
Kimsuky operators run local LLMs to generate polished decoys on virtual assets and finance, Genians found. The shift raises the stakes for crypto firms facing AI-enhanced phishing.
North Korean hacking group Kimsuky is running local artificial intelligence models to craft phishing lures that target cryptocurrency and finance professionals, according to researchers at South Korean cybersecurity firm Genians Security Center. The shift marks a move away from recycled documents toward AI-generated content that mirrors genuine business materials.
Genians identified signs that Kimsuky operators have set up offline environments for large language models using tools such as Ollama, GPT4All and Msty. Those tools let the models function without cloud connections, cutting the risk of detection or data leakage. Researchers also found evidence of retrieval-augmented generation technology for document handling, frameworks for building AI agents, speech-to-text software, and the AI coding assistant Cursor.
Collectively, the setup points to a group that is embedding AI into broader attack workflows – malware support, analysis of compromised material and process automation – rather than relying on occasional use of public generative AI services, Genians said.
The most visible change is in the quality of lure documents. In past campaigns Kimsuky often reused materials stolen from earlier intrusions. Since early 2026, researchers have observed a growing reliance on AI-generated content. The files address virtual assets, financial investments and related professional topics. They feature natural phrasing, consistent formatting and structures that closely match genuine business reports or strategy decks, Genians said.
One example mimicked investment strategy materials associated with a Korean fintech service that had itself warned users about phishing attempts. Metadata and timing patterns in some samples support the assessment of automated generation, the researchers added.
Delivery follows a familiar pattern. Spear-phishing messages or other channels deliver ZIP archives containing malicious LNK shortcut files. Those shortcuts carry icons and names that resemble legitimate PDFs or official documents. When opened, they trigger obfuscated PowerShell commands that download additional payloads, display a harmless decoy file to reassure the victim, and establish persistence through scheduled tasks. Command-and-control activity has been linked to abuse of public Git-based repositories for distributing encrypted payloads, including variants of AsyncRAT.
Kimsuky continues to target foreign diplomatic bodies alongside military, security and virtual asset sectors. The addition of AI-generated finance and crypto lures increases the odds of engaging individuals and organizations that handle digital assets or financial platforms, Genians said. By producing higher-quality, more scalable social engineering material and keeping sensitive operations internal through local AI setups, the group strengthens its ability to support both espionage and potential financial objectives.
For crypto firms, the threat is more convincing, thematically relevant phishing that can serve as an entry point for credential theft or malware deployment. Genians advised defenders to strengthen detection around anomalous LNK behavior, PowerShell activity and unexpected use of development or repository services. Kimsuky's focus on virtual asset targets remains a constant, the researchers said.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.