How Is Kimsuky Using AI In Cyberattacks?

North Korean hacker group Kimsuky is building local artificial intelligence environments that could help automate cyberattacks against cryptocurrency and financial companies, according to research released Monday by South Korean cybersecurity firm Genians.

Researchers found evidence that the group operated three local large language model environments using Ollama, GPT4All and Msty. Unlike cloud-based AI services, these systems can run locally, allowing attackers to analyze information and generate content without sending sensitive data to external providers.

The tools also support retrieval-augmented generation, which allows language models to reference collections of stored documents while answering queries. For hackers, that could make it easier to process stolen information, search large datasets or generate attack material while keeping activity inside a controlled environment.

Kimsuky has also collected software libraries used to embed language models into custom applications, alongside the Cursor AI coding assistant and speech-to-text tools. Genians said the activity appears focused on incorporating existing open-source AI models into malware development, data analysis and attack automation rather than building proprietary AI models from scratch.

“This provides concrete evidence that the Kimsuky-affiliated threat actor is moving beyond one-off experimentation with AI and is continuously preparing to integrate the technology into actual attack capabilities,” Genians said.

Why Are Crypto Firms An Attractive Target?

The research also found continued use of generative AI to create phishing material aimed at cryptocurrency, fintech and investment targets. Some documents closely copied materials used by a Korean AI-powered investment platform, using polished language, professional formatting and visual elements designed to make fraudulent communications appear legitimate.

That matters because phishing attacks often rely on small errors that expose fraudulent emails or documents. Generative AI can reduce spelling mistakes, improve formatting and produce more convincing business language, making it harder for employees to identify malicious communications based solely on presentation.

Cryptocurrency companies are particularly valuable targets because successful attacks can provide direct access to digital assets while compromised employee credentials may expose wallets, internal systems or transaction infrastructure.

North Korean hackers stole about $2.02 billion in cryptocurrency last year, according to blockchain analytics data, including the roughly $1.5 billion attack on crypto exchange Bybit. Their methods have ranged from conventional phishing campaigns to placing IT workers inside cryptocurrency businesses to gain access to sensitive corporate systems.

Investor Takeaway

AI does not need to create entirely new hacking techniques to increase risk for crypto firms. Automating phishing, coding, research and data analysis can make existing attack methods faster, cheaper and more difficult for employees and security teams to detect.

What Does Local AI Change For Cybersecurity?

Running AI models locally gives attackers an important operational advantage. Queries involving stolen data, malware code or planned attacks do not have to pass through external AI platforms, reducing the chance that activity is logged, restricted or detected by service providers.

Local models can also be modified and combined with other software without the safeguards imposed by commercial cloud services. That allows threat groups to build customized workflows for writing malicious code, analyzing compromised networks or generating large numbers of tailored phishing messages.

The approach does not necessarily mean AI is independently executing attacks. Genians’ findings instead point to hackers using the technology as another layer of automation inside established cyber operations.

NEAR Protocol co-founder Illia Polosukhin has previously warned that AI can accelerate the discovery of software vulnerabilities, potentially allowing attackers to identify weaknesses faster than traditional security teams can patch them.

Can AI Make Crypto Exploits Harder To Prevent?

The growing use of AI may shorten the time between discovering a vulnerability and exploiting it. That creates a particular challenge for cryptocurrency companies, where smart contracts, wallets and custody systems can hold large amounts of immediately transferable assets.

The recent $100 million exploit affecting Coldcard Bitcoin hardware wallets has been linked to suspicions that an obscure vulnerability was uncovered using AI. While individual incidents may differ, the case illustrates how automated code analysis could help attackers find weaknesses that might otherwise remain unnoticed for longer periods.

For exchanges, custodians and financial firms, the response will increasingly depend on more than filtering suspicious emails. Employee verification, access controls, code reviews, behavioral monitoring and rapid patching become more important when attackers can use AI across several stages of an operation.

Kimsuky’s activity shows that the immediate cybersecurity risk from AI is not necessarily a new generation of autonomous hacking systems. The more practical threat is that established groups can use readily available models to improve the speed, scale and quality of attacks they already know how to conduct.