
Kimsuky is using AI to create fake documents and assist with coding. The group's shift toward automation threatens an industry already hit by $972 million in first-half losses.
North Korean hackers are weaving generative AI into their cyber operations, adding automation to a threat that already accounts for most crypto hacking losses worldwide.
North Korea-linked groups stole roughly $643 million in cryptocurrency during the first half of 2026, or 66% of all crypto hacking losses globally, according to blockchain intelligence firm TRM Labs. The industry suffered $972 million in losses from 207 hacking incidents in the period.
Cybersecurity researchers have found that Kimsuky, a cyber threat group tied to North Korea's Reconnaissance General Bureau, is weaponizing generative AI to support its campaigns. A report from South Korean cybersecurity firm Genians found the group deployed AI tools and large language model platforms including Ollama, GPT4All, and Msty, alongside retrieval-augmented generation technology.
Kimsuky historically used fake emails from real work contacts to target people in diplomacy, academia, and security, sending malicious files masquerading as materials for international events, research reports, invitations, and honorarium payments. Genians said the group is now testing generative AI tools for its next wave of attacks, setting up a local LLM, a RAG environment, and an AI-assisted development environment.
The AI push suggests North Korean cyber operations are moving beyond simple phishing assistance toward broader automation. Researchers found evidence of AI-assisted coding tools, speech-to-text systems, and AI-generated documents designed to resemble legitimate financial and cryptocurrency materials. Genians found Kimsuky weaponized AI-generated documents on virtual assets and financial affairs to deceive targets, with the AI content closely replicating authentic corporate documents in tone and design.
Forensics showed the threat actor was using Ollama, GPT4All, and Msty to run local AI models, RAG systems, AI agents, and speech-to-text tools. They were also heavily relying on the Cursor AI coding software while hiding code through Base64 encoding, fragmented strings, and custom-built decoding routines.
Kimsuky initiates its attack chain when a user downloads a malicious ZIP archive via email and opens the enclosed LNK shortcut. These shortcuts use decoy icons and professional filenames -- official research, honorarium requests, media reports, or embassy correspondence -- to mimic legitimate business documents.
"This analysis shows that a nation-backed hacking group is advancing its attack capabilities by building local LLMs and AI development environments to integrate AI into actual attack frameworks," said Moon Jong-hyun, head of the Genians Security Center.
Blockchain security firm CertiK estimates that North Korean hackers stole $2.06 billion in digital assets in 2025, accounting for 60% of the year's total cryptocurrency theft. In a single attack last year, North Korean hackers pulled off the biggest cryptocurrency heist on record, stealing $1.5 billion from Bybit.
CertiK also found that North Korea has scaled crypto theft into a primary financial engine for the state, plundering roughly $6.75 billion across 263 logged incidents from 2016 to 2026. Social engineering is central to the country's hacker operations, with most major North Korean heists beginning with some form of human manipulation.
CertiK warned that 2026 could see greater use of AI in social engineering, more attempts to target IT workers, and the emergence of new laundering methods. It recommended that at-risk organizations implement liveness-vetted video interviews and rigorous background checks to counter AI-generated or borrowed identities. It also advised companies to enforce zero-trust policies for remote contractors, conduct employee security awareness training, mandate cooling-off periods for withdrawals, and secure critical infrastructure such as bridges and hot wallets.
Hackers have made off with over $900 million worldwide since the start of 2026. A TRM Labs study shows a gap between the number of cyberattacks and the actual cash stolen in early 2026. Hackers hit systems 207 times but grabbed only $972 million -- nowhere near the $2.3 billion taken during the first half of 2025.
The attacks are getting more sophisticated. Of the 207 incidents, 125 were smart contract exploits, in which attackers now exploit multiple code weaknesses together rather than just one. The stolen cash is still being drained from financial firms and crypto projects.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.