Skip to content
North Korean Hackers Build Local AI Systems to Sharpen Cyberattacks

North Korean Hackers Build Local AI Systems to Sharpen Cyberattacks

En.Sedaily August 10, 2026

Kimsuky, a hacking group under North Korea's Reconnaissance General Bureau, has shown signs of building a local large language model (LLM) environment to automate and advance its cyberattacks using generative artificial intelligence, according to a security analysis. Analysts say the group is now weaving AI throughout its operations — moving beyond simple phishing emails to using crypto and financial materials produced with generative AI.

Genians (263860.KQ), a cybersecurity firm, said on the 10th that these findings emerged from its analysis of Kimsuky's latest attack activity. North Korean hacking groups have until now relied mainly on spear-phishing emails that impersonate real work contacts to target diplomatic and security experts. Their previously confirmed use of AI had also been concentrated in the preparation stage of attacks, such as forging images and voices and creating phishing lures.

In this analysis, however, investigators found traces that the threat actor had directly built local LLM execution environments and a retrieval-augmented generation (RAG) setup, and operated an AI-based development environment. Specifically, they found signs that the group had built or used local LLM execution and management tools such as Ollama, GPT4All and Msty, along with a RAG configuration, an AI agent development framework and speech-to-text (STT) tools.

Multiple traces of installing and using an AI-based code editor (Cursor) were also identified. Genians interpreted this as evidence that research and technical verification are underway to use AI for malware development and attack automation.

The attack techniques have also grown more sophisticated. While the group previously reused stolen legitimate documents in many cases, it has recently been using crypto and financial documents believed to have been created with generative AI as spear-phishing lures. The method deceives users with natural writing and a level of polish comparable to real work documents, prompting them to run malicious files.

Kimsuky was found to be targeting the cryptocurrency sector in particular. Malicious documents disguised as investment strategy reports and financial materials were distributed continuously.

"This analysis is a case showing that a state-backed hacking group is advancing its attack capabilities, going as far as building local LLM and AI development environments to weave AI into an actual attack system," said Moon Jong-hyun, director and head of the Genians Security Center. "As attacks are expected to become more sophisticated with the advance of AI technology, an EDR-based threat hunting system that focuses on execution behavior rather than document content is more important than anything."

The Genians Security Center is closely sharing its analysis results with domestic and international cooperation channels, including the Korea Internet & Security Agency (KISA) threat intelligence network consultative body.

Original reporting by Kim Tae-young for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

Extracted Entities

APT Groups (1)

Attack Types (2)

Companies (1)

Countries (1)

Industries (1)

MITRE ATT&CK (1)

Platforms (1)

Tools (2)