A North Korean hacking group has developed tools based on large language models and collected software that could help automate cyberattacks, analyse stolen data and create more convincing phishing campaigns, South Korean cybersecurity firm Genians said on Monday.
Genians (263860.KQ) said it found evidence that the North Korea-linked group Kimsuky had established tools for running and managing AI models locally, including Ollama, GPT4All and Msty, alongside a document- technology known as retrieval-augmented generation (RAG), Reuters reported.
According to the company, the tools could allow operators to process documents without sending sensitive information to external AI services.
Genians also found AI agent development frameworks, speech-to-text software and Cursor, an AI-assisted coding tool, on infrastructure it linked to the campaign.
The findings suggest that Kimsuky is moving beyond using generative AI to create phishing lures and is developing the capability to integrate existing AI models into malware development, data analysis and attack automation, Genians said in a report.
Genians also said it found finance- and cryptocurrency-themed decoy documents that appeared to have been generated using AI. The materials were designed to resemble legitimate investment reports and other workplace documents, the company said.
The company's findings could not be independently verified.
North Korea has for years used state-linked cyber units for espionage , financial theft and revenue generation, according to US and South Korean authorities, as well as cybersecurity experts.
The US Treasury sanctioned Kimsuky in 2023 as a North Korean government-controlled cyber-espionage group, saying it gathered intelligence in support of Pyongyang's strategic objectives.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
