
The North Korean-linked hacker group Kimsuky is employing local AI systems to target cryptocurrency and financial companies, according to South Korean cybersecurity analysts Genians.
Researchers discovered that Kimsuky utilizes local LLM environments based on Ollama, GPT4All, and Msty. These tools operate offline and support the Retrieval-Augmented Generation method, allowing queries without sending data to cloud services.

The group’s infrastructure also includes libraries and frameworks for embedding language models into their software, an AI assistant for programming called Cursor, and speech recognition tools.
Genians linked this activity to the integration of open LLMs in malware development, data analysis, and attack automation.
According to the company, Kimsuky is not merely experimenting with AI but is preparing to integrate it into actual attack tools. The focus is on using existing technologies rather than training their own models.
Genians also noted that the group continues to use generative AI to create phishing documents about digital assets, investment strategies, and fintech services. Some materials mimicked documents from a Korean AI investment platform, featuring natural language and professional formatting.

In August, crypto exchange Bybit filed a civil lawsuit against North Korea and the Lazarus Group.
