North Korea-linked hacking group Kimsuky has been confirmed for the first time by a South Korean security firm to be using an open-source AI coding agent as an attack tool. Unique traces left by the AI agent were discovered during the mass production of decoy files disguised as financial and insurance-related documents.
Genians Security Center announced in a report released on the 7th that analysis of 13 malicious Windows LNK files and decoy documents collected between the 11th and 18th of last month revealed multiple indicators of cyberattacks exploiting the open-source AI coding agent "opencode."
opencode is a tool that automatically performs code writing and file creation based on natural language instructions in a terminal environment. The analyzed LNK files used keywords disguised as financial and financial-operations scenarios—including fund disbursement, insurance premiums, interest payments, policy funds, certificate renewal, store reference data, customer documents, and Visa payments—to lure users into clicking.
The 'Digital Fingerprint' Left by the AI Agent
The metadata of the decoy PDF files contained unique identifier records generated through script-based processes in the opencode environment, rather than through conventional document editing software such as Word. The security firm explained that these values are not produced by standard document creation programs.
The fact that multiple documents shared completely identical creation timestamps down to the second is also noteworthy. Unlike typical user behavior where documents are created or edited sequentially, this suggests that multiple documents were generated simultaneously through a single automated process or script.
Another piece of evidence pointing to AI coding agent usage was the presence of unsubstituted "(placeholder)" markers in document bodies where specific figures—such as payment cycles and interest rates—should have appeared. This suggests the hackers distributed AI-generated drafts without properly reviewing them.
Genians had previously disclosed evidence of Kimsuky using AI and local large language models (LLMs) for attack preparation and decoy creation, but this is the first time the use of an AI coding agent like opencode has been confirmed.
Evidence Attributing the Attack to Kimsuky
The center determined that the forged attribute descriptions in the LNK files matched the fingerprints described in reports on Kimsuky's Operation GitPower. Factors including abnormally long execution arguments, URL fragment concatenation methods, hidden scheduled tasks, and the continuation and expansion of decoy themes disguised as financial, legal, and business documents collectively point to Kimsuky as the perpetrator.
When the malicious file executes, it connects to GitHub accounts pre-created by the hackers to receive additional commands. Some variants also used Pastebin—a text-sharing site frequently used for sharing hacking materials—as an additional command delivery channel. This dual-channel setup ensures that even if the GitHub path is blocked, commands can still be received via Pastebin.
Infected computers also had scheduled tasks secretly registered, disguised as Windows' built-in BitLocker feature or MATLAB software. These scheduled tasks begin repeating at regular intervals after five minutes, continuously downloading additional malicious commands from GitHub.
Enhanced Evasion Capabilities
The new variants also showed significantly strengthened detection-evasion features. They first check whether tools used by security analysts are running, and immediately halt execution if detected. They also delete command execution history to erase analysis traces.
A Genians Security Center representative emphasized: "AI is increasing the sophistication of decoy documents and the speed of attack preparation, while evasion techniques are becoming increasingly refined. It is essential to build an integrated response framework centered on endpoint detection and response (EDR) that continuously incorporates the latest indicators of compromise, analyzes correlations between attack stages, and rapidly blocks anomalous behavior."
This discovery carries significant implications for the cybersecurity industry, as it shows that a state- hacking group has elevated generative AI tools beyond simple text generation or code assistance to the automated production stage of attack infrastructure. As the visual sophistication of decoy documents increases, it becomes harder for users to intuitively determine whether files are malicious.
The security firm advised: "We have entered an era where examining decoy documents alone is insufficient to determine whether an attack is underway." It recommended transitioning to an integrated security framework that detects a series of anomalous behaviors—such as executing suspicious files after decompressing archives, accessing GitHub or Pastebin, and registering hidden scheduled tasks—as a single correlated chain of activity.
Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
