North Korea-Linked Kimsuky Builds Local AI Tools

A North Korean-linked hacking group is developing its own artificial intelligence capabilities to automate parts of cyberattacks, analyse stolen information and create more convincing phishing campaigns, according to findings from South Korean cybersecurity firm Genians.

The firm linked the activity to Kimsuky, a cyber-espionage group associated with North Korea, after identifying infrastructure containing tools capable of running and managing large language models locally.

According to Genians, the group had installed software including Ollama, GPT4All and Msty, which can be used to operate AI models on local systems rather than relying on external cloud-based services.

Running models locally could allow operators to process sensitive or stolen information without transmitting it to commercial AI providers, reducing exposure to the monitoring and safety controls built into some externally hosted AI services.

Researchers also identified retrieval augmented generation, or RAG, technology within the infrastructure. RAG allows an AI system to retrieve information from a collection of documents and use that material to generate context-specific responses.

In a cyber operation, such technology could potentially make it easier to search, organise and analyse large volumes of collected material.

Genians also identified AI agent development frameworks, speech-to-text software and Cursor, an AI-assisted coding tool, on infrastructure associated with the campaign.

The findings indicate that the group may be moving beyond using generative AI primarily to produce phishing content and towards integrating AI into broader cyber operations, including malware development, data analysis and attack automation.

Genians also found finance and cryptocurrency-themed decoy documents that appeared to have been generated using AI. The materials were designed to resemble legitimate investment reports and workplace documents, potentially making phishing attempts more convincing to intended targets.

The cybersecurity firm's findings could not be independently verified.

Kimsuky has previously been linked by cybersecurity researchers and government agencies to intelligence-gathering operations targeting organisations and individuals in sectors including government, research and foreign policy.

The latest findings come as cybersecurity researchers increasingly examine how state-linked and criminal groups are adopting generative AI. While AI does not necessarily introduce entirely new forms of cyberattack, it can potentially reduce the time required for tasks such as writing phishing emails, analysing information, producing code and adapting malicious campaigns.

The use of locally operated models introduces an additional consideration for AI safety. Commercial AI platforms can apply usage policies, monitoring systems and safeguards intended to detect malicious activity. Open models running on infrastructure controlled by an attacker may operate outside those protections.

Genians' findings suggest that AI could increasingly become part of the underlying infrastructure used by sophisticated threat actors rather than functioning only as an external tool for generating content.

The development also reflects the dual-use nature of AI in cybersecurity. Similar capabilities can help legitimate security teams analyse vulnerabilities, automate defensive tasks and process threat intelligence, while malicious actors may attempt to apply them to offensive operations.

As AI tools become more accessible, cybersecurity companies are likely to focus increasingly on detecting malicious behaviour and infrastructure rather than relying solely on identifying suspicious content.

For businesses, the findings add another dimension to the evolving cyber threat environment, particularly as AI-generated phishing materials become harder to distinguish from legitimate workplace communications.