
Local AI setups let Kimsuky analyze stolen data and generate phishing lures without relying on cloud providers, Genians says. Crypto companies must shift detection from obvious errors to sender verification.
North Korean state-linked hackers are building custom artificial intelligence environments that could make their phishing campaigns harder to detect, South Korean cybersecurity firm Genians said.
The group, tracked as Kimsuky and tied to Pyongyang's Reconnaissance General Bureau, set up local large language model systems using Ollama, GPT4All and Msty, Genians reported. The researchers also found evidence the group tested retrieval-augmented generation, the AI coding assistant Cursor, speech-to-text software and tools for building AI agents.
The systems run on infrastructure controlled by the attackers rather than through a public cloud provider. That lets operators analyze stolen documents and generate phishing material without sending sensitive data to an outside service, Genians said. It reduces the risk that their activity or the stolen material gets exposed through a third party.
Researchers identified decoy documents themed around finance, cryptocurrency and investment that appeared to have been created with AI. The files were built to look like legitimate investment reports and workplace documents. For a group that has long relied on spear-phishing as its primary intelligence-gathering method – the U.S. Treasury sanctioned Kimsuky in 2023 over that precise tactic – cleaner, more convincing lures mean a higher hit rate.
The mechanics of the phishing chain itself remain familiar. Genians observed malicious ZIP archives containing LNK shortcut files that, when opened, launch an embedded PowerShell loader. Researchers also linked GitHub and GitLab repositories to the operation, using Git-based infrastructure for command-and-control and to distribute encrypted AsyncRAT payloads.
What changes with local AI is how efficiently parts of that process can be improved. Local models could help attackers analyze stolen documents in place, tailor phishing emails to specific targets, assist with writing malware and automate repetitive tasks without ever touching a public chatbot, Genians said. The firm assessed that the group is accumulating the tools and expertise needed to integrate AI more widely into future operations.
For crypto companies, the research points in a specific direction. Obvious spelling mistakes and poorly formatted documents are becoming less useful as red flags. Defenses now depend more on sender verification, suspicious file behavior and endpoint activity monitoring than on whether a phishing message looks obviously fake.
Genians stressed that it found evidence of Kimsuky integrating existing AI technologies, not training proprietary models. The firm assesses the group is accumulating the tools and expertise needed to incorporate AI more widely into future operations.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.