Back Finance.Biggo North Korea's Kimsuky Attempts to Weaponize AI with Ollama, GPT4All
Evidence has been uncovered that Kimsuky, a hacking group operating under North Korea's Reconnaissance General Bureau, has built local large language model (LLM) execution environments to integrate generative artificial intelligence into its cyberattacks, using this foundation to conduct sophisticated spear-phishing campaigns. The group appears to be simultaneously pursuing automation and advancement of its attacks, even incorporating document-based Retrieval-Augmented Generation (RAG) systems and speech recognition tools.
In a threat analysis report released on the 10th, South Korean cybersecurity firm Genians announced it had secured evidence that Kimsuky repurposed GitHub and GitLab-based command-and-control (C2) infrastructure as an AI technology research environment. Genians has named and is tracking this campaign as "Operation GitPower."
According to the report, traces of three local LLM execution tools — Ollama, GPT4All, and Msty — were found installed and running on Kimsuky's C2 servers. Evidence of actual usage was also confirmed, including RAG feature configurations, the collection of libraries for AI agent development, and files related to OpenAI's speech-to-text model "Whisper." However, Genians assessed that there is not yet sufficient evidence to conclude the group has advanced to the stage of directly training AI models, describing it instead as "a phase of researching and learning how to integrate existing AI into attack activities."
Records also showed the installation of "Cursor," an AI-powered code editor, used to edit attack documents and review generated outputs. Genians analyzed this as evidence of research and validation aimed at leveraging AI for malware development and attack automation.
Regarding attribution, sentences believed to have been typed on a Korean Dubeolsik keyboard repeatedly contained North Korean vocabulary such as "ssaiteu" (site) and "riryeok" (resume). The system manufacturer name appearing as the North Korean brand "Arirang" was also presented as supporting evidence.
A defining characteristic of the attacks discovered is the significantly improved quality of bait documents produced using generative AI. Unlike in the past, when hacking groups recycled leaked legitimate documents or sent phishing emails with awkward translations, they are now mass-producing documents that are virtually indistinguishable from genuine business materials.
In this campaign, malicious files mimicking investment strategy materials distributed by a South Korean fintech platform were used. File names such as "2026 July Practical Strategy Pack.pdf.lnk" were designed to be mistaken for standard PDF investment reports. The document design also demonstrated sophistication, referencing modern document organization formats like Notion, applying consistent colors and margins across pages, visually organizing tables and headings, and even inserting emojis.
Social engineering techniques designed to entice targets into opening files without suspicion have also evolved considerably. A wide range of topics were exploited that recipients could easily mistake as directly related to their work, including requests for case payments, research materials, press manuscript reviews, urgent embassy correspondence, and legal and financial documents. While attachments appeared to be HWP (Hangul Word Processor) documents or PDFs, they were actually malicious LNK shortcut files that executed PowerShell scripts in the background upon opening. According to Genians, cases were also confirmed where the file information itself was forged to appear as a legitimate HWP document.
Evidence was also captured indicating that the attackers primarily targeted professionals in the virtual asset and financial sectors, attempting to verify the exposure of virtual asset wallets, Gmail account information, and website registration histories.
The greatest threat posed by such AI-powered attacks lies in the simultaneous increase in both attack speed and precision. Leveraging generative AI drastically reduces the time and cost required to produce bait documents and emails optimized for a target's occupation and interests. Consequently, traditional methods of identifying phishing based solely on spelling errors or awkward phrasing are no longer effective.
Moon Jong-hyun, head of Genians Security Center, emphasized, "With the advancement of AI technology, social engineering attacks are expected to become even more sophisticated. Moving beyond the conventional approach of judging document quality, a threat hunting system based on Endpoint Detection and Response (EDR) that focuses on detecting execution behaviors is more critical than ever." He added, "This analysis serves as a case study demonstrating how a state- hacking group is advancing its attack capabilities by building local LLM and AI development environments to integrate AI into its actual attack framework."
Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
