North Korean Hacking Group Reportedly Builds AI Tools for Cyberattacks

A North Korean-linked hacking group is reportedly expanding its use of artificial intelligence by developing tools that could help automate cyberattacks, analyze stolen information and create more convincing phishing campaigns.

South Korean cybersecurity company Genians said it identified evidence that the group known as Kimsuky had established infrastructure for running and managing artificial intelligence models locally.

The reported setup included tools such as Ollama, GPT4All and Msty, which can be used to run or interact with AI models on local systems. Genians also identified retrieval-augmented generation, commonly known as RAG, within the infrastructure it examined.

RAG technology allows AI systems to retrieve information from a specific collection of documents before generating a response. In a cyber operation, such technology could potentially help attackers search and analyze large volumes of stolen material.

According to Genians, running AI models locally could also allow operators to process sensitive documents without sending the information to external AI platforms.

The cybersecurity company said it found additional tools associated with AI development and automation, including AI agent frameworks, speech-to-text software and Cursor, an AI-assisted coding tool.

The findings suggest that Kimsuky may be moving beyond the use of generative AI for creating phishing messages and other social engineering material.

Genians said the group appears to be exploring ways to integrate existing AI models into activities such as malware development, stolen-data analysis and attack automation.

Artificial intelligence has increasingly become a tool used by cybercriminals and threat actors. Generative AI can make it easier to produce convincing messages, translate content and automate certain research tasks.

The reported use of local AI models could represent another development because sensitive information can potentially be processed without being uploaded to a third-party AI service.

Genians also reported finding finance and cryptocurrency-themed documents that appeared to have been created using AI. The materials were reportedly designed to resemble legitimate investment reports and workplace documents.

Such documents could potentially be used as decoys or lures in targeted cyber campaigns. However, the specific purpose of the materials and their connection to individual attacks would require further investigation.

Genians’ findings have not been independently verified, and the reported tools alone do not establish that every identified application was used directly in a cyberattack.

Kimsuky has previously been associated with cyber-espionage campaigns targeting organizations and individuals. North Korean-linked cyber groups have also been accused by governments and cybersecurity researchers of conducting espionage, financial theft and other operations.

The United States Treasury sanctioned Kimsuky in 2023 and described it as a North Korean government-controlled cyber-espionage group. Washington said the group collected intelligence in support of Pyongyang’s strategic objectives.

The latest report highlights the growing intersection between artificial intelligence and cybersecurity threats. As AI tools become more capable and widely available, threat actors can potentially use existing technologies rather than developing every capability from scratch.

For organizations, the development reinforces the importance of strong email security, employee awareness, endpoint protection and controls around sensitive data.

The reported activity also demonstrates why cybersecurity teams are increasingly monitoring how legitimate AI software is being used on suspicious infrastructure.

If threat actors can combine local AI models with stolen documents, coding assistants and automated agents, security teams may face increasingly sophisticated campaigns.

The findings from Genians therefore offer another indication that artificial intelligence is becoming part of the broader cyber threat landscape, although the full scale and operational impact of Kimsuky’s reported AI capabilities remain unclear.