is not for entertainment: it covers the full cycle — from malware development to attack automation and data analysis.

From Crypto Lures to Full Automation

Previously, Kimsuky had already used AI to create fake financial and cryptocurrency documents mimicking investment reports. Now, however, the focus appears to be on deeper integration. RAG technology allows useful data to be extracted from stolen files, while speech recognition systems convert intercepted audio recordings into searchable text.

It is important to emphasize that this is happening against the backdrop of impressive financial results for North Korean hackers. According to industry estimates, groups linked to the DPRK stole approximately $2.02 billion in cryptocurrency in 2025 alone. AI is becoming not just a tool for them, but a force multiplier.

Notably, researchers found no traces of training their own models, which points to a phase of knowledge accumulation and testing. However, this is only a matter of time. The integration of AI into cyberattacks is not the future — it is already the present. The cryptocurrency market and everyone working with digital assets should take this threat with the utmost seriousness: the next phishing attempt may be indistinguishable from a genuine email, and a breach may be fully automated.