
North Korea's Kimsuky builds local AI setups for attacks, as DPRK-linked hackers stole $609M in H1 2026. Crypto firms face new AI-powered threats.
Alpha Score of 74 reflects strong overall profile with strong momentum, strong value, strong quality, moderate sentiment.
North Korea's Kimsuky group has been setting up local AI environments as it looks to bring artificial intelligence into its cyberattack operations, according to a report from South Korean cybersecurity firm Genians. The threat actor, which has repeatedly targeted cryptocurrency and financial firms, was found running local large language model setups using Ollama, GPT4All, and Msty.
The local approach prevents conversation data from being transmitted to external AI services, reducing the risk of exposure, Genians said. In GPT4All, investigators detected a database linked to its LocalDocs feature. The evidence suggests the group may have tried to connect documents in its possession to an AI system and use them as a knowledge source, the firm added.
Kimsuky also collected libraries and frameworks that can integrate AI into software, including LLaMaSharp, Microsoft Semantic Kernel and Microsoft Agents AI. These components cover local AI execution, document retrieval, automated agents and integration with external AI services. Investigators also found files related to Whisper and faster-whisper, speech-to-text tools that could be abused to process material stolen from compromised systems.
"This provides concrete evidence that the Kimsuky-affiliated threat actor is moving beyond one-off experimentation with AI and is continuously preparing to integrate the technology into actual attack capabilities, including malware development, data analysis, and the advancement of attack techniques."
Genians said in the report.
The AI push comes as North Korea-linked attackers already account for more than half of all cryptocurrency stolen this year. DPRK-linked groups stole about $609 million during the first half of 2026, making up roughly 55% of the $1.1 billion lost across 212 incidents, according to blockchain security firm Blockaid.
The KelpDAO and Drift Protocol attacks were linked to TraderTraitor, a North Korean state-sponsored group associated with Lazarus. Those two attacks accounted for most of the DPRK-linked losses. Humanity Protocol also lost $32 million in an attack tied to the same group.
Beyond direct hacks, North Korean operatives have sought access from inside the industry. Prominent blockchain investigator ZachXBT previously reported that North Korean IT workers generated more than $3.5 million in crypto through fake developer identities and a coordinated payment system. The operation came to light after a hacker compromised one worker's device and exposed records tied to nearly 390 accounts. The leaked data showed the operation was bringing in about $1 million a month. Workers used fake identities and forged documents to secure jobs on different projects. Their payments were tracked through an internal platform. Chat logs revealed dozens of workers active in the same system.
For crypto firms, the combination of AI-enhanced external attacks and insider infiltration through fake IT workers raises the security bar. AI tools could automate reconnaissance, generate convincing phishing messages, or analyze stolen data faster. The local LLM setups mean Kimsuky can run these capabilities without relying on external cloud services that might be monitored.
The Genians findings show the group is actively building the components to weave AI into its attack chain. That shift, if operationalized, could make North Korea-linked threats harder to detect and faster to execute. Exchanges, DeFi protocols and tokenization platforms that rely on third-party developers or remote contractors face an added layer of risk from the fake worker pipeline.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.