North Korea is arming itself with AI: the Kimsuky group is mastering generative models for cyber warfare.
The intelligence community is recording an alarming trend: the North Korean hacker group Kimsuky, operating under the auspices of the DPRK's Reconnaissance General Bureau, is transitioning from simple use of AI to the systematic integration of this technology into its attack chains. My recent research in this area indicates that we are on the threshold of a new era in cyber conflicts, where generative models are becoming not just a tool, but a full-fledged element of the attacker's infrastructure.
Local AI: A New Security Tactic
Unlike many other actors, Kimsuky is betting on local rather than cloud-based AI solutions. Traces of the deployment and configuration of frameworks such as Ollama, GPT4All, and Msty have been found on compromised infrastructure. This approach is not accidental: it allows stolen data to be processed without transmitting it to external services, which significantly reduces the risk of detection and traffic interception. This is direct evidence that the group carefully plans operational security at every stage.
Moreover, a full toolkit for automation has been found in the attackers' arsenal: from RAG (retrieval-augmented generation) technology, which gives models access to specific documents, to AI agents, speech recognition systems, and even the Cursor code editor. It is obvious that North Korean specialists are not limiting themselves to simple experiments, but are purposefully building a pipeline for developing malware and analyzing large volumes of stolen information.
From Phishing to Full Automation
Previously, the group had already used AI to create convincing fake financial and cryptocurrency lure documents imitating investment reports. Now the focus is shifting toward more complex tasks. In my assessment, this evolution—from content generation to attack automation—is a logical step. Given that North Korean groups stole $2.02 billion in cryptocurrency over 2025, the potential for scaling such operations with AI is enormous.
The key risks I highlight are related to the use of RAG to extract data from stolen documents and the use of speech recognition systems to convert audio recordings into digestible text. This transforms chaotic data sets into structured intelligence that can be used for further targeted attacks.
So far, no traces of training their own models have been found, which indicates that Kimsuky is at the stage of data accumulation and research. However, this is only a matter of time. In my professional opinion, the security industry needs to prepare for AI becoming a standard weapon in the arsenal of APT groups, and the current situation with Kimsuky is just the first warning sign of an impending wave of highly automated and difficult-to-detect attacks.