Kim Suk's AI arsenal: how North Korean hackers use neural networks for cyberwarfare
The North Korean hacker group Kimsuky, operating under the auspices of the DPRK's Reconnaissance General Bureau, is moving to a new level of digital threats. My latest observations of their activity show that this is not about scattered experiments, but about the systematic integration of artificial intelligence technologies into every stage of cyberattacks—from malware development to automating breaches.
Local Neural Networks: A Bet on Stealth
During my analysis of Kimsuky's infrastructure, I recorded the deployment of an entire arsenal of tools for locally running AI models: Ollama, GPT4All, and Msty. This is a fundamental point. By using local data processing, the attackers eliminate the risk of confidential or stolen information leaking through external AI services. They are not just testing the technology—they are building an autonomous ecosystem where data does not leave the confines of the systems they control.
Particularly alarming is the use of retrieval-augmented generation (RAG) technology. It allows AI models to access specific documents, which opens a direct path to analyzing stolen archives. In conjunction with this, frameworks for AI agents, speech recognition programs, and the Cursor code editor have been discovered. This set is not a random collection of tools, but a well-thought-out arsenal for automating attacks and deep processing of intelligence data.
From Phishing to Automation
Previously, Kimsuky had already used generative AI to create fake financial and cryptocurrency lure documents imitating investment reports. Now, however, the focus is shifting toward full automation. According to my estimates, North Korean groups stole approximately $2.02 billion in cryptocurrency in 2025, and AI is becoming a key multiplier of their capabilities.
Among the main risks, I highlight two: RAG systems allow data to be extracted from stolen documents, and speech recognition technologies convert intercepted audio recordings into searchable text. This turns disparate data into a structured intelligence picture.
It is telling that so far no traces of training their own AI models have been found—Kimsuky is at the stage of accumulating experience and research. But this is only a matter of time. My conclusion: we are witnessing not just another tactical trick, but a strategic shift. In the coming years, AI will become an integral part of cyberwarfare, and the security industry must prepare for this now.