North Korean Hackers Are Using Local AI to Make Crypto Phishing Harder to Spot

Share:
South Korea's Genians found North Korean state-linked group Kimsuky building local LLM and AI environments using Ollama, GPT4All, Msty, RAG, Cursor and speech‑to‑text tools to improve phishing, malware development and attack automation while keeping operations on attacker‑controlled infrastructure. Researchers observed AI-generated finance and crypto investment decoys delivered via ZIP/LNK PowerShell loaders, AsyncRAT and GitHub/GitLab C2, noting the group was sanctioned by the US Treasury in 2023 and urging crypto firms to prioritize sender verification, suspicious file behavior and endpoint security over superficial phishing signs.
North Korean state-linked hacking group Kimsuky is building local artificial intelligence environments that researchers say could improve phishing campaigns, malware development and attack automation.
South Korean cybersecurity firm Genians said it found evidence that Kimsuky configured local large language model environments using Ollama, GPT4All and Msty. The group also experimented with retrieval-augmented generation, or RAG, AI coding assistant Cursor, speech-to-text software and tools for developing AI agents.
The important detail is that these systems can run on infrastructure controlled by the attackers rather than through an external cloud AI provider. According to Genians, that allows operators to process documents without sending sensitive information to third-party services, which reduces the risk that their activity or stolen material is exposed outside their own infrastructure.
(Source: Genians)
AI is already appearing in phishing materialResearchers identified finance, cryptocurrency and investment-themed decoy documents that appeared to have been generated with AI. The files were designed to resemble legitimate investment reports and workplace documents, which gives attackers a way to produce cleaner and more convincing lures for targeted victims.
The phishing chain itself still relies on familiar tactics. Genians observed malicious ZIP archives containing LNK shortcut files that can launch an embedded PowerShell loader when executed. Researchers also linked GitHub and GitLab repositories to the operation, with Git-based infrastructure used for command-and-control activity and the distribution of encrypted AsyncRAT payloads.
(Source: Genians)
What changes with AI is how efficiently parts of that process could be improved. Local models could help attackers analyze stolen documents, generate tailored phishing material, assist with malware development and automate repetitive attack tasks without relying on a public chatbot.
Genians made sure to mention that it found evidence of Kimsuky integrating existing AI technologies, rather than training proprietary models. The firm assesses the group to be accumulating the tools and expertise needed to incorporate AI more widely into future operations.
Kimsuky has long been associated with North Korea's Reconnaissance General Bureau. The US Treasury sanctioned the group in 2023 and described spear-phishing as one of its primary methods for intelligence collection.
For crypto companies, the research suggests that obvious spelling mistakes and poorly formatted documents are becoming even less useful as phishing warning signs. Defenses now need to focus on sender verification, suspicious file behavior and endpoint activity rather than whether a phishing message simply ”looks fake.”
Read More

